
There's no score you're supposed to hit. Microsoft Secure Score is a checklist with a percentage stapled to it, and the percentage is the least useful part. What matters is which recommendations you've actually done and which ones you've quietly skipped for two years.
Most small business tenants we open land in the 30s to 50s. That number tells you almost nothing on its own. A 45% built on MFA, conditional access, and tuned mail flow rules beats a 65% built on twenty cosmetic toggles.
What is Microsoft Secure Score?
Microsoft Secure Score is a measurement of your security posture inside Microsoft 365, shown as a percentage of points earned against points available. You'll find it at security.microsoft.com/securescore in the Defender portal.
Microsoft's own documentation is blunt about the math: "Each recommended action is worth 10 points or less, and most are scored in a binary fashion." Do the thing, get the points. Don't, get zero.
Partial credit exists where coverage is partial. Microsoft's example: protect 50 of your 100 users with MFA on a 10-point action and you get 5 points.
The score covers more than Exchange and SharePoint. Recommendations span Entra ID, Defender for Endpoint, Defender for Identity, Defender for Office, Purview Information Protection, Teams, and Defender for Cloud Apps, plus non-Microsoft products like Okta, Salesforce, ServiceNow, and Zoom.
Why is my Secure Score so low?
Because Microsoft shows you every possible recommendation regardless of what you're licensed for. Their documentation says it plainly: "We show you the full set of possible recommendations for a product, regardless of license edition, subscription, or plan."
So a Business Premium tenant sees E5-only recommendations it can't act on. Those points sit in your denominator permanently, and on a small tenant they're a meaningful share of what's available.
The second reason is stale scoring. Secure Score updates in real time as you make changes, but it also syncs daily for system data, and Entra and Teams recommendations refresh on their own schedule — weekly for Entra, monthly for Teams. A change you made Tuesday may not show until next week.
What's a good Microsoft Secure Score for a small business?
There isn't a target percentage, and a well-run Business Premium tenant with every practical control enabled still won't break out of the 60s once unreachable E5 recommendations are counted against it. The only benchmark worth using is the comparison band in the portal itself, which shows how you compare to organizations of similar size.
Chase a number you read in a vendor blog and you'll end up enabling settings that earn points and break workflows.
Use the score as a work queue, not a grade. Sort recommendations by points, filter out the ones your licensing can't reach, and work the top of the list. When a recommendation genuinely doesn't apply, mark it resolved through an alternate mitigation or accept the risk in the portal so it stops distorting your number.
Which Secure Score actions actually matter?
Start with identity. Microsoft's documentation states that "Research by Microsoft shows that MFA can block more than 99.2% of account compromise attacks." Every identity recommendation in Secure Score is downstream of that.
Here's the order we work in for a 10 to 100 person tenant:
| Action | What it stops | Licensing needed |
|---|---|---|
| MFA on every account, admins first | Password-only account takeover | Any Microsoft 365 plan |
| Block legacy authentication | The bypass that makes MFA optional without telling you | Any plan (Security Defaults or Conditional Access) |
| Restrict user consent to apps | OAuth consent phishing, which walks straight past MFA | Any plan |
| Limit Global Admins to two to four, named | Blast radius when one admin is compromised | Any plan; PIM needs Entra ID P2 |
| Safe Links and Safe Attachments for everyone | Malicious URLs and attachments, including delayed weaponization | Business Premium or Defender for Office P1 |
| Unified audit log and mailbox auditing | Nothing — but it's how you reconstruct a breach | Any plan |
Notice what's missing: nothing here requires a new product. These are settings you already own.
Two of these have dedicated walkthroughs if you want the detail — our guides to OAuth consent phishing and rolling out PIM without locking yourself out.
Does Secure Score mean I'm secure?
No. Secure Score measures configuration inside Microsoft's cloud. It doesn't see your firewall, your backups, your network segmentation, your unpatched line-of-business server, or whether anyone would notice an alert at 2am on a Saturday.
A tenant at 70% with no monitoring and no tested restore is in worse shape than one at 50% with both. Treat the score as one instrument on the dashboard, not the dashboard.
If you want a configuration standard that goes deeper than Secure Score, the CIS Microsoft 365 Benchmark is free and far more prescriptive. It's also a lot more work.
Cyber insurers and compliance auditors increasingly ask for Secure Score screenshots. That's a fine reason to keep it healthy. It's a bad reason to let it define your security program.
How do I improve my Secure Score without breaking things?
Change one thing at a time and pilot it. Conditional access policies in particular should go out in report-only mode first, run for a week, then enforce. The portal shows you exactly who would have been blocked.
Do the identity work first, mail flow second, device and data controls third. Re-check the score monthly, not daily — you'll only frustrate yourself watching a number that syncs on its own schedule.
And write down what you skipped and why. Six months from now, when an auditor or an insurer asks about the twelve open recommendations, "we accepted that risk because X" is an answer. "We don't know" isn't.
Frequently asked questions
Do I have to pay extra for Microsoft Secure Score?
No. Secure Score comes with access to the Microsoft Defender portal, which is included with Microsoft 365 business and enterprise subscriptions. What costs money is acting on some of the recommendations, because a portion of them require licensing you may not hold.
How often does Microsoft Secure Score update?
The score updates in real time when you make a change, and syncs daily for system data on achieved points. Entra ID recommendations refresh about once a week and Teams recommendations about once a month, so identity and Teams changes can take several days to appear in the score.
Can I get to 100% Secure Score?
Not realistically, and you shouldn't try. The score includes recommendations for licenses you don't own and products you don't use, and some actions would break normal business workflows. A well-configured small business tenant with every practical control turned on still leaves points on the table.
Does Secure Score affect cyber insurance?
Indirectly. Insurers don't underwrite on the score itself, but they ask about the controls behind it — MFA coverage, admin counts, email filtering, logging. A healthy Secure Score usually means those answers are already yes. See our guide to cyber insurance requirements for small business.
Who should own Secure Score in a small company?
One named person, usually your IT provider, with a monthly review and a short written record of what changed. Left unowned, the score drifts down as Microsoft adds recommendations and your configuration ages. Ownership matters more than frequency.
Where to start
Open the portal and look at your identity recommendations. If MFA isn't at 100% coverage and legacy authentication is still allowed, you've found your next two weeks of work.
If you'd rather have someone else read the list and tell you what's real, book a complimentary security assessment. We'll go through your tenant, separate the recommendations that matter from the ones that don't, and hand you the short list. You can also see how we approach this in our managed security services.
Joel Baum leads cybersecurity at The NetSys Group, which has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Discuss microsoft 365 management & backup for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



