Microsoft Secure Score is a percentage grade of your Microsoft 365 security configuration, built into every tenant and updated continuously. It measures how many of Microsoft’s recommended protections you have adopted, ranks what to fix next, and is increasingly the number insurers, auditors, and larger clients ask about. If your business runs on Microsoft 365, you already have one; most owners have simply never opened the page it lives on.

It is also one of the few security measurements a non-technical owner can actually use, which is why it is worth the five minutes this guide takes to explain.

What Secure Score actually is

The score lives in the Microsoft Defender portal at security.microsoft.com, and it works like a points system: every recommended security control is worth points, and your score is the percentage of available points you have earned.

The recommendations span four areas:

  • Identity: user accounts, admin roles, and sign-in protections in Microsoft Entra
  • Devices: the security state of enrolled computers
  • Apps: email and cloud app protections, including Office 365
  • Data: information protection controls

Some actions score all-or-nothing (a setting is either on or off). Others give partial credit: if 5 of your 100 users have multi-factor authentication, you get 5% of the points that MFA coverage is worth. That detail matters, because it means the score rewards coverage, not intentions. An MFA rollout that quietly stalled at the sales team shows up in the number.

The score also adjusts to what you own. The total available points reflect your current licenses, and controls you have covered with a non-Microsoft tool can be marked as resolved through a third party so the score credits them.

Why the number is worth your attention

It is objective. Most small businesses assess their security by feel: no incidents lately, IT seems on top of things, probably fine. Secure Score replaces that with a measurement taken directly from your live configuration. It does not care how busy the quarter was.

Outsiders use it as a proxy. Cyber-insurance underwriters, compliance auditors, and larger clients doing vendor due diligence increasingly ask about Microsoft 365 configuration, and Secure Score is the fastest evidence available. A business that can say “we hold our score above target and review the recommendations monthly” has an answer most competitors do not.

It is a prioritized roadmap, not just a grade. The Recommended actions tab ranks improvements by points remaining, implementation difficulty, and user impact. The ranking is not perfect, but it turns “improve our security” from an open-ended anxiety into a sequenced list, and completed work shows up in the score within a day or two.

It benchmarks you. The portal compares your score against organizations of similar size, which answers the question owners actually ask: are we behind?

What the score does not tell you

Microsoft is candid about the limits, and you should be too.

It is not a breach probability. The score measures how many risk-offsetting features you have adopted. It says nothing about whether tonight’s phishing email gets clicked. A 90% tenant with an untrained team can still lose a wire transfer.

It can be gamed. Some points come from low-value actions, and a score can be inflated by chasing easy points while the important identity controls stay red. This is why Microsoft’s own guidance says to focus on high-importance recommendations rather than the number itself.

Not every recommendation fits every business. Security trades against usability, and the scoring system acknowledges it: you can formally mark a recommendation as “risk accepted” when it genuinely does not fit. A deliberate, documented exception is healthy. Twenty silent red items nobody has reviewed is not.

It only sees Microsoft’s world. Your firewall, your backups, your line-of-business apps, and your staff’s judgment are all outside the frame. The score is one instrument on the dashboard, not the whole dashboard.

What typically moves the score most

In the small-business tenants we review, the same handful of identity actions usually holds the most unclaimed points, and they are also the controls that stop the most real-world attacks:

  1. MFA for everyone, not just admins, and enforced rather than optional
  2. Legacy authentication blocked, since older sign-in protocols bypass MFA entirely
  3. Admin role hygiene: few global admins, separate admin accounts, no daily driving with elevated rights
  4. Conditional access policies that challenge risky sign-ins
  5. Device enrollment, so laptops are actually visible to the tooling that grades them

None of these requires new licensing in a typical Microsoft 365 Business Premium tenant. They require someone to do the work carefully, in the right order, without locking the CEO out of email on a Tuesday.

How to check yours

If you have admin access, go to security.microsoft.com/securescore and look at three things: the percentage, the comparison line against similar organizations, and the top five recommended actions. That five-minute look tells you more about your Microsoft 365 security than most annual reviews.

If you do not have admin access, ask whoever does for those three things. The quality of the answer is itself a signal.

And if the honest answer is that nobody has ever opened that page, that is a normal place to start and a fixable one. Reviewing and working the Secure Score backlog is part of how we run Microsoft 365 tenants, and it connects to the broader security program for businesses that need the full dashboard, not just the Microsoft corner of it. Get in touch and we will tell you where your tenant stands.