We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Secure Score
Microsoft Secure Score, UAE

Your score counts recommendations for licences you do not own, which is why it looks worse than you are.

Microsoft shows the full set of possible recommendations for a product regardless of which edition you hold, so part of every score is unreachable without buying something. Understanding that, and knowing which points are genuinely worth chasing, is the difference between improving security and improving a number.

Book a Secure Score reviewSee how it is calculated
Microsoft Secure Score improvement for UAE organisations
  • 10 pointsMaximum for any single action
  • 17 productsIncluding Okta, Salesforce and Zoom
  • Partial creditProportional to users or devices covered
  • BenchmarkedCompared against similar organisations
Read this before you set a target

Four reasons a Secure Score target is a bad objective.

We work on Secure Score in almost every Microsoft engagement, and we advise against making the number itself the goal. Here is why.

  • Part of your score is unreachable without buying licences. Microsoft shows recommendations for the full product regardless of the edition you own, deliberately, so best practice is visible. A target that treats those points as achievable is a target that can only be hit by spending money you may not need to spend.
  • Points are not weighted by your actual risk. Every action is worth ten or fewer points regardless of whether it addresses the thing most likely to hurt your organisation. Two easy configuration changes can outscore the single control that would genuinely have stopped last year incident.
  • Microsoft says it directly: security should be balanced with usability, and not every recommendation can work for your environment. Some recommendations are wrong for your business, and applying them to gain points is a worse outcome than accepting the risk and recording why.
  • The number is not a breach probability. Microsoft states it is not an absolute measurement of how likely you are to be breached and should not be interpreted as a guarantee in any manner. Presented to a board without that caveat, it produces false confidence, which is worse than no number at all.
How the score actually works

Eight things about Secure Score that change how you should read it.

Microsoft describes it as a measurement of your security posture where a higher number means more recommended actions taken. The mechanics underneath are more interesting than the number, and most organisations act on the number without knowing them.

It counts recommendations you cannot act on

Microsoft states that it shows the full set of possible recommendations for a product regardless of licence edition, subscription or plan, and that your absolute security posture as represented by the score stays the same no matter which licences you own. That is deliberate and defensible, and it means a portion of every organisation score is unreachable without a purchase. Reading the score without knowing that leads to bad decisions in both directions.

Ten points maximum, and most actions are all or nothing

Each recommended action is worth ten points or less and most are scored in a binary fashion: implement it and you get the full value, do not and you get none. Some award partial credit proportional to coverage. Microsoft example is multifactor authentication worth ten points where fifty of one hundred users are protected, which yields five. That maths is why partial rollouts show up as partial scores.

Seventeen products, and seven of them are not Microsoft

The published list covers Microsoft Entra ID, Exchange Online, SharePoint Online, Teams, Purview Information Protection, App governance and the Defender family, and also Okta, Salesforce, ServiceNow, GitHub, Zoom, Docusign and Citrix ShareFile. Most organisations have no idea their Salesforce or Okta configuration is being assessed here, and those recommendations are frequently the ones nobody has ever looked at.

Non-Microsoft solutions can claim the points

Points are awarded for configuring recommended features, for doing security-related tasks, and explicitly for addressing a recommended action with a non-Microsoft application or an alternate mitigation. So an organisation using a third-party product to solve a problem can record that and stop losing points for it. Most organisations never do this, which understates their score and makes the trend meaningless.

Security defaults award specific, published point values

Turning on security defaults in Microsoft Entra ID awards full points for three named actions: ensuring all users can complete multifactor authentication, worth nine points, requiring multifactor authentication for administrative roles, worth ten, and enabling a policy to block legacy authentication, worth seven. For a small organisation without Conditional Access, that is twenty six points and a genuine security improvement from one change.

Accepting a risk is a legitimate answer

Where an action cannot or should not be applied, you can accept the risk or the remaining risk rather than leaving it open. Microsoft also advises that where security defaults are enabled, sign-in risk and user risk policy recommendations should be marked as resolved through alternative mitigation rather than configured on top. Recording those decisions is what turns the score into an honest posture statement.

Benchmarking against organisations like yours

Alongside metrics and trends, the score can be compared against similar organisations. That is more useful than the absolute number, because it answers the question a board actually asks, which is not what our score is but whether it is normal for a business of our size and sector. It also removes some of the distortion from unreachable licence-dependent points.

Microsoft says explicitly that it is not a breach probability

Microsoft states that Secure Score is not an absolute measurement of how likely your system or data could be breached, that it represents the extent to which you are using security controls that can help offset that risk, and that it should not be interpreted as a guarantee against breach in any manner. Anybody presenting a score to a board as a risk rating is misrepresenting what it is.

How we approach it

Four things we do differently with Secure Score.

Working a Secure Score is easy to do badly, and a consultancy paid to raise a number has an incentive to raise it the cheapest way rather than the most useful way.

We separate the reachable points from the rest before doing anything

Because Microsoft shows recommendations for the full product regardless of the edition you hold, part of your score is only available by purchasing something. We identify that portion first, so the target you set is achievable on what you already own and any licence conversation is a separate, explicit decision rather than a hidden condition of hitting a number.

We order by risk reduction, not by points per hour of effort

Every action is worth ten points or fewer regardless of how much risk it addresses, so optimising for points optimises for the wrong thing. We rank by what would actually change the outcome of a realistic attack on your organisation, then note the point value, rather than the other way round.

We check the products nobody knows are assessed

Okta, Salesforce, ServiceNow, GitHub, Zoom, Docusign and Citrix ShareFile all appear in the covered product list. These recommendations are almost always untouched, they cover systems holding customer data, contracts and source code, and they represent some of the easiest genuine improvements available in most tenants.

We record risk acceptance rather than leaving items open

Microsoft says security should be balanced with usability and not every recommendation works for every environment, and it provides statuses for accepting risk and for resolution through alternative mitigation. Recording those decisions turns the score into an honest posture statement and gives an auditor something far better than an open item with no explanation.

Where this matters most

Six UAE situations where working the score properly pays off.

The common factor is either a board that has started asking for a security number, or an organisation that owns considerably more security capability than it has configured.

A board that has started asking for a security metric

Secure Score is the most available number in a Microsoft estate, which is why it ends up in board packs. Presented properly, with the benchmark against similar organisations, the trend, and Microsoft own statement that it is not a breach probability, it is a reasonable indicator. Presented as a risk rating, it produces false confidence, and that is worse than no metric.

An organisation on E5 using a fraction of it

The most common situation we find. Recommendations appear for the whole Defender family, Purview, Entra and more, and a large proportion are unactioned simply because nobody knew the capability was included. Here the score is genuinely low for the right reason, and working it delivers real security improvement on licensing already paid for.

A mixed estate with Okta or Salesforce alongside Microsoft

Recommendations for Okta, Salesforce, ServiceNow, GitHub, Zoom and Docusign exist and are almost never reviewed, because nobody expects a Microsoft dashboard to assess them. For organisations that ended up with a mixed identity or SaaS estate through acquisition, this is a fast route to findings about the systems that were governed least.

A small organisation with no Conditional Access

Security defaults award full points for three named actions worth twenty six points in total, and more importantly they deliver multifactor authentication for all users, multifactor authentication for administrators and blocking of legacy authentication. For a business without the licensing or capacity for Conditional Access, that single change is the highest-value security action available.

An organisation answering a client security questionnaire

Enterprise clients increasingly ask suppliers to evidence their security posture. A Secure Score with a documented trend, recorded risk acceptances and non-Microsoft mitigations noted answers a great deal of a questionnaire directly, and it does so with vendor-generated evidence rather than self-assertion.

An organisation where the score went up and then drifted back

A recognisable pattern. A project raises the score, the project ends, nobody owns it, new users are added without controls and configurations get relaxed for a business reason nobody recorded. The fix is ownership and a review rhythm rather than another remediation project, and that is a cheaper conversation than the second project.

Three positions

How organisations actually use their Secure Score.

The middle column, chasing the number, is more common than doing nothing and can be actively harmful, because it prioritises whatever is easy to score rather than whatever reduces risk.
Unreachable licence-dependent points identified
Score read properlyYes
Chasing the numberNo
Never lookedNo
Non-Microsoft mitigations recorded
Score read properlyYes
Chasing the numberNo
Never lookedNo
Risk acceptance documented where appropriate
Score read properlyYes
Chasing the numberNo
Never lookedNo
Actions prioritised by risk, not by points
Score read properlyYes
Chasing the numberNo
Never lookedNo
Non-Microsoft product recommendations reviewed
Score read properlyYes
Chasing the numberRarely
Never lookedNo
Benchmarked against similar organisations
Score read properlyYes
Chasing the numberSometimes
Never lookedNo
Trend tracked over time with an owner
Score read properlyYes
Chasing the numberSometimes
Never lookedNo
Presented to leadership with its limitations stated
Score read properlyYes
Chasing the numberNo
Never lookedNot applicable
Usability weighed against each recommendation
Score read properlyYes
Chasing the numberNo
Never lookedNot applicable
Frequency in the UAE market
Score read properlyUncommon
Chasing the numberCommon
Never lookedCommon in SMEs
Feature
Score read properly
Chasing the number
Never looked
Unreachable licence-dependent points identified
YesNoNo
Non-Microsoft mitigations recorded
YesNoNo
Risk acceptance documented where appropriate
YesNoNo
Actions prioritised by risk, not by points
YesNoNo
Non-Microsoft product recommendations reviewed
YesRarelyNo
Benchmarked against similar organisations
YesSometimesNo
Trend tracked over time with an owner
YesSometimesNo
Presented to leadership with its limitations stated
YesNoNot applicable
Usability weighed against each recommendation
YesNoNot applicable
Frequency in the UAE market
UncommonCommonCommon in SMEs
What is assessed

The seventeen products currently covered.

Reproduced from the Microsoft list. The non-Microsoft entries are the ones worth checking first, because almost nobody knows those recommendations exist and they are frequently untouched.
ProductCommonly overlooked
Microsoft Entra IDNo, this is where most attention goes
Exchange OnlineNo, usually reviewed
SharePoint OnlinePartly, sharing settings often untouched
Microsoft TeamsYes, and the state refreshes only monthly
Defender for Endpoint, Identity and OfficePartly, depends what is deployed
Defender for Cloud Apps and App governanceYes, OAuth recommendations rarely actioned
Purview Information ProtectionYes, where labelling has never been deployed
OktaYes, most organisations do not know it is assessed
SalesforceYes, and it holds customer data
ServiceNowYes, and it holds a great deal of operational detail
GitHubYes, and it holds your code and secrets
ZoomYes, essentially never reviewed
DocusignYes, and it holds executed contracts
Citrix ShareFileYes, where it is still in use
How a review runs

Five steps, and the first is establishing what the number means.

Typically two to four weeks for the review and initial remediation. The ongoing rhythm matters more than the initial improvement, because scores drift.
  1. 1

    Establish the honest baseline

    Current score, the portion of it that is unreachable on your current licences, the benchmark against similar organisations, and the trend if any history exists. This is the step that stops the whole exercise being built on a misreading of the number.

  2. 2

    Claim the points you have already earned

    Recording non-Microsoft applications and alternate mitigations that already address recommendations, and accepting risk where an action genuinely does not fit your environment. This usually moves the score before any configuration changes, and it makes the remaining gap an honest one.

  3. 3

    Work the high-risk actions, in risk order

    Ranked by what would actually change the outcome of a realistic attack rather than by point value or ease. Where security defaults are appropriate and Conditional Access is not in place, that single change addresses multifactor authentication for users and administrators and blocks legacy authentication.

  4. 4

    Review the products nobody has looked at

    Okta, Salesforce, ServiceNow, GitHub, Zoom, Docusign and Citrix ShareFile recommendations, plus Teams and SharePoint sharing settings. These are almost always untouched and frequently produce the most surprising findings relative to how little effort they take.

  5. 5

    Assign ownership and set the review rhythm

    Who owns the score, who may change action statuses, which permissions model you use, and how often it is reviewed. Scores that improve during a project and then drift back are the normal outcome without an owner, and that is a governance fix rather than a technical one.

Straight answers

What organisations ask about Microsoft Secure Score.

Most often because Microsoft shows the full set of possible recommendations for a product regardless of licence edition, subscription or plan, so recommendations you cannot act on without buying something still count against you. Microsoft states this is deliberate, so that best practice remains visible, and that your absolute posture as represented by the score stays the same whatever licences you own. Identifying that unreachable portion is the first thing we do.

There is no universal answer, and any consultant giving you a target percentage without knowing your licensing is guessing. The more useful comparison is the benchmark against similar organisations, which the product provides, and the trend over time. Both survive the licence distortion better than the absolute number, and both are more meaningful to a board than a percentage with no context.

Each recommended action is worth ten points or less, and most are scored in a binary fashion where implementing the action gives you the full value. Some award partial credit proportional to coverage. Microsoft worked example is a ten point multifactor authentication action where fifty of one hundred users are protected, which yields five points. That is why a partial rollout shows a partial score rather than nothing.

Yes, and almost nobody does it. Microsoft lists addressing a recommended action with a non-Microsoft application or software, or an alternate mitigation, as one of the three ways points are awarded. An organisation using a third-party product to solve a problem can record that against the relevant recommendation and stop losing points for it, which makes both the score and its trend honest.

Yes, and this surprises nearly everyone. The published list includes Okta, Salesforce, ServiceNow, GitHub, Zoom, Docusign and Citrix ShareFile alongside Entra ID, Exchange Online, SharePoint Online, Teams, Purview Information Protection, App governance and the Defender family. Those non-Microsoft recommendations cover systems holding customer data, contracts and source code, and in our experience they are almost never reviewed.

If you do not have Conditional Access configured, very probably. Microsoft states that enabling security defaults awards full points for three named actions: ensuring all users can complete multifactor authentication at nine points, requiring multifactor authentication for administrative roles at ten, and enabling a policy to block legacy authentication at seven. More importantly than the points, those are three of the highest-value controls available. Organisations using Conditional Access take a different route.

Accept the risk and record it. Microsoft states plainly that security should be balanced with usability and that not every recommendation can work for every environment, and it provides statuses for accepting risk or remaining risk and for resolution through alternative mitigation. Microsoft even advises specifically that where security defaults are enabled, sign-in risk and user risk policy recommendations should be marked as resolved through alternative mitigation rather than configured on top.

No, and Microsoft says so directly. It states that Secure Score is not an absolute measurement of how likely your system or data could be breached, that it represents the extent to which you are using security controls that can help offset that risk, that no online service is immune from breaches, and that the score should not be interpreted as a guarantee against breach in any manner. Anybody presenting it to a board as a risk rating is misrepresenting it.

The score updates in real time to reflect what is shown in the visualisations and recommended action pages, and also syncs daily to receive system data about achieved points. Two exceptions are worth knowing: Microsoft Teams recommendation state refreshes once a month, and Microsoft Entra recommendation state once a week, so a change in those areas will not appear immediately.

Microsoft recommends roles with the fewest permissions. With Defender Unified role-based access control there are dedicated permissions under the security posture category, named Exposure Management read and Exposure Management manage. Using Microsoft Entra roles instead, read and write access sits with Security Administrator or higher, Exchange Administrator and SharePoint Administrator, with read-only for several other roles including Security Reader and Global Reader.

Yes, through the Graph API, with one caveat worth planning around. Microsoft states that the Defender Unified role-based access control model is currently only supported in the Microsoft Defender portal, and that if you want to use the Graph API, for example for internal dashboards or Defender for Identity Secure Score, you should continue to use Microsoft Entra roles. Graph API support for the unified model is planned for a later date.

Secure Score is Microsoft own assessment against its own recommendations, and it is limited to what Microsoft can see and score. Our audit is independent, covers things the score does not, weighs findings against your actual business risk rather than a fixed point value, and produces a report written for your management rather than a dashboard. The two are complementary and we usually work the score as part of the audit.

Usually because the denominator moved rather than because you got worse. New users added without a control applied reduce a proportionally scored action. Microsoft adds new recommendations over time, which increases the total available. A licence or product change alters the recommendation set. This is exactly why the trend needs an owner who can explain movements, rather than a number reported without context.

Recording existing non-Microsoft mitigations and appropriate risk acceptances can move the score within days and costs nothing. Genuine configuration improvements take two to four weeks for the high-value items. The score continuing to hold is a longer question, because without an owner and a review rhythm most organisations see it drift back within two quarters.

We scope per organisation, driven by tenant size and whether you want the remediation delivered or just identified and prioritised. What we will tell you free in the first conversation is roughly what proportion of your score is unreachable on your current licensing, because that single fact changes how you should read the number and frequently changes the target somebody has already set.
Working the score properly

Fifteen questions worth answering first.

The first group establishes what your score actually means. The second is where the real points are. The third is governance, because a score with no owner drifts back down within two quarters.

What your score means

  • Do you know which points are unreachable on your licences?
    Recommendations show regardless of edition owned.
  • Have you recorded non-Microsoft mitigations?
    Points are available for them and are usually unclaimed.
  • Have you accepted risk where an action does not apply?
    A legitimate status, not a failure.
  • Do you know your benchmark against similar organisations?
    More useful than the absolute number.
  • Is anybody presenting this to a board as a risk rating?
    Microsoft says explicitly that it is not one.

Where the real points are

  • Are security defaults on, or Conditional Access configured?
    Defaults award 26 points across three actions.
  • Is legacy authentication blocked?
    Seven points, and a genuine risk reduction.
  • What proportion of users have MFA?
    Partial credit is proportional to coverage.
  • Have you looked at the non-Microsoft product recommendations?
    Okta, Salesforce, GitHub, Zoom and others.
  • Are Defender recommendations being worked?
    They appear whether or not the product is deployed.

Governance

  • Who owns the score?
    Without an owner it drifts back within two quarters.
  • How often is it reviewed?
    It updates in real time and syncs daily.
  • Who has permission to change action statuses?
    Read and write is a narrow set of roles.
  • Are you using Defender Unified RBAC or Entra roles?
    Unified RBAC is Defender portal only for now.
  • Is the trend reported anywhere?
    The trend matters more than any single reading.
Related reading

The pages around this one.

Microsoft 365 security audit

The independent assessment that covers what the score cannot see and weighs findings against your actual business risk.

Learn more

Conditional Access

The alternative to security defaults for organisations that need finer control, and where most of the identity points live.

Learn more

Defender for Cloud

The Azure-side posture score, which is a separate secure score covering cloud resources rather than Microsoft 365.

Learn more
Next step

Ask what proportion of your score you can actually reach.

It is the first question worth answering and almost nobody has. Once you know which points are available on the licences you already hold, the target becomes achievable and any licensing conversation becomes an explicit decision rather than a hidden condition.

Book a Secure Score reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Entra Conditional Access

The control that decides who reaches your data

Learn more

Defender for Cloud

Azure posture, and the free tier almost nobody has enabled

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

MFA Solutions

Entra MFA, passwordless, FIDO2

Learn more

Defender for Endpoint

Business, Plan 1 or Plan 2, and what each actually gives you

Learn more

M365 Licensing

Optimize your Microsoft 365 licensing costs

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy