Your score counts recommendations for licences you do not own, which is why it looks worse than you are.
Microsoft shows the full set of possible recommendations for a product regardless of which edition you hold, so part of every score is unreachable without buying something. Understanding that, and knowing which points are genuinely worth chasing, is the difference between improving security and improving a number.

- 10 pointsMaximum for any single action
- 17 productsIncluding Okta, Salesforce and Zoom
- Partial creditProportional to users or devices covered
- BenchmarkedCompared against similar organisations
Four reasons a Secure Score target is a bad objective.
We work on Secure Score in almost every Microsoft engagement, and we advise against making the number itself the goal. Here is why.
- Part of your score is unreachable without buying licences. Microsoft shows recommendations for the full product regardless of the edition you own, deliberately, so best practice is visible. A target that treats those points as achievable is a target that can only be hit by spending money you may not need to spend.
- Points are not weighted by your actual risk. Every action is worth ten or fewer points regardless of whether it addresses the thing most likely to hurt your organisation. Two easy configuration changes can outscore the single control that would genuinely have stopped last year incident.
- Microsoft says it directly: security should be balanced with usability, and not every recommendation can work for your environment. Some recommendations are wrong for your business, and applying them to gain points is a worse outcome than accepting the risk and recording why.
- The number is not a breach probability. Microsoft states it is not an absolute measurement of how likely you are to be breached and should not be interpreted as a guarantee in any manner. Presented to a board without that caveat, it produces false confidence, which is worse than no number at all.
Eight things about Secure Score that change how you should read it.
It counts recommendations you cannot act on
Microsoft states that it shows the full set of possible recommendations for a product regardless of licence edition, subscription or plan, and that your absolute security posture as represented by the score stays the same no matter which licences you own. That is deliberate and defensible, and it means a portion of every organisation score is unreachable without a purchase. Reading the score without knowing that leads to bad decisions in both directions.
Ten points maximum, and most actions are all or nothing
Each recommended action is worth ten points or less and most are scored in a binary fashion: implement it and you get the full value, do not and you get none. Some award partial credit proportional to coverage. Microsoft example is multifactor authentication worth ten points where fifty of one hundred users are protected, which yields five. That maths is why partial rollouts show up as partial scores.
Seventeen products, and seven of them are not Microsoft
The published list covers Microsoft Entra ID, Exchange Online, SharePoint Online, Teams, Purview Information Protection, App governance and the Defender family, and also Okta, Salesforce, ServiceNow, GitHub, Zoom, Docusign and Citrix ShareFile. Most organisations have no idea their Salesforce or Okta configuration is being assessed here, and those recommendations are frequently the ones nobody has ever looked at.
Non-Microsoft solutions can claim the points
Points are awarded for configuring recommended features, for doing security-related tasks, and explicitly for addressing a recommended action with a non-Microsoft application or an alternate mitigation. So an organisation using a third-party product to solve a problem can record that and stop losing points for it. Most organisations never do this, which understates their score and makes the trend meaningless.
Security defaults award specific, published point values
Turning on security defaults in Microsoft Entra ID awards full points for three named actions: ensuring all users can complete multifactor authentication, worth nine points, requiring multifactor authentication for administrative roles, worth ten, and enabling a policy to block legacy authentication, worth seven. For a small organisation without Conditional Access, that is twenty six points and a genuine security improvement from one change.
Accepting a risk is a legitimate answer
Where an action cannot or should not be applied, you can accept the risk or the remaining risk rather than leaving it open. Microsoft also advises that where security defaults are enabled, sign-in risk and user risk policy recommendations should be marked as resolved through alternative mitigation rather than configured on top. Recording those decisions is what turns the score into an honest posture statement.
Benchmarking against organisations like yours
Alongside metrics and trends, the score can be compared against similar organisations. That is more useful than the absolute number, because it answers the question a board actually asks, which is not what our score is but whether it is normal for a business of our size and sector. It also removes some of the distortion from unreachable licence-dependent points.
Microsoft says explicitly that it is not a breach probability
Microsoft states that Secure Score is not an absolute measurement of how likely your system or data could be breached, that it represents the extent to which you are using security controls that can help offset that risk, and that it should not be interpreted as a guarantee against breach in any manner. Anybody presenting a score to a board as a risk rating is misrepresenting what it is.
Four things we do differently with Secure Score.
We separate the reachable points from the rest before doing anything
Because Microsoft shows recommendations for the full product regardless of the edition you hold, part of your score is only available by purchasing something. We identify that portion first, so the target you set is achievable on what you already own and any licence conversation is a separate, explicit decision rather than a hidden condition of hitting a number.
We order by risk reduction, not by points per hour of effort
Every action is worth ten points or fewer regardless of how much risk it addresses, so optimising for points optimises for the wrong thing. We rank by what would actually change the outcome of a realistic attack on your organisation, then note the point value, rather than the other way round.
We check the products nobody knows are assessed
Okta, Salesforce, ServiceNow, GitHub, Zoom, Docusign and Citrix ShareFile all appear in the covered product list. These recommendations are almost always untouched, they cover systems holding customer data, contracts and source code, and they represent some of the easiest genuine improvements available in most tenants.
We record risk acceptance rather than leaving items open
Microsoft says security should be balanced with usability and not every recommendation works for every environment, and it provides statuses for accepting risk and for resolution through alternative mitigation. Recording those decisions turns the score into an honest posture statement and gives an auditor something far better than an open item with no explanation.
Six UAE situations where working the score properly pays off.
A board that has started asking for a security metric
Secure Score is the most available number in a Microsoft estate, which is why it ends up in board packs. Presented properly, with the benchmark against similar organisations, the trend, and Microsoft own statement that it is not a breach probability, it is a reasonable indicator. Presented as a risk rating, it produces false confidence, and that is worse than no metric.
An organisation on E5 using a fraction of it
The most common situation we find. Recommendations appear for the whole Defender family, Purview, Entra and more, and a large proportion are unactioned simply because nobody knew the capability was included. Here the score is genuinely low for the right reason, and working it delivers real security improvement on licensing already paid for.
A mixed estate with Okta or Salesforce alongside Microsoft
Recommendations for Okta, Salesforce, ServiceNow, GitHub, Zoom and Docusign exist and are almost never reviewed, because nobody expects a Microsoft dashboard to assess them. For organisations that ended up with a mixed identity or SaaS estate through acquisition, this is a fast route to findings about the systems that were governed least.
A small organisation with no Conditional Access
Security defaults award full points for three named actions worth twenty six points in total, and more importantly they deliver multifactor authentication for all users, multifactor authentication for administrators and blocking of legacy authentication. For a business without the licensing or capacity for Conditional Access, that single change is the highest-value security action available.
An organisation answering a client security questionnaire
Enterprise clients increasingly ask suppliers to evidence their security posture. A Secure Score with a documented trend, recorded risk acceptances and non-Microsoft mitigations noted answers a great deal of a questionnaire directly, and it does so with vendor-generated evidence rather than self-assertion.
An organisation where the score went up and then drifted back
A recognisable pattern. A project raises the score, the project ends, nobody owns it, new users are added without controls and configurations get relaxed for a business reason nobody recorded. The fix is ownership and a review rhythm rather than another remediation project, and that is a cheaper conversation than the second project.
How organisations actually use their Secure Score.
| Feature | Score read properly | Chasing the number | Never looked |
|---|---|---|---|
Unreachable licence-dependent points identified | Yes | No | No |
Non-Microsoft mitigations recorded | Yes | No | No |
Risk acceptance documented where appropriate | Yes | No | No |
Actions prioritised by risk, not by points | Yes | No | No |
Non-Microsoft product recommendations reviewed | Yes | Rarely | No |
Benchmarked against similar organisations | Yes | Sometimes | No |
Trend tracked over time with an owner | Yes | Sometimes | No |
Presented to leadership with its limitations stated | Yes | No | Not applicable |
Usability weighed against each recommendation | Yes | No | Not applicable |
Frequency in the UAE market | Uncommon | Common | Common in SMEs |
The seventeen products currently covered.
| Product | Commonly overlooked | |
|---|---|---|
| Microsoft Entra ID | No, this is where most attention goes | |
| Exchange Online | No, usually reviewed | |
| SharePoint Online | Partly, sharing settings often untouched | |
| Microsoft Teams | Yes, and the state refreshes only monthly | |
| Defender for Endpoint, Identity and Office | Partly, depends what is deployed | |
| Defender for Cloud Apps and App governance | Yes, OAuth recommendations rarely actioned | |
| Purview Information Protection | Yes, where labelling has never been deployed | |
| Okta | Yes, most organisations do not know it is assessed | |
| Salesforce | Yes, and it holds customer data | |
| ServiceNow | Yes, and it holds a great deal of operational detail | |
| GitHub | Yes, and it holds your code and secrets | |
| Zoom | Yes, essentially never reviewed | |
| Docusign | Yes, and it holds executed contracts | |
| Citrix ShareFile | Yes, where it is still in use |
Five steps, and the first is establishing what the number means.
- 1
Establish the honest baseline
Current score, the portion of it that is unreachable on your current licences, the benchmark against similar organisations, and the trend if any history exists. This is the step that stops the whole exercise being built on a misreading of the number.
- 2
Claim the points you have already earned
Recording non-Microsoft applications and alternate mitigations that already address recommendations, and accepting risk where an action genuinely does not fit your environment. This usually moves the score before any configuration changes, and it makes the remaining gap an honest one.
- 3
Work the high-risk actions, in risk order
Ranked by what would actually change the outcome of a realistic attack rather than by point value or ease. Where security defaults are appropriate and Conditional Access is not in place, that single change addresses multifactor authentication for users and administrators and blocks legacy authentication.
- 4
Review the products nobody has looked at
Okta, Salesforce, ServiceNow, GitHub, Zoom, Docusign and Citrix ShareFile recommendations, plus Teams and SharePoint sharing settings. These are almost always untouched and frequently produce the most surprising findings relative to how little effort they take.
- 5
Assign ownership and set the review rhythm
Who owns the score, who may change action statuses, which permissions model you use, and how often it is reviewed. Scores that improve during a project and then drift back are the normal outcome without an owner, and that is a governance fix rather than a technical one.
What organisations ask about Microsoft Secure Score.
Fifteen questions worth answering first.
What your score means
- Do you know which points are unreachable on your licences?Recommendations show regardless of edition owned.
- Have you recorded non-Microsoft mitigations?Points are available for them and are usually unclaimed.
- Have you accepted risk where an action does not apply?A legitimate status, not a failure.
- Do you know your benchmark against similar organisations?More useful than the absolute number.
- Is anybody presenting this to a board as a risk rating?Microsoft says explicitly that it is not one.
Where the real points are
- Are security defaults on, or Conditional Access configured?Defaults award 26 points across three actions.
- Is legacy authentication blocked?Seven points, and a genuine risk reduction.
- What proportion of users have MFA?Partial credit is proportional to coverage.
- Have you looked at the non-Microsoft product recommendations?Okta, Salesforce, GitHub, Zoom and others.
- Are Defender recommendations being worked?They appear whether or not the product is deployed.
Governance
- Who owns the score?Without an owner it drifts back within two quarters.
- How often is it reviewed?It updates in real time and syncs daily.
- Who has permission to change action statuses?Read and write is a narrow set of roles.
- Are you using Defender Unified RBAC or Entra roles?Unified RBAC is Defender portal only for now.
- Is the trend reported anywhere?The trend matters more than any single reading.
The pages around this one.
Microsoft 365 security audit
The independent assessment that covers what the score cannot see and weighs findings against your actual business risk.
Conditional Access
The alternative to security defaults for organisations that need finer control, and where most of the identity points live.
Defender for Cloud
The Azure-side posture score, which is a separate secure score covering cloud resources rather than Microsoft 365.
Ask what proportion of your score you can actually reach.
It is the first question worth answering and almost nobody has. Once you know which points are available on the licences you already hold, the target becomes achievable and any licensing conversation becomes an explicit decision rather than a hidden condition.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Entra Conditional Access
The control that decides who reaches your data
Defender for Cloud
Azure posture, and the free tier almost nobody has enabled
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
MFA Solutions
Entra MFA, passwordless, FIDO2
Defender for Endpoint
Business, Plan 1 or Plan 2, and what each actually gives you
M365 Licensing
Optimize your Microsoft 365 licensing costs
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly