11.1 Security Exposure Management & Secure Score

Key Takeaways

  • Microsoft Security Exposure Management provides an organization-wide view of attack surface and security posture across Microsoft security products, including attack paths, business-critical assets, and a security posture score
  • Microsoft Secure Score is a numeric measurement of configuration posture built from improvement actions (e.g., enable MFA, block legacy authentication, require compliant devices) — it is not the same as Exposure Management's attack-surface mapping
  • Secure Score surfaces a target score and a comparison against similar-sized organizations so administrators can prioritize the highest-value remediation work
  • Exposure Management correlates signals from Defender for Endpoint, Defender for Cloud Apps, Defender for Identity, Entra ID, and other sources to expose multi-stage attack paths that single-product views miss
  • Use Secure Score to prioritize configuration remediation and Exposure Management to understand how those misconfigurations chain into exploitable attack paths
Last updated: August 2026

Quick Answer: Microsoft Security Exposure Management gives you an organization-wide view of your attack surface and attack paths across Microsoft security products. Microsoft Secure Score is a numeric measurement of your security configuration posture built from improvement actions. MS-102 administrators use Exposure Management to see how an attacker could move and Secure Score to decide what to fix first.

Domain 3 of the MS-102 exam expects you to know how to review and respond to security posture findings produced by Microsoft's XDR stack. Two tools dominate this objective: Microsoft Security Exposure Management and Microsoft Secure Score. They are complementary, not redundant, and the exam will test whether you can tell them apart.

Microsoft Security Exposure Management

Microsoft Security Exposure Management is a posture and attack-surface solution that aggregates signals from across the Microsoft security ecosystem to give administrators a single, organization-wide view of exposure. Rather than looking at one product's alerts, it correlates asset inventory, identity, device, email, cloud app, and network signals to answer a question that no single Defender product can answer alone: how could an attacker actually chain our misconfigurations into a breach?

Core Capabilities

  • Attack surface mapping — inventories devices, identities, applications, cloud resources, and unmanaged assets that surface in telemetry, then maps the relationships between them.
  • Attack paths — visualizes multi-hop routes an attacker could take from an initial foothold to a business-critical asset (for example, a compromised low-privilege account → a stale local admin on a jump box → Domain Admin).
  • Business-critical assets — lets administrators tag crown-jewel assets so that attack paths are scored against what actually matters to the business.
  • Security posture score — a measurement of exposure across the mapped assets, broken down by initiative (data security, identity posture, device posture, app posture) so you can see where the gaps are.
  • Streamlined correlation — pulls signals from Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Entra ID, Microsoft Defender for Cloud, and other connected sources.

How Administrators Use Exposure Management

A typical workflow is: open the Exposure Management dashboard in the Microsoft Defender portal, review the attack paths view to find the cheapest route to a tagged business-critical asset, drill into the contributing findings, and assign remediation. Because attack paths are recomputed as telemetry changes, you can verify after remediation that the path is broken — not just that a single alert was closed.

Microsoft Secure Score

Microsoft Secure Score is a numeric measurement of an organization's security configuration posture. It is built from a catalog of improvement actions, each worth a defined number of points. Examples of common high-value actions include:

  • Require multi-factor authentication for all users
  • Block legacy authentication
  • Require compliant devices (Microsoft Intune) for access
  • Enable Microsoft Defender for Endpoint on supported devices
  • Apply mailbox policies that block known malware and phishing patterns

The Secure Score dashboard shows your current score, your target score (the realistic maximum after accounting for actions you've chosen to accept the risk on), and a comparison against similar organizations so you can benchmark. Each improvement action lists the points available, the effort to implement, and a link to the configuration experience in the relevant product.

Secure Score vs. Exposure Management — the distinction that the exam tests

Secure ScoreExposure Management
What it measuresConfiguration posture against a catalog of best-practice actionsThe live attack surface and how misconfigurations chain into attack paths
Unit of workA single improvement action worth N pointsAn attack path, a business-critical asset, an initiative score
Source of signalConfiguration state of Microsoft servicesCorrelated telemetry and inventory across Microsoft security products
Primary usePrioritize and track remediation of known misconfigurationsUnderstand and break the routes an attacker could actually take

A useful way to remember the split: Secure Score tells you that MFA is not enforced on 40 accounts; Exposure Management shows you that one of those 40 accounts is the first hop on an attack path to a Domain Admin credential.

Responding to Findings

For both tools, "review and respond" means more than reading a dashboard:

  1. Triage — use severity and the affected business-critical asset to decide what to address first.
  2. Assign — route the remediation task to the correct team (identity, endpoint, compliance) through Microsoft Defender or the integration with Microsoft Entra and Intune.
  3. Remediate — apply the configuration change the improvement action or attack-path finding recommends.
  4. Verify — confirm the score moved and, for Exposure Management, that the attack path no longer resolves.
  5. Report — use the score trend and attack-path reduction over time to report posture improvements to stakeholders.

Microsoft publishes Secure Score improvement actions and their point values on a rolling basis; the catalog changes as new controls are added, so the MS-102 exam does not expect you to memorize exact point values. Focus on what the score represents and how an administrator uses it to prioritize work.

Test Your Knowledge

What is the key difference between Microsoft Secure Score and Microsoft Security Exposure Management?

A
B
C
D
Test Your Knowledge

An administrator sees that one of 40 accounts without MFA is the first hop on a path to a Domain Admin credential. Which tool surfaced this finding?

A
B
C
D
Test Your Knowledge

Which comparison does the Microsoft Secure Score dashboard provide to help administrators prioritize remediation?

A
B
C
D