11.2 Microsoft Secure Score

Key Takeaways

  • Microsoft Secure Score is a measurement of security posture: a higher number means more recommended improvement actions have been taken
  • It is not a pass/fail exam score, not a 700-point Microsoft certification result, and not the Microsoft Purview Compliance Manager compliance score
  • Recommended actions are grouped into Identity, Device, Apps, and Data and award points (typically 10 or fewer); some actions give partial points when only some users or devices are covered
  • You can compare your anonymized score with organizations that have a similar seat count and can mark an action as resolved through a third-party or alternate mitigation to receive the points
  • Secure Score reports how thoroughly you use Microsoft security controls; Microsoft is explicit that it is not a guarantee the tenant cannot be breached
Last updated: August 2026

Quick Answer: Microsoft Secure Score is a security posture number in the Microsoft Defender portal (https://security.microsoft.com/securescore). Higher is better because it means more recommended improvement actions are in place. It is not a pass/fail exam score and not the Microsoft Purview Compliance Manager compliance score. Actions cover identity, devices, apps, and data, can award partial points, and can be compared with similar organizations.

The April 30, 2025 MS-900 outline asks you to describe Microsoft Secure Score benefits and capabilities. This is a “what the number means” skill. You will not be asked to calculate an unpublished formula, set Unified RBAC from memory, or promise a magic target percentage. You will be asked whether a higher score is better, whether 72% means the tenant passed an exam, whether Secure Score is the same as Compliance Manager, which categories the recommended actions fall into, and whether you can compare yourself with peers.

Official Learn sentence, word for word in spirit: Microsoft Secure Score is a measurement of an organization’s security posture, with a higher number indicating more recommended actions taken. From one dashboard, organizations monitor and improve the security of Microsoft 365 identities, apps, and devices. Microsoft lists three benefits you should be able to restate:

  • Report on the current state of security posture.
  • Improve that posture with discoverability, visibility, guidance, and control.
  • Compare with benchmarks and establish key performance indicators (KPIs).

That is the whole product on this exam: a living scorecard plus a prioritized to-do list, not a trophy and not a regulator’s attestation.

How points work

You earn points when you:

  • Configure a recommended security feature (turn on MFA, block legacy authentication, enable a Safe Links policy).
  • Complete a security-related task the recommendation describes.
  • Address the same control with a non-Microsoft application or an alternate mitigation, and mark the action that way.

Each recommended action is worth 10 points or less. Most are binary: do the whole thing, get all the points. Others are percentage-based. Microsoft’s own example is the one to memorize: a recommendation awards 10 points for protecting all users with multifactor authentication. If 50 of 100 users are protected, you receive 5 points (50 ÷ 100 × 10). Partial coverage still moves the score. The score is not pass/fail. There is no official “70 means you passed Secure Score.”

Microsoft shows you the full set of possible recommendations for a product even if your license edition does not include every control. The idea is to teach the best practice, not to hide the control you have not bought. Your absolute Secure Score still reflects what is configured, not a participation trophy for owning E5. Views on the overview tile can include:

ViewWhat it shows
Your Secure ScorePoints achieved out of points possible, also shown as a percentage
Planned scoreProjected score if items you marked Planned are finished
Current license scoreWhat you can achieve with the Microsoft licenses you already own
Achievable scoreWhat you can achieve with those licenses after the risks you already accepted

The visualizations update as configuration changes. Microsoft also syncs daily to refresh achieved points. After you complete an action, expect on the order of 24–48 hours before the new points appear. Teams-related and Entra-related recommendations can refresh on their own monthly or weekly cadence in addition to configuration-change updates. Do not invent a faster SLA than Learn publishes.

Recommended-action groups: identity, device, apps, data

On the Secure Score page, Microsoft groups recommended actions so a fundamentals candidate can map them to the rest of MS-900:

GroupTypical source productsExample improvement action
IdentityMicrosoft Entra ID accounts and roles; Defender for Identity postureRequire MFA for admins; block legacy authentication
DeviceMicrosoft Defender for Endpoint (also called Microsoft Secure Score for Devices)Turn on attack-surface reduction or a vulnerability recommendation
AppsEmail and cloud apps, including Office 365 and Defender for Cloud AppsEnable Safe Links / Safe Attachments; fix a SaaS misconfiguration
DataMicrosoft Purview Information ProtectionApply a sensitivity or encryption-related control the recommendation names

Device-category items are special: you typically cannot set a free-text status in Secure Score itself. Microsoft sends you to the related Defender Vulnerability Management recommendation. A global exception there can flow back into Secure Score; a per-device-group exception does not flip the Secure Score status to completed.

Security defaults in Microsoft Entra ID are preconfigured settings that blunt common identity attacks. If you turn security defaults on, Secure Score awards the points for the overlapping MFA and legacy-authentication actions (Microsoft documents 9 points for all-user MFA, 10 points for MFA on administrative roles, and 7 points for blocking legacy authentication). Learn’s advice: do not also stack the older sign-in-risk / user-risk policy recommendations on top — mark those as resolved through alternate mitigation so you are not double-penalized for a control security defaults already covers.

Statuses you can set (and which ones give points)

Except for completed items that Microsoft has already verified, you choose a status:

StatusPoints?When to use it on the exam
To addressNot yetYou agree it matters and will get to it; also the default for partial completion
PlannedNot yetThere is a concrete plan (a change window, an owner, a ticket)
Risk acceptedNoUsability or a business constraint means you will not implement it; remaining risk is accepted
Resolved through third partyYesA non-Microsoft tool already implements the control
Resolved through alternate mitigationYesAn internal process or a different Microsoft feature covers the intent
CompletedYes (already counted)Microsoft data confirms full points; you cannot override a completed status

Two exam ideas hide in that table. First, accepting risk does not raise the score — and Microsoft says that is fine, because security must be balanced with usability. Second, crediting a third-party or alternate control does raise the score, so the number better reflects real posture. Microsoft has no visibility into how completely that third-party tool is implemented; the honor system is the point of those two statuses.

Identity Secure Score in the Microsoft Entra admin center is not a rival product. It is the identity slice of Microsoft Secure Score. If a question asks for the all-up Microsoft 365 posture number, the answer is Microsoft Secure Score in the Defender portal, not “only the Entra identity tile.”

Loading diagram...
How Microsoft Secure Score turns recommended actions into a posture number

Compare with similar organizations

A documented benefit is comparison with organizations like yours. On the overview tab a bar chart shows how your score sits relative to peers. On Metrics & trends a comparison line shows the average for organizations with a similar seat count, and you can add a custom comparison. Microsoft states the comparison data is anonymized — you do not get a list of named tenants. Use this on the exam when the stem says “are we better or worse than companies our size?” Secure Score comparison is the feature. It is a benchmark, not a league table and not a regulatory ranking.

History and trends also show points achieved, points that regressed because someone turned a control off, and a risk-acceptance timeline. Regression is why Secure Score is a living measurement: a weekend change that disables MFA will pull the number down after the next sync.

What Secure Score is not

Microsoft publishes an explicit risk-awareness statement. Secure Score is a numerical summary of posture based on configurations, user behavior, and other security-related measurements. It is not an absolute measurement of how likely you are to be breached. No online service is immune, and Secure Score must not be interpreted as a guarantee against a security breach. If a scenario says “our score is 95, so we can skip Defender for Endpoint,” the score is being misused.

Keep these look-alikes separate:

ScoreHomeWhat it measures
Microsoft Secure ScoreDefender portal → Secure ScoreSecurity posture — recommended security controls for identities, devices, apps, and data
Microsoft Purview Compliance Manager scorePurview Compliance ManagerCompliance posture against assessments, regulations, and the Microsoft 365 data-protection baseline
Microsoft exam scaled scoreCertification resultWhether a person passed MS-900 or another exam (700 is the official passing scaled score)
Endpoint Analytics scoreIntuneDevice experience (startup, reliability, work-from-anywhere), not threat posture
Defender for Cloud secure scoreAzure / Defender for CloudAzure/multicloud workload posture — a different model and a different number

The MS-900 trap is almost always Secure Score versus Compliance Manager. Same “improvement actions and points” shape, different question. “Turn on MFA and Safe Links” is Secure Score. “Map controls to ISO or GDPR and see Microsoft-managed versus customer-managed actions” is Compliance Manager (Chapter 12’s neighborhood). “Did the candidate pass the fundamentals exam?” is a 700 scaled score, which has nothing to do with the tenant’s Secure Score percentage.

Realistic exam-style scenarios

CISO dashboard. Leadership wants a single number for “how much of Microsoft’s recommended security configuration have we actually turned on?” Open Microsoft Secure Score. Do not export Compliance Manager and call it Secure Score.

Partial MFA. Half the users have MFA. The MFA recommended action is worth 10 points. Expect partial points, not a hidden action and not a failed tenant.

Third-party MFA. The company already uses a non-Microsoft MFA product that meets the control. Mark resolved through third party so the score reflects reality. Microsoft will not inspect that vendor for you.

We will not disable legacy auth for one factory app. Set risk accepted. Points stay unearned. That is a valid outcome, not a broken score.

Peer pressure. The board asks whether a 61 percent score is typical for a 3,000-seat organization. Use the similar-organization comparison. Do not invent an official “minimum Secure Score.”

Security defaults. A small tenant enables Entra security defaults. Related MFA and legacy-auth Secure Score actions should show as complete (or as alternate mitigation for overlapping risk policies). That is still Secure Score, not a new product.

Exam traps

  • Higher is better. There is no pass mark. 40 is weaker posture than 80; neither is “fail the exam.”
  • Secure Score ≠ Compliance Manager. Security configuration versus regulatory/compliance assessments.
  • Secure Score ≠ the 700 exam score. People pass MS-900. Tenants improve Secure Score.
  • Risk accepted earns zero points. Third-party or alternate mitigation can earn the points.
  • Recommendations appear even for features you have not licensed. Visibility is not the same as entitlement.
  • It is not a breach guarantee. Microsoft says so in the product documentation.
  • Identity Secure Score is a slice, not a replacement for the Defender portal Secure Score.
  • Defender for Cloud’s score is a different score for Azure workloads.

Official sources

Test Your Knowledge

What is Microsoft Secure Score?

A
B
C
D
Test Your Knowledge

In the Microsoft Defender portal, Microsoft groups Secure Score recommended actions into which categories?

A
B
C
D
Test Your Knowledge

Which statement about Microsoft Secure Score is correct?

A
B
C
D
Test Your Knowledge

A recommended action awards 10 points for protecting all users with multifactor authentication. Fifty of 100 users are currently protected. What does Microsoft Secure Score do?

A
B
C
D