Microsoft Secure Score tells you how many of Microsoft's recommended configuration actions you have taken inside your Microsoft environment. That is worth knowing. What it does not tell you is how likely you are to be breached, and Microsoft says as much in its own documentation: the score represents the extent to which you are using security controls that can help offset the risk of being breached, and should not be interpreted as a guarantee against a breach in any manner.
The trouble starts when the number gets treated as a grade. It turns up in board packs, in provider reports, and now and then in a sales pitch, and it is easy to move a Secure Score a long way without changing much about your real exposure. The score is a benchmark. It is not an independent certification. Once you know how it is built, you know when the number is telling you something and when it is only telling you about itself.
TL;DR: What to remember
- ✅ Secure Score counts the Microsoft-recommended actions you have completed. It is a configuration measure, not a breach forecast, and Microsoft states that plainly.
- ✅ You can lift the number by knocking off the easy actions, so a rising score is not proof that risk fell. Ask which actions were done, not by how much the score moved.
- ✅ It covers Microsoft products and a set of supported non-Microsoft ones. The unpatched server and the finance team's payment checks sit outside it.
- ✅ A strong score is not an Essential 8 maturity level, and it is not a position you can state to a client or an insurer.
Contents
- What the number actually counts
- How the score is built, and where it misleads
- What the score cannot see
- How to use it without being fooled by it
- The score, answered without the spin
What the number actually counts
Microsoft describes Secure Score as a measurement of an organisation's security posture, with a higher number indicating more recommended actions taken. You earn points for configuring recommended security features, for completing security-related tasks, and for addressing a recommended action with a non-Microsoft application or an alternate mitigation.
Read that carefully and the shape becomes clear. The score counts actions taken against Microsoft's recommendation list. It is a completion measure against a checklist Microsoft maintains, covering identities, apps and devices across its own products. For a business measuring nothing else at all, that is genuinely valuable: it gives you discoverability, a prioritised list of concrete improvements, a trend over time, and a comparison against similar organisations. That is a far better starting point than opinion. The failure mode is not the tool. It is treating a completion measure as a risk measure.
How the score is built, and where it misleads
The number is not arbitrary, but the way it is assembled produces two effects that catch people out. Neither is obvious from looking at a percentage on a dashboard.
Each action is worth ten points or less, and most are all or nothing
Each recommended action is worth 10 points or less, and Microsoft notes that most are scored in a binary fashion: implement the action and you get 100% of its points. Some are scored proportionally. Microsoft's own worked example is multi-factor authentication, an action worth 10 points for protecting all users, where 50 of 100 users are protected scores 5 points. So the total is a running tally of items ticked off, weighted lightly and mostly counted as done or not done.
Points do not track risk reduction
A straightforward policy toggle and a difficult, high-impact control can carry similar point values. That means a score can be raised efficiently by completing the easy items, which is a rational thing to do for anyone being measured on the number, and it is why a score moving up is not by itself evidence that risk moved down. If somebody reports a score improvement, the useful follow-up is which actions were completed, not by how much it rose. The actions are the substance. The percentage is the wrapper.
Part of your gap may sit behind a higher licence tier
Microsoft's rule here has two parts worth reading carefully. You see recommendations for a product if you hold a licence for that product. Then, within that product, Microsoft shows the full set of possible recommendations regardless of licence edition, subscription or plan, so you can see best practice, and it states your absolute security posture as represented by the score stays the same no matter which edition you own. The practical effect is that part of a low score can represent capability sitting behind a higher tier rather than work you have not done, and closing it is a purchasing decision. That is worth knowing before anyone commits the business to a target number.
You can record a decision to accept the risk
Microsoft also notes plainly that security should be balanced with usability, and that not every recommendation will work for every environment. It provides for this directly: where you cannot or do not want to enact a recommended action, you can choose to accept the risk or the remaining risk, which records the decision rather than leaving it looking like neglect. Using that status deliberately is what turns an unexplained gap into a documented one, and it is the same discipline a framework assessment expects of an exception. A gap you decided on is a different thing from a gap nobody noticed.
What the score cannot see
The boundary is narrower than the whole of your business, though wider than Microsoft alone. Secure Score covers Microsoft products and also carries recommendations for a set of supported non-Microsoft products, and the score can reflect when a non-Microsoft solution or an alternate mitigation has addressed a recommended action. What it cannot do is see the parts of your estate that sit outside that supported set.
So it will not tell you about the unsupported server in the back office, the line-of-business application nobody patches, the network device still running default credentials, your physical security, your supplier arrangements, whether your backups actually restore, or whether your finance team checks a change of bank details by phone before they pay it. Several of those are among the most common causes of loss for Australian small and medium businesses, and none of them appears in the number.
It is also worth understanding what the score is not aligned to. Australian businesses are commonly asked to demonstrate a position against ASD's Essential Eight, which is assessed against a target maturity level using standardised outcomes and ranked evidence quality. Secure Score and an Essential Eight assessment measure different things by different methods, and a strong score does not translate into a maturity level. Where the two touch, notably multi-factor authentication, patching and administrative privileges, the score is a useful indicator and not a substitute for an assessment.
How to use it without being fooled by it
None of this is an argument for ignoring the score. It is an argument for using it as the thing it is.
- Treat it as a work queue, not a grade. The recommended actions list is genuinely good prioritisation, and working through it is productive.
- Report actions, not just the number. "We enforced multi-factor authentication on the last 40 users" tells a board something real. A percentage on its own does not.
- Record the declines you make on purpose. Where a recommendation does not suit your environment, note the decision and the reason. That converts a permanent gap in the number into a documented exception, which is also what a framework assessment will expect to see.
- Separate the licence-limited items. Knowing which part of the gap needs a purchase turns an unexplained score into a budget conversation.
- Do not let it be your only measure. Pair it with something that looks outside Microsoft entirely.
This is why inSUPPORT assesses against the compliance frameworks that apply to the client's industry as well as the Microsoft estate. A well-run configuration pass closes a large number of recommended actions quickly, and that is real work worth doing. It still measures the Microsoft estate against Microsoft's list. It does not tell you whether the unsupported server in the back office is still sitting there, and that is the part that tends to matter on the day something goes wrong.
The score, answered without the spin
What is a good Secure Score?
There is no universal published threshold, so be wary of a provider presenting one as an industry standard. Microsoft does support setting your own goals and tracking against them, and offers comparison against similar organisations, which is more useful than an absolute number because it accounts for size and product mix. Set a goal deliberately, treat the comparison as context, and remember that part of any gap may sit behind a licence tier.
Our provider reports our score every month. Is that enough reporting?
It is a reasonable component and a thin diet on its own. A useful monthly report says which recommended actions were completed, which were declined and why, what sits outside the Microsoft estate, and what changed in the environment. The score is the headline for that report, not the report itself.
Does a high Secure Score mean we would pass an Essential 8 assessment?
No. They are different instruments. An Essential Eight assessment tests controls against a target maturity level using standardised outcomes and ranked evidence, and it covers ground the score does not reach. Overlap exists on multi-factor authentication, patching and privilege restriction, so a strong score is a good sign, and it is not a position you can state to a client or an insurer.
Can the score go down when we have changed nothing?
Yes, and it surprises people. Microsoft adds and retires recommendations over time, and the score updates as data syncs, so the denominator moves under you. A score that drifts down without a configuration change usually means the recommendation set changed, not that your environment got worse. It is another reason to report the actions alongside the number.
If your security reporting is currently a score and a colour, the gap is everything that number cannot see. A Cyber Strength Audit looks past the Microsoft estate and assesses the whole environment against the frameworks your industry uses, then hands you a plain English read on where you actually stand, ranked by business impact. inSUPPORT supports Australian businesses of roughly 30 to 300 users and has run more than 1,500 Cyber Strength Audits. We do not hand you a number and leave you to explain it.
Book a Cyber Strength Audit →Sources
- "Microsoft Secure Score", Microsoft Learn. The definition of the score, what earns points, the 10-points-or-less binary scoring, the multi-factor authentication partial-scoring example, and the statement that the full recommendation set is shown regardless of licences held. learn.microsoft.com
- "Essential Eight assessment process guide", Australian Signals Directorate. The standardised assessment outcomes and evidence quality ranking that an Essential Eight position is measured by, in contrast to a configuration score. cyber.gov.au
- "Essential Eight maturity model", Australian Signals Directorate. Target maturity levels and the position that the Essential Eight is a minimum set of preventative measures requiring additional controls where the environment warrants. cyber.gov.au
Related Reading
- How the Essential 8 Maturity Model Benchmarks Cybersecurity
- What is Maturity Level 3
- The 6 Step Cyber Strength System
- IT, compliance and security run together
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


