10/09/2026

Close the Secure Score Gap for Mid-Sized Engineering and Finance Firms


Microsoft Secure Score is the percentage figure showing how many of Microsoft’s recommended security configurations your tenant has actually switched on. Treat it as a prioritized action list, not proof you’re safe. The first move for most IT teams: enforce MFA everywhere, block legacy authentication, and trim standing admin accounts. Those three changes alone typically close a meaningful chunk of the gap between where you sit and where you should be.


TL;DR:

  • Enforcing MFA everywhere, blocking legacy authentication, and reducing admin accounts typically close most security gaps identified by Secure Score.
  • The score assesses three domains: Identity, Data & Apps, and Devices, with the current score updated daily based on configured security measures.
  • Recommended actions are prioritized by impact, effort, and existing licensing, with partial credit given for measures like MFA coverage percentage.
  • Secure Score reflects configuration status and not actual policy quality or incident response effectiveness, risking score inflation if misunderstood.
  • Regular reviews are essential as score changes may result from licensing, organizational growth, or evolving threats, not just environment improvements.

Techtron
Strengthen Your Microsoft 365 Security
Techtron helps professional service firms manage cybersecurity, Microsoft 365, Azure, and infrastructure with proactive support tailored to business needs.
Explore IT services

What Secure Score actually measures

Secure Score breaks your tenant into three domains: Identity, Data & Apps, and Devices. Identity covers authentication controls, admin roles, and conditional access. Data & Apps looks at how Microsoft 365 apps, SharePoint, and email are configured against data leakage and phishing. Devices tracks endpoint protection, patching, and threat detection coverage across laptops and servers.

Your score is a fraction: points earned against total points available for the licenses you hold. Microsoft Secure Score calculates this at the tenant level and updates it daily as configurations change.

The dashboard gives you several views worth understanding before you act on any of them. Current score shows where you stand today. Planned score projects where you’d land if every queued action were completed. Achievable score shows the realistic ceiling given your current licensing tier, and a separate current license view strips out recommendations you can’t act on without buying more Microsoft 365 or Azure capacity. For a finance or engineering firm deciding whether to upgrade a license tier, that distinction between “achievable” and “current license” is often the difference between a justified spend and a wasted one.

How do you find your Secure Score in Microsoft Defender?

Sign into security.microsoft.com/securescore with an account holding sufficient permissions. You’ll land on the overview page showing your score, trend line, and comparison against similar organizations.

Viewing rights typically require Security Reader, Global Reader, or a Defender unified RBAC Exposure Management role scoped to Secure Score. Making changes to action status needs broader Security Administrator access. If an outsourced provider manages your tenant, they should request delegated access through Granular Delegated Admin Privileges rather than a shared global admin login. That keeps the audit trail clean and limits blast radius if a partner account is ever compromised.

Not every recommendation is pass or fail. MFA enforcement, for instance, often earns partial credit based on what percentage of users have it enabled, so moving from 60% to 90% coverage nudges the score up incrementally rather than all at once.

Each item in the Recommended Actions tab carries one of five statuses: To address, Planned, Risk accepted, Resolved through third party (or alternate mitigation), and Completed. Microsoft ranks these actions by points remaining, implementation difficulty, user impact, and technical complexity, so the list itself is already sorted roughly by bang for your buck.

Five Secure Score recommendation statuses

That “Resolved through third party” status matters more than people realize. If you’ve deployed a firewall or endpoint tool outside the Microsoft stack that already covers a recommendation, mark it there instead of leaving it flagged red forever. Otherwise your score understates your real posture, and you end up explaining the same gap to your board every quarter.

Completed status only appears once Microsoft’s own telemetry confirms the change took effect. Self-reported fixes that haven’t propagated yet will still show as outstanding.

Quick wins and a simple way to prioritize the rest

Identity fixes tend to deliver the fastest points per hour of effort, which is why most practical Secure Score playbooks push teams to start there before touching devices or data policies.

Start with these:

  • Enforce MFA for every user, not just admins, since NIST names it a core control against credential theft.
  • Block legacy authentication protocols that bypass conditional access entirely.
  • Reduce standing (permanently active) admin accounts to the smallest workable number.
  • Enable the unified audit log so you have a record when something does go wrong.

For everything beyond those four, filter the Recommended Actions list to “Have license? = Yes” first, so you’re not chasing points you’d need a license upgrade to unlock. Then sort by impact multiplied by effort. Export the filtered list to CSV, assign an owner to each line, and set a review date for anything marked Risk Accepted.

Pro Tip: Don’t chase a perfect score. A defensible, documented 75 to 85% with clear reasons behind every skipped item holds up far better in an audit than a rushed 95% nobody can explain.

Permissions, RBAC and safe delegation

Grant Secure Score visibility through least-privilege Entra roles for day-to-day viewing, and reserve write access for a small group using Defender’s unified RBAC Exposure Management roles where your license supports them. Log every status change so you can trace who accepted a given risk and why. If a managed provider requests access, delegated admin privileges scoped to security functions beats handing over global admin rights.

Using Secure Score for reporting and compliance

Secure Score recommendations map reasonably well onto NIST, CIS, and ISO control families, which makes the dashboard useful supporting evidence in a board report or an insurance questionnaire. Trend lines and peer benchmarks give you a KPI to justify a security budget line that might otherwise get cut.

Here’s the caveat worth repeating to anyone above you who thinks a high score equals compliance: Secure Score measures configuration coverage, not whether your incident response plan works or your conditional access policies are scoped sensibly. Microsoft’s own documentation is explicit that it’s a posture indicator, not a certification.

How often should you check and set targets for Secure Score?

Check regularly, report periodically to leadership, and re-check promptly after any major change, like a new acquisition or a shift to hybrid work. As a rough operational guide: low scores signal real exposure, mid-range scores mean the basics are missing, higher scores indicate reasonably managed tenants, and very high scores reflect mature, disciplined configuration management. Set your target against the achievable score for your license tier, not the theoretical maximum, and document every accepted risk that explains the gap.

The limitations nobody puts on the dashboard

Secure Score has a real blind spot: it rewards configuration, not judgment. A conditional access policy can technically exist, earn full points, and still be scoped so loosely it does nothing useful. Microsoft’s documentation acknowledges this directly, noting the score can’t evaluate policy quality or how mature your incident response actually is.

The bigger organizational risk is what happens once a number appears on a dashboard: people start managing to the number. A leadership team sees 82% and assumes the tenant is well protected, when 82% might reflect a dozen low-effort identity fixes while the three hardest, highest-risk device recommendations sit untouched for a year. Score inflation through “easy” points is a common pattern in firms that treat Secure Score as a KPI to hit rather than a diagnostic to interrogate.

Another pitfall: license mismatch. A firm running Microsoft 365 Business Premium will never touch the ceiling reserved for E5 tenants, no matter how well configured it is. Comparing your score against a benchmark built on richer licensing sets an unfair, and demotivating, target.

Finally, “Risk accepted” statuses have a habit of becoming permanent by neglect rather than decision. A risk accepted eighteen months ago by someone who has since left the company isn’t a documented risk anymore, it’s an unmanaged one. Review those statuses on a schedule, not just when someone happens to notice them.

None of this means the score is useless. It means it’s one input among several, best paired with a proper audit of policy design and a real test of how your team responds when something actually goes wrong.

The limitations nobody puts on the dashboard — overview diagram

How Secure Score works with your other Microsoft security tools

Secure Score doesn’t operate in isolation. It pulls signal from Microsoft Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, and Entra ID Protection, aggregating their configuration state into one composite number. When you enable a Defender for Endpoint policy, the related Secure Score recommendation typically updates within a day.

This integration cuts both ways. If your organization runs security tools outside the Microsoft ecosystem, say a third-party firewall or a separate SIEM, Secure Score won’t see them unless you manually mark the relevant recommendation as “Resolved through third party.” That’s a manual step teams frequently forget, and it’s the single most common reason a well-defended tenant still shows a mediocre score.

The practical value of this integration shows up during incident triage. If Defender for Identity flags unusual sign-in activity, cross-referencing against your Secure Score identity recommendations tells you quickly whether the gap that let the incident happen was already flagged and ignored, or genuinely unknown. That distinction changes how you brief leadership afterward.

For firms also running network hardening separate from the Microsoft stack, reviewing broader network security best practices alongside Secure Score recommendations helps close gaps the dashboard can’t see on its own. The same logic applies to web-facing assets: a firm running HubSpot CMS alongside Microsoft 365 should look at web security plugins as a complementary layer, since Secure Score has no visibility into a public website’s defenses at all.

Does Secure Score scale to your organization’s size and industry?

Secure Score’s methodology stays consistent regardless of tenant size, but its practical meaning shifts a lot depending on how many licenses, admins, and endpoints you’re running. A 25-person engineering firm with a handful of admins can realistically push toward 85% or higher because there’s less complexity to manage. A 300-person financial services firm with multiple departments, legacy integrations, and a wider mix of device types will often plateau lower, not from negligence but from sheer surface area.

Industry matters too, mostly through licensing choices rather than the scoring logic itself. Financial services firms tend toward higher Microsoft 365 tiers because of data governance requirements, which unlocks more recommendations, and therefore a higher achievable ceiling, than a firm on a lower tier. Engineering firms with heavy CAD and file-sharing workflows often see their Data & Apps score lag behind Identity, simply because collaboration tools multiply the number of places data can leak.

The mistake many mid-sized South African firms make is benchmarking against a global average that assumes deeper licensing and larger security teams than they actually have. A more useful benchmark is your own achievable score for your specific license tier, tracked over time, rather than a headline percentage designed for enterprise tenants with dedicated security operations centers. Growth changes the picture too: a firm expanding from 40 to 150 staff will see its score dip temporarily as new devices and accounts get provisioned faster than policies catch up. That’s expected, not a failure.

How does Secure Score calculate risk and impact?

Each recommended action carries a fixed maximum point value set by Microsoft, reflecting how much that control reduces risk across the tenant. MFA enforcement, for example, carries substantial weight because credential theft remains one of the most common breach vectors industry-wide. A cosmetic setting with minimal security bearing carries far fewer points.

Where an action supports partial credit, like the percentage of users covered by MFA, the score scales linearly with adoption. Ten percent of users covered earns a small fraction of the maximum; ninety percent earns most of it. This is why chasing the last few percentage points on a partial-credit item is often more efficient than tackling a new binary action from zero.

Impact ranking, separate from the raw point value, factors in implementation difficulty, expected user disruption, and technical complexity. Microsoft’s own ranking system surfaces actions with high points and low disruption near the top of your list, which is exactly why the default sort order in the portal is worth trusting rather than reordering by gut feel.

There’s a subtlety worth flagging for anyone building a business case from this data: a high point value doesn’t always mean high real-world risk reduction for your specific environment. A recommendation might carry heavy points because it matters a lot for a typical tenant, while your organization already mitigates that risk through a control Microsoft can’t see. This is exactly why identity-first prioritization, backed by documented reasoning behind every skipped action, tends to outperform blindly chasing the highest point values on the list.

Keeping Secure Score metrics current

A score checked once and forgotten is close to worthless. Microsoft adjusts recommended actions periodically as threats evolve, licensing changes, and new features roll out, so a tenant that scored 78% eighteen months ago might show a different percentage today purely because the scoring model shifted, not because anything in the environment changed.

Build a maintenance rhythm around three triggers: scheduled reviews, license changes, and organizational events. Monthly checks catch drift before it compounds. Any license upgrade, adding Defender for Identity, for instance, should trigger an immediate re-check, since new recommendations often appear the moment new licensing activates. Mergers, office openings, and rapid headcount growth all shift the device and identity landscape fast enough to justify an out-of-cycle review.

Exporting recommended actions and re-checking the score after remediation closes the loop between action taken and measurable improvement, which matters when you’re justifying the time spent to a CFO who wants proof, not assurances. Keep a simple log: date, action completed, score before, score after. Over a year, that log becomes the clearest evidence you’ll have that security spending is producing something concrete rather than disappearing into overhead.

Techtron’s perspective: making Secure Score part of the routine, not a one-off audit

Most firms we work with treat Secure Score as something to check once a year, usually after a scare. That’s backwards. Our workflow with co-managed clients runs assess, prioritize, implement, evidence, then report, on a recurring cycle rather than a single sweep. MFA rollouts, conditional access design, endpoint hardening, and ongoing monitoring map directly onto the highest-value Secure Score categories, which means the remediation work and the reporting evidence come from the same process instead of two disconnected efforts.

For professional services firms running 20 to 300 staff, particularly in engineering and financial services, this matters because the compliance conversation with clients or regulators tends to arrive faster than internal IT capacity can respond. Building Secure Score remediation into a recurring managed service closes that gap before it becomes a scramble.

— Steven

How Techtron helps you close the Secure Score gap

Specialized IT service providers offer an alternative to hiring an internal security analyst to chase Secure Score line items every quarter, potentially reducing overhead and hiring risk. Co-managed and fully managed IT services can build Secure Score remediation into a monthly cycle including MFA rollout, conditional access design, endpoint hardening, and ongoing monitoring, all tracked and reported consistently rather than addressed only before audits.

If you’re a financial services or engineering firm with 20 to 300 staff and you’ve never actually looked at your Secure Score, or looked once and never went back, that’s the exact gap our managed IT services are built to close. Reach out through Techtron for an assessment of where your tenant stands today, and what it would take to move it somewhere defensible.

Sources