Microsoft Secure Score: What It Means and How to Improve It
Microsoft Secure Score measures how well your Microsoft 365 tenant is configured for security — showing your score against Microsoft's recommended settings and providing an ordered list of improvement actions. This guide explains what the score means and which improvements matter most for UK SMEs.
Overview
Microsoft Secure Score measures your M365 security configuration as a percentage of recommended settings implemented. The industry average is approximately 50%; above 70% indicates a well-hardened environment. High-impact improvements — MFA via Conditional Access, legacy authentication blocking, Defender for Business — should be prioritised over low-impact items that improve the score number without meaningfully reducing risk.
Learn about M365 securityWhat Is Microsoft Secure Score?
Microsoft Secure Score is a built-in measurement tool in the Microsoft 365 Defender portal (security.microsoft.com) that shows how well your Microsoft 365 environment is configured for security. It expresses your configuration as a numerical score and as a percentage of the maximum available points for your licence tier. The higher the score, the more recommended security actions you have completed.
Secure Score is free and available to every Microsoft 365 tenant. It covers identity security (Entra ID configuration), device security (Defender for Business and Intune), application security (Exchange Online, SharePoint, Teams), and data security (Microsoft Purview). The recommendations are drawn from Microsoft's own security guidance and are weighted by impact — more impactful actions are worth more points.
How Secure Score Is Calculated
Microsoft Secure Score works by checking your current M365 configuration against a set of recommended security actions. For each action, Microsoft checks whether it is configured correctly and awards points if it is. The score is the sum of points achieved divided by the maximum possible points, expressed as a percentage.
The maximum possible score varies by licence tier — a Business Premium tenant has more available points than a Business Basic tenant, because Business Premium includes additional security features (Conditional Access, Defender for Business, Intune) that can be configured. A Business Basic tenant that has implemented all available security actions may score 100% of its possible points, but the absolute score number will be lower than a Business Premium tenant that has implemented the same proportion of recommendations.
The score updates continuously as configurations change — enabling a new security policy immediately increases the score; removing a control immediately decreases it. This makes Secure Score a useful real-time monitoring tool for M365 security posture.
What a Good Score Looks Like
Microsoft's published data shows that the average Secure Score across all M365 tenants is approximately 50%. This means the typical Microsoft 365 organisation has implemented roughly half of the recommended security actions available to it. For most UK SMEs, a score above 50% indicates a better-than-average configuration; above 70% indicates a well-hardened environment.
However, the score number matters less than which specific recommendations are implemented. A tenant with a 60% score that has enabled MFA, blocked legacy authentication, and deployed Defender for Business is far more secure than a tenant with a 70% score that has implemented many low-impact recommendations but left MFA disabled. AMVIA focuses on implementing high-impact recommendations first, rather than optimising the score number.
High-Value Improvements for UK Businesses
The Secure Score improvement actions are categorised by impact and implementation effort. The highest security ROI improvements typically include:
- Enable MFA for all users via Conditional Access — highest impact, addresses 99%+ of account takeover attacks
- Block legacy authentication — eliminates the most common MFA bypass used in password spray attacks
- Require MFA for admin roles — protects the highest-value accounts in the tenant
- Enable Microsoft Defender for Business — provides endpoint protection and threat detection
- Configure Safe Attachments and Safe Links — protects against email-borne malware and phishing
- Configure anti-phishing policies with impersonation protection — protects against Business Email Compromise
- Enable audit logging — essential for incident investigation
- Restrict external sharing in SharePoint — prevents inadvertent data exposure
Improvements That Require Business Decisions
Some Secure Score recommendations have operational trade-offs that require business decisions rather than purely technical ones. Requiring device compliance before accessing M365 (which increases the score significantly) means that personal devices and unmanaged devices cannot access company data without being enrolled in Intune — a policy that needs to be communicated and managed, not just technically configured.
Similarly, restricting external sharing in SharePoint may affect how you collaborate with clients or partners. AMVIA reviews the impact of each high-value recommendation in the context of your specific business processes before implementing, ensuring that security improvements do not unnecessarily disrupt operations.
Using Secure Score for Ongoing Security Management
Secure Score is not a one-time exercise. Microsoft adds new recommendations as new security features are released and as the threat landscape evolves. A score that was good six months ago may have slipped relative to new recommendations. AMVIA includes quarterly Secure Score reviews in its managed M365 service — reviewing new recommendations, assessing their relevance for the client's environment, and implementing those that provide meaningful security improvement.
Secure Score also provides comparison data — showing how your score compares to other organisations of a similar size and industry. This peer comparison helps contextualise your position and can support board-level reporting on security posture.
How AMVIA Can Help
AMVIA provides a Secure Score review as part of its Microsoft 365 security service. For new clients, the review identifies the current score, maps the highest-impact improvement actions to the client's licence tier and environment, and produces a prioritised improvement plan. AMVIA then implements the improvements and monitors the score on an ongoing basis. Contact AMVIA on 0333 733 8050 to discuss a Secure Score review for your Microsoft 365 tenant.
Key Points
What UK businesses need to know about Microsoft Secure Score.
Score Reflects Configuration
Secure Score checks your actual M365 settings in real time — it increases immediately when you implement a recommendation and decreases if a control is removed.
Impact Matters More Than Score
MFA enforcement, legacy authentication blocking, and Defender for Business configuration are worth more in real security terms than optimising low-impact recommendations to chase a higher number.
Licence Tier Affects Maximum Score
Business Premium tenants have more available points than Business Basic — because Business Premium includes more security features that can be configured and scored.
Quarterly Review Keeps Score Current
Microsoft adds new recommendations over time. A score that was good six months ago may have slipped. Regular review ensures new recommendations are assessed and implemented.
Secure Score Improvement Checklist
MFA enabled for all users via Conditional Access — highest-impact single improvement
Legacy authentication blocked — eliminates the most common MFA bypass
MFA required for all admin roles — protects highest-value accounts
Defender for Business enabled and configured — not just installed
Safe Attachments and Safe Links enabled with appropriate policies
Anti-phishing policy configured with impersonation protection
Audit logging enabled with appropriate retention
Secure Score reviewed quarterly — new recommendations assessed and prioritised
Frequently Asked Questions
The industry average is approximately 50%. A score above 70% indicates a well-hardened configuration. However, the score number matters less than which specific recommendations are implemented — a tenant that has enabled MFA, blocked legacy authentication, and deployed Defender for Business is meaningfully secure regardless of whether its overall score percentage is 55% or 75%. AMVIA focuses on high-impact recommendations first.
Some recommendations do have operational impact if implemented without testing. Blocking legacy authentication — one of the highest-impact recommendations — can disrupt older email clients, printers, and applications that use basic authentication. AMVIA assesses the impact of each recommendation before implementation, testing in report-only or audit mode where available, and working through any dependencies before enforcing new controls.
Secure Score measures configuration against Microsoft's recommended settings — it does not measure everything that makes an organisation secure. A high score indicates that recommended M365 configurations are in place, which substantially reduces common attack surface. But security also depends on staff awareness, incident response capability, network security, and physical controls that fall outside M365 configuration.
Improve Your Microsoft Secure Score
AMVIA reviews your M365 Secure Score, identifies the highest-impact improvements for your licence tier, and implements them as part of a structured M365 security engagement.
Related Resources
Microsoft 365 Security Guide
A complete guide to M365 security — Secure Score as part of the full security picture.
M365 Tenant Hardening Guide
The specific M365 configurations that improve Secure Score and reduce real attack surface.
Conditional Access Guide
Conditional Access configuration — one of the highest-impact Secure Score improvements available.