QG Professional Services
- Microsoft & Cloud
- Cybersecurity
Every Microsoft 365 tenant has a Secure Score, most IT managers have seen it, and remarkably few organisations use it for anything. That is a waste of the best free security instrument in the platform — but the opposite failure exists too: treating the score as a target to be gamed rather than a measurement to be understood. We measure every security engagement against Secure Score, so we have strong opinions about both mistakes.
What Secure Score actually measures
Secure Score, in the Microsoft Defender portal, evaluates your tenant's configuration against Microsoft's recommended security controls across identity, devices, apps and data. Each recommended action carries points; your score is the percentage of available points you have achieved. Two properties matter for interpreting it:
- It is relative to your licences. The denominator is what your tenant could achieve with what you own. A Business Premium tenant and an E5 tenant at "60%" are not equally secure — the E5 tenant's 60% covers a far larger control surface.
- It measures configuration, not outcomes. It cannot see your processes, your user behaviour, your third-party tools, or whether anyone reads the alerts. A high score with an unmonitored inbox of Defender incidents is theatre.
Used correctly, it is three things: a baseline, a prioritised to-do list (each improvement action names its points, impact and affected users), and a trend line that catches configuration drift.
What the numbers actually look like in the field
Published averages hover in the mid-40s per cent, and our assessment experience across Egyptian and regional tenants is consistent with that or lower: the typical unassessed tenant sits between 25 and 40 per cent. The pattern behind low scores is remarkably uniform — MFA gaps outside admin roles, legacy authentication still enabled, no device compliance policies, Defender features licensed but unconfigured.
What "good" looks like depends on tier, because the denominator differs:
- Business Premium, well deployed: 55–60% is a realistic, strong outcome — the SMB hardening set fully implemented.
- E3, well deployed: 60–75%, reflecting the added information-protection surface.
- E5, well deployed: 75%+ is achievable and should be the ambition — the full Defender XDR, Entra P2 and Purview estate configured. In our engagements, the typical uplift from baseline to hardened state is 30 to 50 percentage points.
Above roughly 80%, marginal points get expensive and increasingly involve trade-offs with usability; the right posture there is deliberate exception management, not point-chasing.
The three ways organisations misuse the score
- Gaming it. Marking recommendations as "resolved through third party" or "risk accepted" without the third party or the risk decision actually existing. The score rises; the exposure doesn't move. Every exception should have a named owner and a written rationale.
- Chasing points over risk. The points ranking is Microsoft's generic weighting, not your threat model. Blocking legacy auth matters more than several higher-point cosmetic actions; sequence by your exposure, as a proper assessment does.
- Measuring once. A score without a review cadence decays silently: new features ship, admins make temporary changes that become permanent, defaults shift. Monthly review, with regressions investigated like incidents, is the discipline that makes the number mean something.
One timing note for 2026. The July 2026 packaging update adds capability to E3 and E5 tenants, which adds available points to the denominator. A score that appears to fall in August may reflect newly available points rather than any regression. Establish what changed before reporting a decline, and treat the new points as the work item they are.
Secure Score and CIS: use both
Secure Score is Microsoft's view of your tenant; the CIS Microsoft 365 Foundations Benchmark is an independent, auditable control framework. They overlap heavily but serve different audiences: Secure Score for operational tracking, CIS for evidenced assurance you can hand an auditor, a board or a customer. Our hardening engagements run both deliberately — CIS as the control set, Secure Score as the progress metric.
Practical steps
Open the Defender portal and record your score today — that is your baseline, whatever it is. Work the top ten improvement actions; most tenants find several high-value items that cost nothing but configuration. Set a monthly review with a named owner. And if your score sits in that 25–40% band, treat it as the useful news it is: the fastest risk reduction available to you is already licensed and waiting to be switched on. A QG security assessment turns that into a sequenced, evidenced remediation plan — measured, of course, on Secure Score.