Microsoft 365 security guide

Microsoft Secure Score: what it means and how to improve it

Microsoft Secure Score tracks adoption of recommended security controls. Use it to guide improvement, not as a probability of avoiding a breach or a certificate that your business is secure. The findings behind the number matter more than reaching an arbitrary percentage.

Published · Last reviewed · By CyberProva

Run your free Microsoft 365 security assessment

No card required · Optional read-only Microsoft 365 connection

What is a good Microsoft Secure Score?

There is no single percentage that establishes security for every organisation. Set a target around relevant recommendations, your risks and your ability to operate the controls.

  • Look at the underlying recommendations and unfinished actions.
  • Check the scope and exceptions behind credited actions.
  • Use peer comparisons as context, not a pass or fail threshold.

How do you improve Microsoft Secure Score?

Review recommended actions in the Microsoft Defender portal. Agree the changes with your administrator, prioritise the important gaps and verify the outcome before moving on.

  • Assign an owner to each selected improvement.
  • Consider operational impact and test changes with your IT team.
  • Document accepted risks and alternative mitigations.
  • Review the trend alongside the actual configuration evidence.

Why is Secure Score not an independent security assessment?

Microsoft says the score is not an absolute measure of breach likelihood. An assessment also needs a stated scope, review of supporting evidence and explanation of gaps beyond the score's recommendations.

  • A score does not establish that a restore test succeeded.
  • It cannot by itself justify every administrator assignment.
  • Provider statements still need evidence and review.
  • A configuration baseline does not replace penetration testing.

Is CyberProva's Cyber health score the same number?

No. CyberProva summarises its own selected assessment checks. It can show Secure Score information where available, but does not relabel Microsoft's score as independent assurance.

  • Review the findings and assessment scope behind Cyber health.
  • Separate automated settings checks from organisation-reviewed evidence.
  • Keep missing data and evidence gaps visible.

Make the answer provable

Evidence to request

  • A dated Secure Score report and selected recommendations.
  • Configuration evidence for changes claimed as completed.
  • A separate record of scope, exceptions, recovery evidence and unresolved questions.

How CyberProva helps

CyberProva uses selected Microsoft 365 checks alongside controls supported by provider evidence. Automated checks verify supported settings; other controls are supported by evidence reviewed by your organisation. This gives you context beyond a single posture metric without claiming complete independent verification.

See what a Microsoft 365 security assessment should cover →

See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions

Common questions

Is a score of 80% safe?

It is not a guarantee. Inspect the remaining recommendations, affected accounts and business impact rather than treating a percentage as proof of safety.

Should we aim for 100%?

Choose and justify suitable controls with your IT team. The highest possible number is not a substitute for an evidence-backed risk decision.

Official guidance

Use these sources with your IT provider when reviewing the controls described above.

From assumptions to evidence

See what needs attention in your organisation

Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.

Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.

Run your free assessment →