Secure Score is free, built in, and genuinely useful. It also can't see three things that decide whether you actually get broken into — and one of them is in Microsoft's own documentation.
Someone in your business opened the Microsoft 365 admin center, found a number, and asked the reasonable question: is 74 good?
It's the most common question we hear, and it deserves a better answer than yes or no. Secure Score is free, it's already turned on, and it measures real things. If you've never looked at it, go look at it — that's a genuinely useful hour. But it was built to answer a narrower question than the one you're actually asking, and the gap between those two questions is where most small-business break-ins happen.
What it's good at
Microsoft Secure Score grades how you've configured Microsoft's own security controls — identity, devices, apps, and data. It gives you a percentage, a list of recommended actions, and a history view so you can see the number move.
That's not nothing. A tenant at 30% almost certainly has something badly wrong, and the recommended actions are real recommendations, not filler. If your score is low and you work through the list, you will be meaningfully safer. Nobody should talk you out of using it.
The problem isn't accuracy. It's scope.
1. It only looks inside your tenant
Secure Score grades your Microsoft configuration. It has no idea what your business exposes to the internet.
The remote desktop port someone opened on the office firewall three years ago so they could work from home: not in the score. The old server still answering on a public IP: not in the score. The management interface on your VPN appliance, the database that got stood up for a project and never firewalled, the forgotten subdomain still pointing at a box nobody patches — none of it.
This matters because that's frequently where the break-in starts. An attacker who finds an exposed service and reuses a password from it doesn't care what your Secure Score was. Your tenant can be beautifully configured and still be reached through a door that isn't in Microsoft's field of view.
2. It scores controls, not chains
Secure Score evaluates recommendations one at a time and adds up points. Attackers don't work that way.
A real intrusion looks like this: a password sprayed against an account without MFA, then a mailbox rule quietly forwarding invoices to an outside address, then a wire request that looks exactly like the ones your bookkeeper approves every week. Each of those, on its own, might be a modest number of points. Together they're your bank account.
A score can't express that. Two businesses with identical scores can be in completely different danger, because one of them has three medium findings that connect and the other has three that don't. The question that actually matters isn't "how many recommendations are outstanding" — it's "which of these lead somewhere."
3. The number can include points for things Microsoft can't see
This one isn't our opinion. It's in Microsoft's own documentation:
Resolved through third party and Resolved through alternate mitigation — The recommended action has already been addressed by a third-party application or software, or an internal tool. You'll gain the points that the action is worth... Keep in mind, Microsoft will have no visibility into the completeness of implementation if the recommended action is marked as either of these statuses.
That feature exists for a good reason — plenty of businesses genuinely do cover a control with something outside Microsoft, and the score should reflect it. But it means a Secure Score is partly a record of what someone told Microsoft, not only what Microsoft verified. If a previous admin or an outgoing IT provider marked a batch of actions that way, the number went up and the configuration didn't change.
Worth ten minutes: filter your recommended actions by status and see how many sit in resolved through third party, resolved through alternate mitigation, or risk accepted. If you can't name the third-party tool that covers each one, you've found something.
The same page notes your achievable score is capped by the licenses you own. Some recommendations simply aren't available on your plan, which means a business on Business Basic and one on E5 are being graded on different exams.
4. It's a snapshot, and only if you remember to look
Nothing about Secure Score tells you when something changed. A guest gets added with more access than intended, someone disables a Conditional Access policy to unblock a deadline, a new app gets consented to on a Friday afternoon — the score moves, and nobody finds out until the next time somebody thinks to check.
Most small businesses check it after an incident, an insurance questionnaire, or a client asking a hard question. All three of those are late.
What to actually do
None of this requires buying anything:
- Look at your score, and work the list. Sort recommended actions by points and start at the top. It's the cheapest security work available to you.
- Audit the "resolved" statuses. Anything marked resolved through a third party should have a name attached. If nobody can name the tool, change it back to to address.
- Find out what you expose to the internet. Ask whoever manages your firewall for a list of open ports on your public IPs, and ask why each one is open. This is outside Secure Score entirely, and it's often where the worst finding lives.
- Look for the chains, not the count. For your top few findings, ask: if an attacker had this one, what would it get them next? The ones that answer that question are the ones to fix first.
- Put a date in the calendar. Quarterly is fine. A number nobody looks at isn't a control.
Where we fit
Tenant Strike reads your Secure Score — it's one input among many, not something we replace. Then it does the parts the score wasn't built for: scanning what your domain exposes to the public internet, correlating findings into the multi-step attack paths an intruder would actually use, and writing each fix in plain English with the portal steps and a warning about what it might break. It's read-only by design and never asks for permission to change anything.
If you just want the outside-in half, the free external scan needs no account and no credentials — it reads public records only, with no port scanning and no sign-in attempts. It'll show you the part of your attack surface that Secure Score was never looking at.
But if you do nothing else after reading this: go filter your recommended actions by status. That one's free, takes ten minutes, and we've never seen a tenant where it turned up nothing.
AI-researched from public sources, human-reviewed on September 3, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.