Skip to main content
Microsoft Secure Score rates how well a company’s Microsoft 365 tenant follows Microsoft’s security recommendations. Open Cloud > Posture > Secure Score to read the latest stored score and its recommendations. From the multi-company Posture overview, opening a Microsoft row also opens that company’s Secure Score. This guide is for company users with Microsoft 365 read access and for MSP staff.

Before you start

  • Your role has Microsoft 365 read access.
  • The company has a connected Microsoft 365 tenant and a synced score. MSP staff connect tenants under Connecting companies to Microsoft 365.
  • Company users ask their MSP to change permissions or security settings.

Open the score for a company

1

Open Secure Score

Go to Cloud > Posture, then choose Secure Score.
2

Check the company

Look at the company selector in the top bar. MSP staff should select one company before they review a score or plan work.
3

Read the summary

Read the cards at the top. See the table below.
4

Choose controls

Select Needs attention, Addressed or All, then click a control’s Title to read its detail panel.
5

Ask for help (company users)

Start with the Home AI Assistant. Include the company, the control title and your concern.
An empty page can mean no stored score exists for the selected companies. It does not mean the company passed every check. Ask the MSP to check the connection and sync.

Read the summary

The summary is separate from the controls table. Changing a table filter does not recalculate these cards. Category totals and the overall score can come from different synced datasets, so their totals need not match. A score is configuration evidence. It does not guarantee security or show that an incident happened.

Choose a control view

Secure Score Needs attention, Addressed and All views.

Example counts depend on the company and synced controls.

Addressed does not mean Completed. Read each control’s status. Planning work in MSPortal does not change Microsoft’s control status. Switching views clears checked rows and can close a detail panel when its control is outside the new view.

Read the columns

  • Title opens the control.
  • Category and Service describe its area.
  • Max Points is the control’s maximum value, not the score you can still gain.
  • Status is Microsoft’s state for the control, with a score-based fallback when none is supplied. An unrecognized state can keep Microsoft’s wording and counts as Unknown.
  • Severity comes from the recommendation tier: Core is Critical, Advanced is High, Defense in depth is Medium, and an unknown tier is Informational. It does not show an active threat.
  • Planner appears when you have Planner access and opens linked work. A blank cell does not show that nobody planned similar work.

Troubleshooting

Frequently asked questions

Open Cloud > Posture > Secure Score, or open a Microsoft row in the multi-company Posture overview. The old Microsoft 365 entry is no longer in the sidebar.
No. Addressed also includes Risk accepted, Resolved externally and Reviewed. Check each status.
Planned counts as needing attention. Creating a Planner item does not change Microsoft’s state or complete the control.
No. It uses Microsoft’s all-tenant average.
No. Severity comes from the recommendation tier. Review the recommendation with your MSP.
Ask your MSP. Company users start with the Home AI Assistant. Viewing a score does not apply a change.