Skip to main content
The Microsoft 365 module provides comprehensive security monitoring through Microsoft Secure Score. Track your organization’s security posture, view recommendations, and create action plans to improve your security configuration.

Accessing M365 Secure Score

  1. Click Microsoft 365 in the sidebar
  2. The Secure Score dashboard displays your security metrics and controls
M365 Secure Score Overview

Summary Dashboard

The summary section displays four key metrics:
MetricDescription
Secure ScorePoints achieved out of total available (e.g., 53/64)
Score PercentageOverall progress percentage with visual progress bar
Industry ComparisonHow your score compares to industry average
30-Day TrendScore change over the past month
The Industry Comparison shows how your organization compares to similar organizations. A positive difference means you’re ahead of the average.

Collapsing the Summary

Click the Collapse Summary button to minimize the summary cards and focus on the controls list.

Security Controls

Controls Table

The controls table lists all security recommendations with:
ColumnDescription
TitleName of the security control
CompanyAssociated Microsoft tenant
CategoryControl category (Identity, Apps, Data)
ServiceMicrosoft service (AzureAD, MS Teams, Exchange)
SeverityCritical, High, Medium, or Low
Max PointsPoints available if implemented
StatusOpen, Completed, or In Progress

Sorting and Filtering

  • Sort by column - Click column headers to sort
  • Search - Use the search box to find specific controls
  • Filter - Click the filter icon to apply filters

Severity Levels

SeverityDescription
CriticalHigh-impact security issues requiring immediate attention
HighImportant security gaps that should be prioritized
MediumModerate security improvements
LowMinor enhancements for comprehensive security

Control Details

Click any control row to view detailed information:
Control Details Panel

Details Section

FieldDescription
StatusCurrent implementation state
Max PointsScore points available
ServiceMicrosoft service affected
CategoryControl category
SeverityRisk level
Implementation CostEffort required (Low, Medium, High)

Remediation Steps

Each control includes step-by-step remediation instructions:
  1. Specific actions to take
  2. Portal navigation paths
  3. Settings to configure
  4. Verification steps

Impact Information

FieldDescription
User ImpactEffect on end users (Low, Medium, High)
Remediation ImpactOverall impact of implementing the fix

Recent Scores

View historical score data for the control to track progress over time.

Taking Action

Add to Planner

Create a planner task to track implementation:
1

Click Add to Planner

From the control details panel, click Add to Planner
2

Review Pre-filled Data

The dialog pre-populates with control information
3

Configure Task Details

Set due date, status, business value, and estimates
4

Use AI Draft

Click AI Draft to generate a comprehensive summary
5

Save

Click Save to create the planner task
Add to Planner Dialog

Planner Task Fields

FieldDescription
CompanyAssociated company
TitleEditable task title
Due DateTarget completion date
StatusNot Started, In Progress, Completed
TypeTask categorization
Business ValueHigh, Medium, Low
Est. HoursEstimated implementation time
Est. CostEstimated implementation cost
Probability of SuccessConfidence slider (0-100%)

Using AI Draft

The AI Draft feature automatically generates professional notes from your selected security controls. Before AI Draft - The Notes section starts empty:
Add to Planner Dialog - Before AI Draft
After AI Draft - Click the AI Draft button to generate comprehensive documentation:
Add to Planner Dialog - After AI Draft
AI Draft creates:
  • Summary - Clear description of what needs to be done and expected impact
  • Actions Required - Specific configuration steps for each control
  • Business Impact - Security benefits and risk reduction explanation
  • Next Steps - Actionable implementation checklist

Relationships

Link the task to:
  • Linked Findings - Related security controls
  • Goals - Strategic objectives
  • Compliance Items - Regulatory requirements

Add to Meeting

Add the control to an upcoming meeting agenda:
1

Click Add to Meeting

From the control details, click Add to Meeting
2

Select Meeting

Choose an existing or create a new meeting
3

Configure Agenda Item

Set discussion time and presenter

Open in Portal

Click Open in Portal to navigate directly to the Microsoft admin portal where you can implement the fix.

Bulk Actions

Selecting Multiple Controls

Select multiple security controls to process them together:
  1. Use the checkbox next to each control to select individual items
  2. Click Select All to select all visible controls
  3. Click the Actions dropdown to view bulk action options
Bulk Actions Menu

Available Bulk Actions

ActionDescription
Add to MeetingAdd selected controls to an upcoming meeting agenda
Add to PlannerCreate a single planner task combining all selected controls
Create Individual TasksCreate separate planner tasks for each selected control

Best Practices

Prioritization Strategy

  1. Start with Critical - Address Critical severity items first
  2. High-Point Items - Focus on controls with highest point values
  3. Low Implementation Cost - Quick wins with minimal effort
  4. User Impact Consideration - Balance security with user experience

Regular Reviews

  • Weekly - Review Critical and High severity items
  • Monthly - Assess overall score progress
  • Quarterly - Comprehensive security posture review

Documentation

  • Create planner tasks for all implementations
  • Use AI Draft to document remediation plans
  • Track score changes after implementations

Prerequisites

Before using M365 Secure Score:
  1. Microsoft 365 Integration - Enable in Settings → Integrations
  2. Permissions - Global Administrator or Security Administrator role
  3. Tenant Access - Valid Microsoft 365 subscription

Troubleshooting

Score Not Updating

  • Microsoft Secure Score updates may have up to 24-hour delay
  • Verify integration permissions are still valid
  • Check Microsoft 365 service health status

Controls Not Loading

  • Refresh the page
  • Check network connectivity
  • Re-authenticate the Microsoft 365 integration

Implementation Not Reflected

  • Allow 24-48 hours for Microsoft to detect changes
  • Verify the configuration was applied to all users/groups
  • Check for policy conflicts