Skip to main content
Open Cloud > Posture > Secure Score to review the latest stored Microsoft security score and recommendations for your company. From the multi-company Posture overview, opening a Microsoft row also opens that company’s Secure Score. Audience: Company users with Microsoft 365 read access and MSP staff. Company users ask their MSP to change permissions or security settings.

Open the right company

  1. Open Cloud, then Posture, then Secure Score when available.
  2. Check the company in the top bar. MSP staff should select one company before reviewing its score or planning work.
  3. Read the summary, then use Needs attention, Addressed or All to choose controls.
  4. Click a control’s Title to read its detail panel.
  5. Company users can start with the Home AI Assistant to request help. Include the company, control title and concern.
An empty page can mean no stored score is available for the selected scope. It does not mean the company passed every security check. Ask the MSP to check the connection and synchronization.

Read the summary

The current 30-Day Trend can display the change with its direction reversed. Do not use its plus/minus sign to conclude that security improved or worsened. Ask your MSP to compare dated source scores until this is corrected.
The summary is separate from the filtered controls table. Changing a table filter does not recalculate these cards. Category totals and the overall score can use different synchronized datasets; their totals need not match. A score is configuration evidence, not a guarantee of security or proof of an incident.

Choose a control view

Secure Score Needs attention, Addressed and All views.

Example counts depend on the company and synchronized controls.

Addressed does not mean Completed. Read each status and its supporting detail. Planning work in MSPortal does not itself update Microsoft’s control status. Switching views clears checked rows and can close a detail panel if that control is outside the new view.

Understand the columns

Title opens the control. Category and Service describe its area. Max Points is its maximum value, not the remaining score improvement. Status reflects the available Microsoft state, with a score-based fallback when no specific state is supplied. Unrecognized states may retain their provider wording and belong to the Unknown filter group. Severity is derived from the recommendation tier: Core is Critical, Advanced is High, Defense in depth is Medium, and an unrecognized tier is Informational. It does not prove an active threat. The Planner column appears with appropriate Planner access and can open linked work. A blank cell does not prove that nobody has planned similar work.

FAQs

Open Cloud > Posture > Secure Score, or open a Microsoft row in the multi-company Posture overview. The older Microsoft 365 entry is not the current sidebar path.
No. Addressed also includes Risk accepted, Resolved externally and Reviewed. Check the individual status.
Planned is an attention status. Creating an MSPortal Planner item does not automatically change Microsoft’s state or complete the control.
Not currently. Its sign can be reversed. Ask the MSP to compare dated source scores instead of relying on the sign.
Do not assume that. The current reader uses available all-tenant comparison data. Missing comparison data displays a dash.
They summarize the stored score independently of the controls table. Filters narrow controls, not the summary score.
No. Severity comes from the recommendation tier. Review the recommendation and supporting evidence with the MSP.
Ask the MSP to manage access and security changes. Start with the Home AI Assistant for a support request; viewing a score does not authorize or apply a change.