Open your company’s posture
- Open Cloud > Posture and choose Current Posture when available.
- Select one company in the top bar. Global View or several selected companies produces Select a company instead of combined scorecards.
- Expand Your Microsoft 365 posture if it is collapsed.
- Read the five headline measures and their detailed metrics, then review Items needing attention.
- Check Data as of and each finding’s timestamps before deciding what needs follow-up.
Understand the five areas
Each headline shows one metric, not a combined grade for every metric in that area.
Coverage shows counts and a rounded percentage, such as 17 of 18 · 94%. A metric with unavailable evidence or no usable coverage denominator shows No data yet; its headline can show a dash.
Colors are display thresholds: coverage is green from 75%, yellow from 50%, orange from 25%, otherwise red. Exception counts are green at zero; unused-account and external-forwarding counts allow one or two as yellow, while most other nonzero exception counts are red. Informational counts carry no health judgment. Green does not mean perfect coverage or prove there are no security issues.
Interpret what was counted
- MFA coverage uses active, licensed member accounts and the supplied registration, per-user MFA, Security Defaults or enforced Conditional Access signals. It is not proof that every sign-in was challenged. The admin metric uses a different scope, so the counts need not match.
- Domain protection requires stored SPF pass, DKIM enabled and DMARC present signals together, excluding onmicrosoft.com domains. It does not establish the strength of every policy.
- Device compliance uses the stored compliance status. Device counts depend on collected CIPP datasets, not every possible endpoint inventory.
- External forwarding checks the destination against known company Microsoft domains, as well as the provider signal. An unexpected result can need domain/mapping review.
- Incidents and alerts use the stored status. Other count labels describe collected records; a standards or policy count does not prove every item is correctly enforced. These are not live monitoring totals or a guaranteed fixed reporting period.
Follow up
Company users start with the Home AI Assistant. Include the company, metric or finding, timestamps and concern. MSP staff should verify the source before acknowledging an exception or changing configuration.- Find and read Current Posture findings
- Review and reopen posture findings as an MSP
- Configure the CIPP integration
- Read Microsoft Secure Score
FAQs
Where do I open Current Posture?
Where do I open Current Posture?
Open Cloud > Posture > Current Posture when the CIPP feature and integration make it available. Select one company.
Can I show several companies in one Current Posture scorecard?
Can I show several companies in one Current Posture scorecard?
No. The current page requires one selected company. Global or multi-company scope shows Select a company.
Is Current Posture the same as Secure Score?
Is Current Posture the same as Secure Score?
No. Current Posture uses CIPP management and security datasets. Microsoft Secure Score and Google calculated checks are separate views.
Does the Account Security headline combine every account metric?
Does the Account Security headline combine every account metric?
No. Each area has one designated headline metric. Read its other metrics separately.
Does green coverage mean everyone is protected?
Does green coverage mean everyone is protected?
No. Green starts at 75% in the current display thresholds. Read the numerator, denominator and actual evidence.
Does Data as of prove every dataset is current?
Does Data as of prove every dataset is current?
No. It is the latest relevant stored timestamp. Datasets can have different ages or incomplete coverage.
Why did the percentage improve after an MSP review?
Why did the percentage improve after an MSP review?
Reviewed resources are excluded from calculations, which can change the numerator and denominator. Review does not itself change Microsoft configuration.
Does No data yet mean zero findings?
Does No data yet mean zero findings?
No. It means the metric has no usable evidence or coverage denominator. Ask the MSP to check the source and synchronization.
Does a zero incident count prove nothing bad happened?
Does a zero incident count prove nothing bad happened?
No. Counts reflect stored, scoped data and review exclusions. Confirm the relevant time period and source coverage with the MSP.
Can a Company administrator enable CIPP or fix permissions?
Can a Company administrator enable CIPP or fix permissions?
Ask the MSP to manage integration setup and permissions. Start with the Home AI Assistant if you need help with a finding.