IT helpdesk support headset icon
Talk to our experts for fast, reliable IT support.

connectivity

How to Improve Your Microsoft Secure Score for Australian Businesses

Microsoft Secure Score gives you a clear, actionable measure of your security posture — and a prioritised list of exactly what to fix first. Here’s how to use it effectively in 2026.
October 1, 2026
Adam Brown, Business Director — Tyto IT
6 min read
Cyber Security
IT administrator reviewing Microsoft Secure Score dashboard to improve business security posture

Microsoft Secure Score is one of the most useful — and most underused — tools available to any Australian business running Microsoft 365. It measures the security posture of your Microsoft environment against a set of recommended controls, assigns a numerical score, and gives you a ranked list of specific improvements you can make, along with the point value of each one. For a business that wants to improve its security without guesswork, Secure Score is an excellent place to start.

This guide walks you through accessing your score, interpreting what it means, and prioritising the actions that will deliver the most meaningful improvement in the least time.

Step 1: Access Your Microsoft Secure Score

You’ll need a Global Administrator, Security Administrator, or Security Reader role in your Microsoft 365 tenant.

  1. Open your browser and go to security.microsoft.com
  2. Sign in with your administrator account
  3. In the left navigation, select Secure score
  4. Your current score, score history, and improvement actions will be displayed on the Overview page

Your score is shown as a number out of the total achievable score. The percentage reflects how many of the available controls your environment currently has in place. Don’t be alarmed if the number looks low — the total achievable score includes enterprise-grade controls that are genuinely out of scope for many small businesses.

Step 2: Understand Your Score Breakdown

Secure Score separates your environment into three categories:

  • Identity — accounts, sign-in policies, MFA, privileged access
  • Devices — endpoint protection, patch levels, compliance status
  • Apps — Microsoft 365 service configuration, email security, Teams settings

Click on Improvement actions to see the full list, ordered by the number of points each action is worth. Each action includes a description of what the control does, the number of score points it contributes, the status of the control in your environment, and the licensing required to implement it.

Start by filtering to Incomplete actions to focus only on what needs attention.

Step 3: Prioritise High-Impact Recommendations

Not every Secure Score recommendation carries equal weight for your business. The practical priority should be based on three questions:

  1. What’s the actual risk? A control that prevents account takeover is more critical than one that adds reporting capability.
  2. What does it require? Some controls can be enabled in minutes; others require pilot testing, user communication, or additional licensing.
  3. Does it apply to your environment? Mark recommendations as Planned, Risk accepted, or Resolved through third party to keep your active list relevant and focused.

For most Australian businesses with 10–100 staff on Microsoft 365, the highest-impact incomplete actions tend to cluster in three areas: identity protections beyond basic MFA, email and collaboration security, and admin account hygiene.

Step 4: Address the Top Recommendations

Here are the actions that appear most frequently as incomplete in small-to-medium Australian Microsoft 365 tenants — and that deliver meaningful protection improvement:

Enable number matching for MFA push notifications

If you’re already using the Microsoft Authenticator app, enabling number matching prevents MFA fatigue attacks — where an attacker sends repeated push notifications hoping the user approves one by mistake. Enable this in Microsoft Entra ID → Security → Authentication methods → Microsoft Authenticator → Configure.

Block legacy authentication protocols

Older authentication methods — SMTP AUTH, IMAP, POP — don’t support MFA. Attackers exploit this to bypass modern authentication controls. A Conditional Access policy blocking legacy authentication for all users closes this gap and is typically worth 15–20 score points.

Require phishing-resistant MFA for administrators

Admin accounts are the highest-value targets in your Microsoft 365 environment. A Conditional Access policy requiring phishing-resistant MFA — FIDO2 security keys or Windows Hello for Business — for Global Administrators provides meaningfully stronger protection than standard push-based MFA.

Enable Safe Links and Safe Attachments in Defender for Office 365

If your subscription includes Defender for Office 365 (included in Microsoft 365 Business Premium), enabling Safe Links and Safe Attachments adds a real-time scanning layer for malicious URLs and email attachments. These are disabled by default and need to be explicitly configured in the Microsoft Defender portal under Email & collaboration → Policies & rules.

Ensure administrators use dedicated admin accounts

If your IT administrators are using their regular email account as their admin account, this is a meaningful configuration risk. Dedicated admin accounts — used only for administrative tasks — limit the damage if a standard user account is compromised. Secure Score flags admin accounts that are also used for everyday activity.

Step 5: Track Your Progress and Set Goals

Secure Score updates within 24–48 hours of a change being made. After implementing an improvement action, revisit your score the next day to confirm it has registered and to see the updated action list.

Set a target score for your organisation — a realistic goal for a Microsoft 365 Business Premium environment is typically 60–75% of the available score for your licensing tier. Tracking your score monthly creates a clear, auditable record of your security posture improvement over time, which is useful for insurance purposes, client due diligence, and board-level reporting.

Frequently Asked Questions

How often should I review my Microsoft Secure Score?

A monthly review is appropriate for most Australian businesses. New improvement actions are added to Secure Score as Microsoft releases new controls and updates existing recommendations. A quarterly deep review with your IT provider is also valuable — some actions require technical implementation that goes beyond what an in-house administrator would typically handle alone.

Does a higher Secure Score mean my business is fully protected?

No. Secure Score measures configuration controls within Microsoft 365 and connected services — it does not account for your physical security, your staff awareness posture, your third-party software vulnerabilities, or your incident response capability. A high score indicates strong Microsoft 365 configuration, which is a significant component of your overall security posture, not the complete picture.

What licensing do I need to act on all Secure Score recommendations?

Some improvement actions are available with any Microsoft 365 licence tier. Others require Microsoft 365 Business Premium, Microsoft Entra ID P1 or P2, or Microsoft Defender add-ons. Secure Score labels each action with the required licence level. If a recommended action requires a higher licence tier, evaluate whether the security value justifies the cost — your Microsoft partner can help with that assessment.

Microsoft Secure Score is not a pass/fail test — it’s a continuous improvement tool. The businesses that get the most from it review it regularly and treat the improvement actions as a working roadmap rather than a compliance checkbox.

If you’d like Tyto to review your Secure Score and prioritise the actions that matter most for your environment, call us on 1300 070 565 or visit tyto.net.au.

Need support ‍now?

Having an IT issue right now? Call our helpdesk on 1300 070 565 — you’ll speak to a real engineer who already knows IT, not a call centre script.
Support Portal
Circular dark gray button with a white arrow pointing diagonally up and right.Black arrow pointing diagonally upward and to the right on white background.

empowering businesses with tailored IT solutions

Contact Us Now
©2026 Tyto. All rights reserved.