
Microsoft Secure Score is one of the most useful — and most underused — tools available to any Australian business running Microsoft 365. It measures the security posture of your Microsoft environment against a set of recommended controls, assigns a numerical score, and gives you a ranked list of specific improvements you can make, along with the point value of each one. For a business that wants to improve its security without guesswork, Secure Score is an excellent place to start.
This guide walks you through accessing your score, interpreting what it means, and prioritising the actions that will deliver the most meaningful improvement in the least time.
You’ll need a Global Administrator, Security Administrator, or Security Reader role in your Microsoft 365 tenant.
Your score is shown as a number out of the total achievable score. The percentage reflects how many of the available controls your environment currently has in place. Don’t be alarmed if the number looks low — the total achievable score includes enterprise-grade controls that are genuinely out of scope for many small businesses.
Secure Score separates your environment into three categories:
Click on Improvement actions to see the full list, ordered by the number of points each action is worth. Each action includes a description of what the control does, the number of score points it contributes, the status of the control in your environment, and the licensing required to implement it.
Start by filtering to Incomplete actions to focus only on what needs attention.
Not every Secure Score recommendation carries equal weight for your business. The practical priority should be based on three questions:
For most Australian businesses with 10–100 staff on Microsoft 365, the highest-impact incomplete actions tend to cluster in three areas: identity protections beyond basic MFA, email and collaboration security, and admin account hygiene.
Here are the actions that appear most frequently as incomplete in small-to-medium Australian Microsoft 365 tenants — and that deliver meaningful protection improvement:
If you’re already using the Microsoft Authenticator app, enabling number matching prevents MFA fatigue attacks — where an attacker sends repeated push notifications hoping the user approves one by mistake. Enable this in Microsoft Entra ID → Security → Authentication methods → Microsoft Authenticator → Configure.
Older authentication methods — SMTP AUTH, IMAP, POP — don’t support MFA. Attackers exploit this to bypass modern authentication controls. A Conditional Access policy blocking legacy authentication for all users closes this gap and is typically worth 15–20 score points.
Admin accounts are the highest-value targets in your Microsoft 365 environment. A Conditional Access policy requiring phishing-resistant MFA — FIDO2 security keys or Windows Hello for Business — for Global Administrators provides meaningfully stronger protection than standard push-based MFA.
If your subscription includes Defender for Office 365 (included in Microsoft 365 Business Premium), enabling Safe Links and Safe Attachments adds a real-time scanning layer for malicious URLs and email attachments. These are disabled by default and need to be explicitly configured in the Microsoft Defender portal under Email & collaboration → Policies & rules.
If your IT administrators are using their regular email account as their admin account, this is a meaningful configuration risk. Dedicated admin accounts — used only for administrative tasks — limit the damage if a standard user account is compromised. Secure Score flags admin accounts that are also used for everyday activity.
Secure Score updates within 24–48 hours of a change being made. After implementing an improvement action, revisit your score the next day to confirm it has registered and to see the updated action list.
Set a target score for your organisation — a realistic goal for a Microsoft 365 Business Premium environment is typically 60–75% of the available score for your licensing tier. Tracking your score monthly creates a clear, auditable record of your security posture improvement over time, which is useful for insurance purposes, client due diligence, and board-level reporting.
A monthly review is appropriate for most Australian businesses. New improvement actions are added to Secure Score as Microsoft releases new controls and updates existing recommendations. A quarterly deep review with your IT provider is also valuable — some actions require technical implementation that goes beyond what an in-house administrator would typically handle alone.
No. Secure Score measures configuration controls within Microsoft 365 and connected services — it does not account for your physical security, your staff awareness posture, your third-party software vulnerabilities, or your incident response capability. A high score indicates strong Microsoft 365 configuration, which is a significant component of your overall security posture, not the complete picture.
Some improvement actions are available with any Microsoft 365 licence tier. Others require Microsoft 365 Business Premium, Microsoft Entra ID P1 or P2, or Microsoft Defender add-ons. Secure Score labels each action with the required licence level. If a recommended action requires a higher licence tier, evaluate whether the security value justifies the cost — your Microsoft partner can help with that assessment.
Microsoft Secure Score is not a pass/fail test — it’s a continuous improvement tool. The businesses that get the most from it review it regularly and treat the improvement actions as a working roadmap rather than a compliance checkbox.
If you’d like Tyto to review your Secure Score and prioritise the actions that matter most for your environment, call us on 1300 070 565 or visit tyto.net.au.