Boost Your Business Security: The Overlooked M365 Secure Score Metric
All dispatches
IT Support1 Apr 202610 min read

Boost Your Business Security: The Overlooked M365 Secure Score Metric

Joe Welch
Joe Welch
Head of Engineering · Black Sheep Support
Share this dispatch

For many UK SMEs, Microsoft 365 (M365) forms the operational backbone of their business. It capably handles email, provides robust document storage in SharePoint, and facilitates team collaboration through Teams. This extensive reliance, however, often cultivates a dangerous assumption: that a premium cloud service automatically equates to comprehensive security. Business owners frequently treat M365 as a 'set it and forget it' utility, inadvertently overlooking their active and crucial role in its ongoing defence. While Microsoft secures the underlying infrastructure, the onus for protecting your specific data, user identities, and access points falls squarely on your organisation. The Microsoft 365 Secure Score is a powerful, yet frequently ignored, tool specifically designed to clarify and measurably improve your security posture within this shared responsibility model. It provides a clear roadmap to a more defensible environment.

What M365 Secure Score actually means

The M365 Secure Score is essentially a quantifiable assessment of your organisation's security configuration within your Microsoft 365 tenant. Accessible via the Microsoft 365 Defender portal (security.microsoft.com), it provides a numerical score out of a possible total, indicating how well your tenant adheres to Microsoft's recommended security best practices. Think of it less as a static report and more as a rolling, dynamic audit. It doesn’t just highlight vulnerabilities; it also offers specific, actionable recommendations to improve your score. Each recommendation, when implemented, contributes points, thereby increasing your overall percentage. The higher the score, the more closely your M365 environment aligns with a robust security posture, significantly reducing common attack vectors and bolstering your overall cyber defence. It’s an objective, practical measure of your current defensive strength, updated daily.

Why it matters for UK SMEs

For UK SMEs, the M365 Secure Score is not merely a technical curiosity; it is a critical indicator of business risk and potential compliance shortcomings. The 'Shared Responsibility Model' underpins this necessity. Microsoft unequivocally secures the cloud infrastructure itself – that includes the physical data centres, the underlying network, and the core platform services. Your responsibility, however, lies unequivocally in securing what you put in the cloud: your data, your user identities, the devices your staff use, and the applications integrated with your tenant. A consistently low Secure Score signals a failure in this fundamental duty, leaving your organisation unduly exposed.

Commercially, this translates into tangible and often severe risks. A compromised M365 tenant can lead directly to debilitating data breaches, significant business disruption, and substantial financial loss. The Information Commissioner's Office (ICO) in the UK takes a dim view of organisations that demonstrably fail to implement appropriate security measures under UK GDPR. Article 32 of the UK GDPR mandates 'appropriate technical and organisational measures' to ensure a level of security appropriate to the risk. A demonstrably low Secure Score could, quite reasonably, be interpreted as a failure to meet this obligation, potentially leading to substantial fines, mandatory reporting requirements, and severe reputational damage that takes years to repair.

Furthermore, many UK businesses, particularly those engaged with government contracts or operating within larger, more stringent supply chains, are increasingly required to demonstrate adherence to recognised frameworks like Cyber Essentials. The NCSC (National Cyber Security Centre) actively promotes Cyber Essentials as a pragmatic baseline for good cyber hygiene. A strong Secure Score directly supports several of the Cyber Essentials controls, particularly those concerning secure configuration, access control, and malware protection. Ignoring your Secure Score is, therefore, akin to knowingly leaving your business exposed to prevalent threats, jeopardising not only your operational continuity but also your ability to win new work, maintain client trust, and satisfy regulatory bodies. It’s a direct measure of your proactive security commitment.

How to improve your Secure Score, a practical walkthrough

Improving your M365 Secure Score requires a systematic and disciplined approach, starting with a thorough understanding of the dashboard and then implementing targeted, prioritised changes. It is not a one-off fix; it's an ongoing programme of security work that evolves with the threat landscape and your business operations.

Accessing and Interpreting Your Score

Your Secure Score is located within the Microsoft 365 Defender portal (security.microsoft.com). After logging in, navigate to 'Secure Score' in the left-hand menu. Here, you will find your current score presented as a percentage, a historical trend graph, and a comprehensive breakdown of recommended actions. Each recommendation provides critical details: the potential points you can gain, the estimated user impact (from low to high), and the implementation cost (none, minimal, moderate, or high). This granular view is invaluable for effective prioritisation. As a general rule, focus initially on 'Recommended Actions' with high point values and low user impact; these often provide the quickest and most impactful gains with minimal disruption to your daily operations. The dashboard also categorises recommendations, typically by:

  • Identity: This category, frequently the most heavily weighted, focuses on user accounts and their authentication methods. It addresses the enforcement of Multi-Factor Authentication (MFA), the disabling of legacy authentication protocols, and the implementation of robust password policies. A strong identity posture is the foundational element of any effective M365 security strategy.
  • Data: This category evaluates how effectively you are protecting sensitive information stored within your M365 environment. It includes recommendations around implementing sensitivity labels, configuring data loss prevention (DLP) policies, and ensuring appropriate encryption is in place. The overarching goal is to identify, classify, and safeguard Personally Identifiable Information (PII) and other critical business data.
  • Devices: This section assesses the security posture of endpoints (laptops, mobile phones, tablets) accessing your M365 environment. It tracks whether devices are managed via Microsoft Intune or Defender for Endpoint, ensuring they comply with essential security policies such as disk encryption, up-to-date operating systems, and antivirus definitions.
  • Apps: This category focuses on the security of third-party applications integrated with your M365 tenant. It highlights risks associated with excessive permissions granted to these applications, which can inadvertently create backdoors into your data, email systems, or other sensitive areas.

High-Impact Actions to Elevate Your Score

While the Secure Score provides a multitude of recommendations, some actions offer a significantly higher return on effort for UK SMEs. These are the areas we typically address first when onboarding new clients, as they provide fundamental improvements.

  1. Enforce Phishing-Resistant Multi-Factor Authentication (MFA): This is absolutely non-negotiable. Traditional SMS or voice-call MFA can be bypassed through sophisticated phishing or SIM-swapping attacks. The Secure Score heavily rewards organisations that move to stronger methods like the Microsoft Authenticator app (especially with number matching enabled) or FIDO2 security keys. This single change drastically reduces the risk of account compromise, which remains the leading cause of breaches. On a recent tenant audit for a 60-user Surrey-based logistics firm, we found 42 users had no MFA enrolled at all, and a further 15 were relying on easily compromised SMS methods. Implementing phishing-resistant MFA across the board immediately boosted their Secure Score by 28% and significantly hardened their perimeter against identity-based attacks.

  2. Disable Legacy Authentication Protocols: Protocols such as POP, IMAP, and older versions of SMTP are outdated and inherently insecure because they do not support modern MFA. Attackers actively target these protocols as easy entry points to gain unauthorised access to mailboxes. Disabling them in your M365 tenant is a quick win for your Secure Score and eliminates a pervasive attack vector. It's worth noting that some older, niche applications might still rely on these protocols, so careful planning and testing are required to avoid business disruption, but the security gain is substantial.

  3. Implement Conditional Access Policies: Conditional Access acts as your M365 security guard, enforcing 'if-then' rules for access attempts. For example, you can mandate MFA for logins originating from unmanaged devices, block access from specific high-risk countries, or require devices to be compliant with your security policies before accessing sensitive data. This granular control is vital for managing risks associated with remote or hybrid working models and is a significant contributor to your Secure Score. It allows for flexible but rigorously secure access.

  4. Onboard Devices to Microsoft Intune and/or Defender for Endpoint: Managing your endpoints (laptops, mobile phones) through Intune ensures they meet your specified security standards before they can access M365 data. This includes enforcing disk encryption, ensuring operating systems are patched and up-to-date, and deploying advanced antivirus solutions like Defender for Endpoint. A device that isn't compliant shouldn't be accessing your company's sensitive information. This aligns directly with Cyber Essentials requirements for secure configuration and malware protection, providing a tangible layer of defence.

  5. Configure Data Loss Prevention (DLP) and Sensitivity Labels: Protecting your data isn't just about who accesses it; it's also about how it's used and shared. DLP policies can prevent sensitive information (such as client bank details, credit card numbers, or personally identifiable information) from inadvertently leaving your organisation via email, external file sharing, or other channels. Sensitivity labels, on the other hand, allow you to classify data (e.g., 'Confidential', 'Internal Only') and apply automatic protection, such as encryption or access restrictions, wherever that data travels. This proactive data governance is crucial for GDPR compliance.

  6. Review and Limit Administrative Privileges: Accounts with global administrator or other highly privileged roles are prime targets for attackers. A core security principle is the 'principle of least privilege', meaning users should only have the permissions necessary to perform their job functions. Regularly review who holds administrative roles, ensure these accounts are protected with the strongest MFA, and consider implementing Privileged Identity Management (PIM) to grant elevated access only when explicitly required and for a limited time. Reducing the attack surface for privileged accounts is a high-impact security measure.

Common mistakes we see

Even with the best intentions, SMEs often make predictable errors when approaching their M365 Secure Score:

  • Treating it as a one-off task: Secure Score is a dynamic metric; security is an ongoing process, not a destination.
  • Focusing solely on the score, not the underlying security: The number is an indicator, not the sole objective. The goal is real risk reduction.
  • Ignoring user impact: Implementing changes without considering how they affect staff can lead to workarounds or resistance, undermining security.
  • Neglecting third-party app permissions: Many organisations overlook the extensive permissions granted to integrated applications, creating significant backdoors.
  • Lack of executive buy-in: Without senior management understanding and support, implementing necessary security changes often stalls.

Key Takeaways

  • M365 Secure Score provides a quantifiable, actionable measure of your tenant's security.
  • It highlights your responsibilities within the shared security model.
  • Improving your score is critical for UK GDPR compliance and Cyber Essentials alignment.
  • Phishing-resistant MFA and disabling legacy authentication are foundational steps.
  • It's an ongoing security programme, not a one-time configuration.

When to call in help

For many UK SMEs, the resources, time, or specialist expertise required to effectively manage and significantly improve their M365 Secure Score simply aren't available internally. Interpreting the recommendations, understanding the potential impact of changes, and implementing them without disrupting business operations can be complex. If you lack a dedicated in-house IT security team, or if your current IT support struggles with advanced M365 security configurations, bringing in external expertise is a pragmatic decision. An experienced managed IT and cyber security provider can efficiently audit your tenant, prioritise high-impact actions, and implement the necessary changes, ensuring your M365 environment is secured to best practice standards, allowing you to focus on running your business. Frankly, not everyone has the time or inclination to become an M365 security expert, and that's perfectly acceptable.

To take the next step

Book a Discovery Call

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.