Microsoft 365 security score

"How secure are we?" One number, measured from both halves.

Microsoft Secure Score rates what you configured, and 1Security shows it exactly as the Defender portal reports it - guidance, peer averages and deep links included. Next to it sits a second score, measured from what actually happens: sensitive data actually reachable, agents without an accountable owner, accounts dormant for months, sign-ins outside every policy. Both halves land in one worklist ranked by the points still on the table, with ninety days of history to prove the trend.

  • 2 scores
    configuration as Microsoft rates it, reality as 1Security measures it
  • 90 days
    of daily history for both halves, with remediation actions counted alongside
  • 5 min
    the shortlist: the highest-value fixes if that is all the time you have

The problem

The score moved. Did the tenant?

Ask for a Microsoft 365 security score today and you get a well-built answer about configuration: Secure Score checks which recommended settings are on, weights them by impact, and attaches remediation guidance written by the people who build the products. That number is genuinely useful, and 1Security shows it untouched, deep links and all.

What no configuration check can see is behavior. A Conditional Access policy earns its points the day it is switched on - whether real sign-ins actually pass through it is a different fact, and it changes with every hire, every guest and every new app. Data works the same way: a tenant can carry a strong score while payment-card files sit reachable by half the company.

So the board hears a number that answers "what did we configure" and takes it as "how secure are we". The distance between those two questions is where incidents start, and it never shows up in a number built from settings alone.

What you get

Both halves of the truth, on one page.

Every control - Microsoft's and 1Security's - lands in the same list, keeps its own evidence, and links to the place where it gets fixed.

  • Secure Score, verbatim

    Microsoft Secure Score exactly as the Defender portal reports it: score, tier, rank, threat tags, Microsoft's own remediation text and a deep link to the setting. No re-scoring, no editorializing - the Microsoft half stays Microsoft's.

  • A second score, measured

    The 1Security half is computed from observed facts: restricted data actually reachable, agents actually lacking an accountable owner, accounts actually dormant, sign-ins actually outside coverage. Every verdict carries its evidence, not a checkbox.

  • Two controls per fact, on purpose

    Where both providers measure the same thing - device compliance, dormant accounts, label protection - they stay separate. A policy that is configured but not covering real sign-ins is precisely the insight one merged number would hide.

  • One worklist, ranked by points

    Controls from both halves sort by the points still on the table, with the "if you only have 5 minutes" shortlist on top. Microsoft controls deep-link into the Defender portal; 1Security controls link to the exact screen where the finding is acted on.

  • Categories no configuration score carries

    AI & agents, observed data exposure, monitoring & response: accountable owners, restricted types actually reachable, outbound sharing to consumer mailboxes, ingestion freshness, unhandled critical anomalies. Measured by 1Security, absent from any settings checklist.

  • Waivers, peers and history

    A control that genuinely does not apply is waived with a note and leaves the possible total - the note stays on record, and the measured value itself is never editable. Microsoft's comparative averages place you against your size band and industry; ninety days of daily history show the trend.

How deep it goes

From one number to the next fix, without leaving the page.

Board preparation, worked end to end - the loop the screen was built for.

Open the screen on Monday and three figures sit side by side: Secure Score as the Defender portal reports it, the score 1Security measured from your tenant, and the combined headline. Under them, the comparison Microsoft publishes for all tenants, your size band and your industry - so "are we behind our peers" is read off the page, not estimated.

Then the worklist. A Microsoft control - block legacy authentication, say - carries Microsoft's own remediation text and a portal deep link. Right under it, a 1Security control carries its measured evidence: "14 of 92 agents have no accountable owner", one click from the agents screen where the owners get assigned. Both are ranked by the points they would return.

Fixing a 1Security control moves more than the score: each one cites the ISO 27001, NIS2 or EU AI Act articles its measurement satisfies, so the same fix advances the compliance picture. What does not apply is waived with a note that stays on record - the standing changes, the measurement never does.

In practice

Four steps to a defensible number.

The Microsoft half is optional and takes one consent to unlock.

  1. 01

    Grant one optional permission

    The 1Security half works from data the platform already collects. The Microsoft half needs a single read-only permission (SecurityEvents.Read.All), granted with one re-consent from the Integrations screen - no new app registration. Until then, the measured half stands alone.

  2. 02

    Read the three figures

    Secure Score verbatim, the measured score, and the combined headline - with Microsoft's peer averages for all tenants, your size band and your industry next to them.

  3. 03

    Work the five-minute shortlist

    The worklist ranks every control by points still on the table. Follow the deep link - into the Defender portal for Microsoft controls, into the exact 1Security screen for measured ones - and close the highest-value gap first.

  4. 04

    Track it, and hand it over

    Ninety days of daily history for both halves, with remediation actions counted alongside. The same score is served over the REST API and MCP, so the board pack and the quarterly review pull the number instead of screenshotting it.

The difference

What the measured half adds over Secure Score alone

The Microsoft half is kept exactly as Microsoft publishes it. Everything below is what the page adds around it.

  • A second score computed from observed behavior, not configuration state
  • The same fact scored twice on purpose - configured and observed, never merged
  • One worklist across both providers, ranked by points still on the table
  • The "if you only have 5 minutes" shortlist for the shortest security session
  • AI & agents, observed data exposure and monitoring & response as scored categories
  • Measured evidence on every 1Security control - counts, not checkboxes
  • Compliance cross-references: each control names the ISO 27001, NIS2 and EU AI Act articles it moves
  • Waive with a note, keep the record - and ninety days of daily history for both halves
  • The score over REST and MCP: GET /security-score under the evidence:read scope

Setup and scope

One optional permission, standard licenses, kept honest.

The measured half requires no premium Microsoft licensing - it is computed from the data 1Security already collects read-only. The Microsoft half arrives with whatever Secure Score your tenant already has, unlocked by a single optional read-only permission. Nothing on the page is editable except a control's standing: active, or waived with a note that stays on record.

  • 1 consent
    read-only SecurityEvents.Read.All unlocks the Microsoft half - no new app registration
  • 3 categories
    of our own: AI & agents, observed data exposure, monitoring & response
  • 90 days
    of daily history for both halves, remediation actions counted alongside

Related

Where this fits

The score is the summary. The three pages below are where its points come from - and where they get fixed.

  • Compliance

    The same measurements read from the framework side - eleven regulations evaluated from one requirement set.

    See compliance
  • Remediation automation

    Points on the table become staged actions with review windows and a recorded trail.

    See remediation
  • Anomaly detection

    Unhandled critical anomalies are one of the monitoring controls - this is where they come from.

    See anomalies

FAQ

Questions teams ask first

Is this just Secure Score with a different skin?

No - and the Microsoft half is deliberately not touched at all: same score, same tiers, same remediation text, same deep links you would see in the Defender portal. What the page adds is the second half: a score measured from observed activity, one worklist across both, and the compliance articles each control moves. The two halves answer different questions, which is why both are shown.

Do we need an E5 license for this?

No. The measured half runs on standard licensing, from data 1Security already collects. The Microsoft half shows whatever Secure Score your tenant already produces - it needs one optional read-only permission, not a license upgrade. Where an individual remediation does require a specific Microsoft SKU, the action itself says so upfront.

Can we exclude controls that do not apply to us?

Yes - waive the control with a note. It leaves the possible total entirely, the same semantics Microsoft uses for ignored controls, so the percentage stays meaningful for your actual environment. The note stays on record, and the measured value underneath is never editable: only the standing changes.

Does a higher score mean we are safe?

A score is a posture summary, not a guarantee - which is exactly why there are two of them here. The configured half can be strong while real sign-ins, reachable data or ungoverned agents say otherwise; the measured half exists to catch that. Treat the number as the trend line and the worklist as the point: the page always shows what to fix next.

How current is it, and can we export it?

The Microsoft half updates as the Defender portal publishes it; the measured half is refreshed continuously from scans and audit-log ingestion. Both keep ninety days of daily history. The score is also served programmatically - GET /security-score on the REST API and the get_security_score MCP tool, both read-only under the evidence:read scope.

Put both halves in front of the board.

Connect read-only, grant one optional permission, and open the next meeting with a number you can defend - plus the ranked list of what earns the next points.

Or keep reporting configuration as if it were reality.