Study guide
Technical reference and lesson notes
Purpose of This Lesson
This lesson introduces Microsoft Secure Score inside Microsoft Defender and explains how it helps organizations improve their overall security posture.
For the SC-200 Microsoft Security Operations Analyst exam, Secure Score is important because it connects directly to posture management, risk reduction, and proactive security operations. While many SOC tasks focus on detecting and responding to active threats, Secure Score helps identify security controls that should be strengthened before those threats become incidents.
A Microsoft Security Operations Analyst may use Secure Score to review recommended actions, identify gaps in identity, device, app, and data protection, and help prioritize improvements that reduce organizational risk.
Key Concepts
What Is Security Posture?
Security posture refers to the current strength, maturity, and readiness of an organization’s security environment.
It is not something you configure once and forget. Security posture changes over time because:
- New threats are discovered.
- Attack techniques evolve.
- Microsoft adds new security recommendations.
- Users, devices, applications, and cloud resources change.
- Misconfigurations or exceptions may be introduced.
- Security controls can drift from their intended state.
A tenant may have strong security today, but if no one maintains it, the environment can become weaker over time. This is why security posture management is an ongoing process.
For SC-200, think of security posture as the proactive side of security operations. It is about reducing risk before alerts and incidents occur.
What Is Microsoft Secure Score?
Microsoft Secure Score is a posture management feature available in the Microsoft Defender portal. It evaluates an organization’s security configuration and provides a score based on implemented security controls.
Secure Score helps answer questions such as:
- How secure is the tenant compared to Microsoft recommendations?
- Which security controls are already implemented?
- Which recommended actions are still outstanding?
- Which areas need the most attention?
- Has the environment improved or regressed over time?
- Which improvements would increase the score?
Secure Score does not replace incident investigation tools, hunting queries, or SIEM analytics. Instead, it helps security teams identify hardening opportunities across Microsoft 365, Defender, identity, devices, apps, and data protection.
Where to Find Secure Score
Secure Score is available from the Microsoft security experience, commonly accessed through the Microsoft Defender portal.
Typical navigation flow:
- Go to the Microsoft portal.
- Open the security area.
- Enter Microsoft Defender.
- Select Secure Score.
From there, you can view the organization’s current score, categories, recommended actions, historical changes, and metrics.
For exam purposes, associate Secure Score with Microsoft Defender / Microsoft 365 security posture recommendations, not Microsoft Sentinel incident generation.
How Secure Score Is Calculated
Secure Score evaluates the resources and services available in your tenant based on the licenses and subscriptions assigned to the organization.
Microsoft then compares your configuration against recommended security actions. Points are awarded when recommended controls are implemented.
Secure Score can consider areas such as:
- Identity security
- Device security
- Data protection
- App security
- Microsoft 365 security configurations
- Defender-related protections
- Azure-related resources, depending on the environment and licensing
The score is also compared against similar organizations, which can help provide context for whether your environment is stronger or weaker than comparable tenants.
Important point: Secure Score is not a perfect measurement of security. It is a Microsoft-guided posture indicator. It helps prioritize improvements, but analysts and administrators still need to apply judgment.
Secure Score Categories
Secure Score organizes recommendations into major categories. These may include areas such as:
Identity
Identity recommendations focus on user and authentication protections.
Examples may include:
- Enabling multifactor authentication.
- Reducing risky sign-in exposure.
- Strengthening administrative account protections.
- Improving identity-based access controls.
Identity is one of the most important security areas because compromised credentials are a common entry point for attackers.
Devices
Device recommendations focus on endpoint security and management.
Examples may include:
- Requiring endpoint protection.
- Enforcing mobile device management policies.
- Improving device compliance.
- Strengthening endpoint security settings.
- Enabling encryption such as BitLocker where applicable.
Device-related posture is especially relevant to Defender for Endpoint and Intune-managed environments.
Apps
App recommendations focus on application access, cloud app security, and configuration risks.
This may include controls around app permissions, application governance, and cloud-based access risks.
Data
Data recommendations focus on protecting sensitive information.
This may include controls related to encryption, information protection, data loss prevention, and secure access to organizational content.
Recommended Actions
The most useful part of Secure Score is the recommended actions section.
Recommended actions show specific improvements Microsoft suggests for the tenant. Each recommendation usually includes:
- A description of the security improvement.
- The affected product or security area.
- The number of points available.
- Implementation guidance.
- Links to Microsoft documentation.
- Step-by-step remediation instructions in many cases.
Examples of recommended actions may include:
- Enable multifactor authentication for all users.
- Require advanced security configurations for managed devices.
- Strengthen Remote Desktop security settings.
- Require secure protocols such as Transport Layer Security.
- Improve mobile device management policy enforcement.
For SC-200, understand that Secure Score does more than display a number. It provides actionable recommendations that can guide posture improvement.
Secure Score History
Secure Score includes historical tracking so analysts and administrators can see whether the organization is improving or regressing.
The history view may show:
- Score changes over time.
- Recently completed actions.
- Recently added recommendations.
- Recently updated recommendations.
- Actions that increased the score.
- Areas where security posture declined.
This is useful in real environments because security teams need to show progress, validate changes, and identify when controls were weakened.
For example, if a setting related to Remote Desktop security was improved, the history may show a positive score change tied to that action.
Planned Actions and Accepted Risk
Secure Score supports workflow-oriented tracking, including states such as:
- Actions to address
- Planned actions
- Risk accepted
- Recently added
- Recently updated
This matters because not every recommendation can be implemented immediately.
An organization may delay or accept risk for reasons such as:
- Business compatibility requirements
- Legacy application dependencies
- Change control windows
- User impact
- Licensing constraints
- Need for testing
- Operational risk
For the SC-200 exam, remember that security operations is not only about finding problems. It is also about prioritizing remediation, documenting risk, and working with responsible teams.
Metrics and Trends
Secure Score can show trends and metrics over time. In a small lab environment, there may not be much data. In a larger production tenant, trends can help identify patterns such as:
- Users frequently affected by malware.
- Device security weaknesses.
- Repeated configuration gaps.
- Areas where posture is improving.
- Areas where security controls are weakening.
This makes Secure Score useful for posture reporting and continuous improvement.
Microsoft Security Operations Context
How Secure Score Fits Into SOC Work
Secure Score is not primarily an alert triage tool. It is a posture improvement and risk reduction tool.
A SOC analyst may use Secure Score to:
- Identify weak security controls.
- Recommend improvements to reduce future incidents.
- Prioritize remediation work.
- Track posture progress over time.
- Support security reviews.
- Provide evidence for governance or compliance discussions.
- Coordinate with identity, endpoint, cloud, and infrastructure teams.
In a mature SOC, Secure Score can feed into a broader security improvement process. For example, if analysts repeatedly investigate credential-based attacks, MFA-related Secure Score recommendations become highly relevant.
Triage and Investigation Relevance
Secure Score is not where an analyst would typically start when investigating an active incident. For active alerts and incidents, the analyst would usually use:
- Microsoft Defender XDR incidents and alerts
- Defender for Endpoint device timeline
- Defender for Identity alerts
- Defender for Office 365 email investigations
- Microsoft Sentinel incidents
- KQL hunting queries
- Entity pages and evidence
However, Secure Score can help after an investigation by identifying controls that would reduce recurrence.
Example:
A SOC investigates a compromised user account. During post-incident review, the analyst notices that MFA was not enforced for all users. Secure Score may contain a recommendation to enable MFA broadly. That recommendation becomes part of the remediation and hardening plan.
Determining Scope and Impact
Secure Score does not directly determine the scope of an active compromise. Instead, it helps identify control gaps that may increase exposure.
For example:
- Missing MFA increases identity compromise risk.
- Weak device management increases endpoint risk.
- Poor mobile device policies increase data exposure.
- Insecure remote access settings increase lateral movement risk.
Scope and impact analysis still requires investigation tools, logs, alerts, entities, and evidence.
Containment and Remediation
Secure Score recommendations may lead to remediation actions, but they should usually be implemented through proper change control.
Examples:
- Enabling MFA tenant-wide may affect all users.
- Enforcing mobile device compliance may block unmanaged devices.
- Changing RDP security requirements may affect remote administration workflows.
- Enabling encryption requirements may require endpoint readiness checks.
A SOC analyst may recommend these changes, but implementation may involve identity administrators, endpoint engineers, infrastructure teams, or change advisory processes.
Documentation and Continuous Improvement
Secure Score is useful for documentation because it provides:
- Current posture score
- Completed actions
- Outstanding recommendations
- Historical trend data
- Evidence of improvement
- Justification for security projects
This supports real SOC processes such as:
- Post-incident reviews
- Monthly security reporting
- Risk register updates
- Compliance readiness
- Security roadmap planning
- Executive posture reporting
Exam-Relevant Takeaways
For the SC-200 exam, remember these points:
- Secure Score is used to assess and improve security posture.
- It is found in the Microsoft Defender security experience.
- It provides recommended actions based on Microsoft security best practices.
- It evaluates controls across categories such as identity, data, devices, and apps.
- It can show historical score changes and posture trends.
- It helps prioritize security improvements but is not an incident investigation tool.
- Secure Score recommendations may include implementation guidance and documentation.
- A low score does not automatically mean the tenant is compromised.
- A high score does not guarantee the tenant is secure.
- Secure Score should be used with operational judgment, testing, and change control.
- For active detection and response, use Defender XDR incidents, Defender product alerts, Sentinel incidents, or hunting queries.
- For posture improvement, use Secure Score recommendations.
Tool / Feature Decision Guide
| Scenario | Best Microsoft Security Tool or Feature | Why |
|---|---|---|
| You need to identify recommended security configuration improvements across Microsoft 365 and Defender | Microsoft Secure Score | Secure Score evaluates posture and provides prioritized recommendations |
| You need to investigate an active security incident involving multiple alerts | Microsoft Defender XDR incidents | Defender XDR correlates alerts and evidence into incidents for investigation |
| You need to ingest logs from multiple cloud, on-premises, and third-party systems | Microsoft Sentinel data connectors | Sentinel depends on connected data sources for SIEM visibility |
| You need to create scheduled detection logic from KQL | Microsoft Sentinel analytics rules | Analytics rules generate alerts and incidents based on query logic |
| You need to automate actions after an incident is created | Microsoft Sentinel automation rules | Automation rules can trigger actions or playbooks based on incident conditions |
| You need to run a security improvement program over time | Microsoft Secure Score | Secure Score tracks improvements, regressions, and recommended actions |
| You need to review a device timeline after malware execution | Microsoft Defender for Endpoint | Defender for Endpoint provides endpoint investigation and response capabilities |
| You need to review risky authentication or identity-related security gaps | Microsoft Secure Score and Microsoft Entra ID security features | Secure Score identifies posture gaps; Entra provides identity controls |
| You need to determine whether an email was malicious and who received it | Microsoft Defender for Office 365 | Defender for Office 365 focuses on email, attachments, URLs, and mailbox threats |
| You need a dashboard-style view of Sentinel data | Microsoft Sentinel workbooks | Workbooks visualize security data and trends |
KQL Notes
This lesson does not introduce KQL or hunting queries.
That is an important distinction for the exam:
- Secure Score is used for posture recommendations.
- KQL is used in Microsoft Sentinel and Defender advanced hunting to query security data.
- Analytics rules use KQL to generate detections in Sentinel.
- Hunting queries use KQL to investigate suspicious activity.
Do not confuse Secure Score recommendations with KQL-based detections. Secure Score tells you what security controls should be improved. KQL helps you search logs and detect suspicious behavior.
Common Exam Traps
Trap 1: Confusing Secure Score with Incident Investigation
Secure Score does not replace incident investigation.
If the question asks how to investigate a compromised device, mailbox, user, or alert, the answer is more likely to involve Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity, or Sentinel.
If the question asks how to improve security posture or review recommended security actions, Secure Score is likely the correct answer.
Trap 2: Treating the Score as a Guarantee of Security
A high Secure Score does not guarantee that the organization is secure.
It means many Microsoft-recommended controls have been implemented. Security still depends on monitoring, detection, response, user behavior, application security, infrastructure design, and operational discipline.
Trap 3: Ignoring Licensing and Available Services
Secure Score recommendations depend on the Microsoft services, licenses, and subscriptions available in the tenant.
If a feature is not licensed or not deployed, it may affect which recommendations appear or how they can be implemented.
Trap 4: Applying Recommendations Without Change Control
Some Secure Score recommendations can have tenant-wide impact.
Examples include:
- Enforcing MFA for all users.
- Changing device compliance requirements.
- Requiring mobile device management.
- Strengthening remote access settings.
In production, these changes should be tested, communicated, and implemented through proper change control.
Trap 5: Confusing Posture Management with SIEM Detection
Microsoft Sentinel is used for SIEM/SOAR workflows, including log ingestion, analytics rules, incidents, automation, hunting, and workbooks.
Secure Score is used for posture management and recommended security improvements.
Real-World SOC Analyst Notes
Secure Score Helps Reduce Alert Volume Over Time
A weak security posture can create more alerts. For example, if MFA is not enforced, the SOC may see more identity-related incidents. If device policies are weak, endpoint compromise risk increases.
Improving Secure Score recommendations can help reduce preventable incidents and alert fatigue.
Recommendations Still Need Operational Review
Not every recommendation should be implemented immediately.
Before applying a Secure Score recommendation, consider:
- User impact
- Business-critical applications
- Legacy systems
- Admin access requirements
- Remote access dependencies
- Break-glass accounts
- Licensing
- Testing requirements
- Rollback plan
- Change control
A SOC analyst may identify the risk, but implementation often requires coordination with other teams.
Secure Score Can Support Post-Incident Hardening
After an incident, Secure Score can help identify control gaps that contributed to the event.
Example:
If an attacker used stolen credentials, MFA recommendations become highly relevant.
If an attacker moved laterally using insecure remote access, recommendations related to RDP, endpoint hardening, or device configuration may become part of the corrective action plan.
Secure Score Is Useful for Governance
Secure Score can provide evidence that the organization is actively improving security posture.
This can support:
- Internal audits
- Security steering meetings
- Risk reviews
- Compliance readiness
- Client reporting
- Executive summaries
- Security roadmap planning
However, Secure Score should be presented as a posture indicator, not a full risk assessment.
Be Careful With Tenant-Wide Changes
Some recommendations may sound simple but have broad impact.
For example, requiring MFA for all users is usually a strong security control, but rollout should account for:
- Emergency access accounts
- Conditional Access policies
- Service accounts
- Legacy authentication
- User enrollment
- Help desk readiness
- Communication plan
SOC analysts should understand the security value while recognizing the operational impact.
Quick Reference Summary
- Secure Score helps measure and improve Microsoft security posture.
- Security posture must be maintained continuously.
- Secure Score provides recommended actions, documentation, and implementation guidance.
- Categories may include identity, data, devices, and apps.
- Score history shows improvement or regression over time.
- Secure Score is proactive, not primarily investigative.
- Use Defender XDR or Sentinel for active incident investigation.
- Use Secure Score for hardening, posture management, and risk reduction.
- Recommendations should be reviewed with business impact and change control in mind.
- Secure Score is useful for SC-200 scenario questions about improving security configuration.
Flashcards
Q: What is Microsoft Secure Score used for?
A: It is used to assess and improve an organization’s Microsoft security posture through recommended actions.
Q: Is Secure Score primarily an incident investigation tool?
A: No. It is primarily a posture management and security improvement tool.
Q: What does security posture mean?
A: The current strength and readiness of an organization’s security controls, configurations, and defenses.
Q: Why can security posture decline over time?
A: Threats evolve, environments change, controls drift, and new vulnerabilities or recommendations appear.
Q: Where would you typically access Secure Score?
A: In the Microsoft Defender security experience.
Q: What kinds of categories can Secure Score evaluate?
A: Identity, data, devices, apps, and other Microsoft security-related areas depending on licensing and services.
Q: What does Secure Score provide besides a number?
A: Recommended actions, descriptions, implementation guidance, documentation, and historical trends.
Q: What is an example of a Secure Score recommendation?
A: Enabling multifactor authentication for all users.
Q: Should Secure Score recommendations always be implemented immediately?
A: No. They should be reviewed for business impact, tested, and handled through proper change control when needed.
Q: What tool should be used for active incident investigation across Defender alerts?
A: Microsoft Defender XDR incidents.
Q: What tool should be used for SIEM detection rules based on KQL?
A: Microsoft Sentinel analytics rules.
Q: Can Secure Score show whether posture improved or regressed?
A: Yes. Secure Score includes history and trend information.
Q: Does a high Secure Score guarantee security?
A: No. It indicates progress against Microsoft recommendations but does not guarantee complete security.
Q: How can Secure Score help after an incident?
A: It can identify recommended controls that may reduce recurrence of similar incidents.
Q: Why is MFA commonly important in Secure Score and SOC operations?
A: MFA reduces the risk of credential-based compromise, which is a common attack path.
Practice Questions
Question 1:
A security operations analyst wants to identify Microsoft-recommended configuration changes that would improve the organization’s security posture across identity, devices, apps, and data. Which tool should the analyst use?
A. Microsoft Sentinel analytics rules
B. Microsoft Secure Score
C. Microsoft Defender for Endpoint device timeline
D. Microsoft Sentinel watchlists
Correct Answer:
B. Microsoft Secure Score
Explanation:
Secure Score is designed to assess security posture and recommend improvements. Sentinel analytics rules are used for detection logic, and Defender for Endpoint device timeline is used for endpoint investigation.
Question 2:
An organization has implemented several security controls, but the security manager wants to see whether the tenant’s posture has improved or regressed over time. Which Secure Score capability is most relevant?
A. Score history and trends
B. Incident queue
C. Advanced hunting schema
D. Data connector health
Correct Answer:
A. Score history and trends
Explanation:
Secure Score includes historical tracking that can show score changes, completed actions, and regressions over time.
Question 3:
A SOC analyst is investigating an active malware alert on a workstation and needs to review device activity, process execution, and related evidence. Which tool is more appropriate than Secure Score?
A. Microsoft Defender for Endpoint
B. Microsoft Secure Score
C. Microsoft Purview compliance portal
D. Microsoft Entra admin center billing page
Correct Answer:
A. Microsoft Defender for Endpoint
Explanation:
Secure Score helps with posture improvement, but active endpoint investigation should be performed with Defender for Endpoint capabilities such as device timeline and evidence review.
Question 4:
A Secure Score recommendation suggests enabling multifactor authentication for all users. What should the security team consider before implementing the change tenant-wide?
A. Whether the change should be tested and coordinated through change control
B. Whether Sentinel data connectors should be deleted first
C. Whether all incidents should be closed automatically
D. Whether Secure Score should be disabled after implementation
Correct Answer:
A. Whether the change should be tested and coordinated through change control
Explanation:
MFA is a strong security control, but tenant-wide enforcement can affect users, service accounts, emergency access accounts, and legacy authentication. It should be planned and tested.
Question 5:
Which statement best describes the difference between Microsoft Secure Score and Microsoft Sentinel analytics rules?
A. Secure Score creates KQL detections, while analytics rules only show posture recommendations.
B. Secure Score helps improve posture, while analytics rules detect activity from connected data sources.
C. Secure Score is used only for email threats, while analytics rules are used only for endpoint threats.
D. Secure Score replaces the need for incident investigation.
Correct Answer:
B. Secure Score helps improve posture, while analytics rules detect activity from connected data sources.
Explanation:
Secure Score provides posture recommendations. Sentinel analytics rules use KQL logic against connected data sources to generate alerts and incidents.