For measuring your own Microsoft tenant, the stronger approach is validation against the baseline your organization approved. Microsoft Secure Score measures every tenant against the same set of Microsoft recommendations, so it cannot reflect the decisions your team has made about your own environment.
Secure Score is a common yardstick. Your baseline is specific to you, and checking against it also reaches areas that Secure Score’s recommendation list does not cover.
The core difference
- Secure Score is generic by design. Every tenant is measured against the same Microsoft recommendations.
- Your baseline is specific. It is the state your team approved for your risk and your regulatory requirements.
- Scope differs. Validation can also check Power Platform, Azure DevOps, AWS, GCP, shadow tenants and your external exposure.
- Drift is measured against your baseline. A finding means a setting moved away from what your team approved.
How does Microsoft Secure Score work?
Secure Score lists recommended actions for each product it covers and gives each one a point value. Some actions give points only when fully completed, and others give partial points when you cover some of your users or devices.
The recommendations cover products such as Microsoft Entra ID, Defender for Endpoint, Defender for Identity, Defender for Office, Exchange Online, SharePoint Online and Teams, along with some non-Microsoft services such as Okta, Salesforce and GitHub. Microsoft says these recommendations do not cover every attack surface of each product, and calls them a good baseline.
Source: Microsoft Learn, Microsoft Secure Score.
Why is Microsoft Secure Score generic?
The same recommended actions apply to every organization that uses Secure Score. You can mark a risk as accepted or credit an action to another tool, and the score still measures your tenant against Microsoft’s list. It has no way to know which settings your team approved or which exceptions are deliberate.
| Question | Microsoft Secure Score | Validation against your baseline |
|---|---|---|
| What is the yardstick? | Microsoft’s recommended actions, the same for every tenant | The baseline your team approved for your environment |
| Who defines what good looks like? | Microsoft | Your team, based on your risk and the frameworks you report against |
| What does it check? | The products on Microsoft’s recommendation list | Identity, Email, SharePoint, Teams, Defender XDR, Power Platform, Azure DevOps, GitHub, AWS and GCP, plus shadow tenants and external exposure |
| How is change reported? | The score moves as actions are completed | Drift detection flags settings that leave the approved state, with before and after values |
| What can you hand an auditor? | A score and its recommended actions | Findings mapped to 15 frameworks, with a history for each one |
What does measuring against your own baseline look like?
- Agree on your baseline. Your team decides the approved state for each control, based on your risk and the frameworks you report against.
- Validate every tenant against it. Scans run on a schedule your team configures and on demand, and each finding shows where a setting diverges from your baseline.
- Watch for drift between scans. Drift detection monitors critical controls and records each change with its before and after values.
- Fix in order of impact and keep the record. Findings connect into attack chains so you can fix what breaks the most paths first, and a risk register keeps each finding’s history.
For why drift matters between assessments, read what continuous control validation means for Microsoft security.
What can validation check that Secure Score does not?
Several areas sit outside Secure Score’s recommendation list. These are some of the places the Accelerynt Security Platform validates.
Shadow tenants
Entra tenants found on your own domains that nobody is managing.
Outside connected to inside
Exposure found across your domains, connected to the settings of the tenant behind it.
Code and pipelines
GitHub repository permissions and workflow secrets, plus Azure DevOps service connections and pipeline policies.
Attack chains
Findings connected into paths across Microsoft 365, Entra, Azure, AWS and GCP, with fixes ranked by impact.
Should you stop using Secure Score?
No. It remains a useful view of Microsoft’s recommendations, and the Accelerynt Security Platform uses Microsoft’s scoring as one of its inputs. The difference is the yardstick: the platform measures your tenant against your baseline, with read-only permissions.
For the full practice, read how to manage Microsoft 365 security and prove it works, and to compare your tenant with an independent benchmark, see how to check Microsoft 365 against the CIS benchmark.
Where to go next
To see where your tenant stands against a baseline, start with a Microsoft Control Validation Assessment. The platform FAQs explain how Secure Score and the platform fit together.
Frequently asked questions
Is there something better than Microsoft Secure Score?
For measuring your own tenant, yes: validation against the baseline your organization approved. Secure Score measures every tenant against the same Microsoft recommendations. A validation platform such as the Accelerynt Security Platform checks your tenant against your own baseline, covers areas outside Secure Score’s recommendation list, and uses Microsoft’s scoring as one of its inputs.
What does Microsoft Secure Score measure?
It measures how many of Microsoft’s recommended security actions your organization has taken. Each action carries points, some actions earn partial points when they cover only some users or devices, and a higher score means more recommended actions are in place.
Why doesn’t Secure Score reflect our own security decisions?
Its recommendations are the same for every organization. You can mark a risk as accepted or mark an action as covered by another tool, and the score still measures your tenant against Microsoft’s list instead of the baseline your team approved.
What is a security baseline?
It is the set of settings your team has approved as the correct state for your environment, based on your risk and your regulatory requirements. Validation checks the live tenant against that baseline and flags any setting that has drifted from it.
Does a high Secure Score mean we are secure?
Microsoft describes the score as a numerical summary of posture and says it is not an absolute measure of how likely a breach is. A high score shows that many recommended actions are in place. Whether your controls match your own baseline is a separate check.
