Strengthen your Entra ID setup with Identity Secure Score
In this post: What is Identity Secure Score? · Where to find it · Why it’s worth checking · How the score is actually calculated · When would you actually use this? · Best practices and how to implement them · Sample walkthrough: enforce MFA for admins
What is Identity Secure Score?
Identity Secure Score is the identity-focused slice of Microsoft Secure Score, found in the Microsoft 365 Defender portal. It scores how locked-down your Entra ID (Azure AD) setup is — MFA coverage, legacy authentication, admin role sprawl — and ranks what to fix first.
URL Reference:
https://security.microsoft.com/securescore
Where to find it
- Go to https://security.microsoft.com/securescore
- Open Secure Score from the left menu
- Filter by “Identity” to see just the Entra ID recommendations
Why it’s worth checking
Each recommendation comes with an impact score and clear implementation steps, and shows whether it’s implemented, partially implemented, or not at all. It’s aimed at IT admins, security auditors, and compliance teams who need a prioritized, measurable list of identity risks — not just a vague “improve security” mandate.
How the score is actually calculated
Identity Secure Score isn’t a single opaque number — it’s a percentage: points earned across every identity-related improvement action, divided by the total points available for actions applicable to your tenant. “Applicable” matters here — an action tied to a feature you don’t have licensed (Identity Protection’s risk policies, for example, require Entra ID P2) doesn’t count against you the same way an unaddressed action you actually could fix does. Each action also shows one of three states — To address, Planned, or Resolved through third party — so you can mark something as handled by a non-Microsoft tool without it sitting in your “to fix” list forever. The portal also shows how your score compares to similar-sized organizations, which is useful context for whether a given gap is unusual or just where most tenants your size actually sit.
Each recommendation comes with an impact score and clear implementation steps — ranked and actionable, not a vague \”improve security\” mandate.
When would you actually use this?
- You just failed a security review and need a prioritized fix list you can hand to leadership, not another spreadsheet of vague advice.
- You suspect MFA isn’t actually enforced everywhere, but checking policy by policy is tedious.
- Legacy protocols like POP/IMAP might still be enabled somewhere without you knowing about it — the score flags this as a specific, scored item instead of a guess.
- You’re being asked to move toward Zero Trust but don’t know where to start on the identity side — the recommendations map directly onto the identity pillar, ranked by impact.
Best practices and how to implement them
| Best Practice | Why It Matters | How to Do It |
|---|---|---|
| Enable MFA for All Users | Protects against password spray & phishing | Use Conditional Access or Security Defaults |
| Limit Legacy Authentication | Old protocols like POP/IMAP bypass MFA | Disable in Entra ID & Exchange Admin |
| Review Role Assignments | Avoid privilege creep | Use PIM (Privileged Identity Management) |
| Configure Sign-In Risk Policies | Automate response to risky logins | Use Identity Protection |
| Enable User Risk Policies | Detects compromised identities | Blocks or requires password reset |
Sample walkthrough: enforce MFA for admins
- Go to Entra Admin Center > Conditional Access
- Create a new policy named
MFA for Admins - Target
Directory Roles> select roles likeGlobal Admin,SharePoint Admin, etc. - Under Grant, choose
Require multi-factor authentication - Enable and monitor compliance
Watch your Identity Secure Score go up after this rolls out. Some controls — like Identity Protection’s risk-based policies — need an Entra ID P2 license, so check what’s covered before planning around a recommendation.
Now that is one useful tip! For questions and clarifications, please write it as a comment below. Have a nice day!
App Catalog Authentication Automation Backup Compliance Content Type CSS Flows Google Javascript Limitations List Metadata MFA Microsoft Node NodeJs O365 OneDrive Permissions PnP PnPJS Policy PowerApps Power Automate PowerAutomate PowerPlatform PowerShell React ReactJs Rest API Rest Endpoint Security Send an HTTP Request to SharePoint SharePoint SharePoint List SharePoint Modern SharePoint Online SPFX SPO Sync Tags Teams Termstore Versioning


