Utilizing Identity Secure Score in M365 Admin Center

Strengthen your Entra ID setup with Identity Secure Score


In this post: What is Identity Secure Score? · Where to find it · Why it’s worth checking · How the score is actually calculated · When would you actually use this? · Best practices and how to implement them · Sample walkthrough: enforce MFA for admins


What is Identity Secure Score?

Identity Secure Score is the identity-focused slice of Microsoft Secure Score, found in the Microsoft 365 Defender portal. It scores how locked-down your Entra ID (Azure AD) setup is — MFA coverage, legacy authentication, admin role sprawl — and ranks what to fix first.

URL Reference:
https://security.microsoft.com/securescore


Where to find it
  1. Go to https://security.microsoft.com/securescore
  2. Open Secure Score from the left menu
  3. Filter by “Identity” to see just the Entra ID recommendations

Why it’s worth checking

Each recommendation comes with an impact score and clear implementation steps, and shows whether it’s implemented, partially implemented, or not at all. It’s aimed at IT admins, security auditors, and compliance teams who need a prioritized, measurable list of identity risks — not just a vague “improve security” mandate.


How the score is actually calculated

Identity Secure Score isn’t a single opaque number — it’s a percentage: points earned across every identity-related improvement action, divided by the total points available for actions applicable to your tenant. “Applicable” matters here — an action tied to a feature you don’t have licensed (Identity Protection’s risk policies, for example, require Entra ID P2) doesn’t count against you the same way an unaddressed action you actually could fix does. Each action also shows one of three states — To address, Planned, or Resolved through third party — so you can mark something as handled by a non-Microsoft tool without it sitting in your “to fix” list forever. The portal also shows how your score compares to similar-sized organizations, which is useful context for whether a given gap is unusual or just where most tenants your size actually sit.


Each recommendation comes with an impact score and clear implementation steps — ranked and actionable, not a vague \”improve security\” mandate.

When would you actually use this?
  • You just failed a security review and need a prioritized fix list you can hand to leadership, not another spreadsheet of vague advice.
  • You suspect MFA isn’t actually enforced everywhere, but checking policy by policy is tedious.
  • Legacy protocols like POP/IMAP might still be enabled somewhere without you knowing about it — the score flags this as a specific, scored item instead of a guess.
  • You’re being asked to move toward Zero Trust but don’t know where to start on the identity side — the recommendations map directly onto the identity pillar, ranked by impact.

Best practices and how to implement them
Best PracticeWhy It MattersHow to Do It
Enable MFA for All UsersProtects against password spray & phishingUse Conditional Access or Security Defaults
Limit Legacy AuthenticationOld protocols like POP/IMAP bypass MFADisable in Entra ID & Exchange Admin
Review Role AssignmentsAvoid privilege creepUse PIM (Privileged Identity Management)
Configure Sign-In Risk PoliciesAutomate response to risky loginsUse Identity Protection
Enable User Risk PoliciesDetects compromised identitiesBlocks or requires password reset

Sample walkthrough: enforce MFA for admins
  1. Go to Entra Admin Center > Conditional Access
  2. Create a new policy named MFA for Admins
  3. Target Directory Roles > select roles like Global Admin, SharePoint Admin, etc.
  4. Under Grant, choose Require multi-factor authentication
  5. Enable and monitor compliance

Watch your Identity Secure Score go up after this rolls out. Some controls — like Identity Protection’s risk-based policies — need an Entra ID P2 license, so check what’s covered before planning around a recommendation.


Now that is one useful tip! For questions and clarifications, please write it as a comment below. Have a nice day!


App Catalog Authentication Automation Backup Compliance Content Type CSS Flows Google Javascript Limitations List Metadata MFA Microsoft Node NodeJs O365 OneDrive Permissions PnP PnPJS Policy PowerApps Power Automate PowerAutomate PowerPlatform PowerShell React ReactJs Rest API Rest Endpoint Security Send an HTTP Request to SharePoint SharePoint SharePoint List SharePoint Modern SharePoint Online SPFX SPO Sync Tags Teams Termstore Versioning

Leave a Comment

Your email address will not be published. Required fields are marked *