If you are an IT leader or Microsoft 365 administrator, chances are you check your Secure Score the way some people check their step count. It is satisfying when the number goes up. It is a little demoralising when it doesn't. And at some point, you have probably wondered: Does this number actually mean my tenant is secure?
The honest answer? Not entirely. And that's not a knock on Secure Score. It is a genuinely useful tool. It just was not built to tell you the whole story.
What Is Microsoft Secure Score?
Microsoft Secure Score is a measurement built into the Microsoft Defender portal that scores your tenant against a set of Microsoft-recommended security actions. Turn on MFA, get points. Enable a Conditional Access policy, get points. It's a great entry point for understanding your security posture, and it's genuinely helpful for benchmarking progress over time.
The problem is not that Secure Score is wrong. It is that it is a summary, not an investigation. It tells you whether a control exists. It does not tell you how well that control is actually working in the real world, with real users, exceptions, and business pressure to just get it working for now (and then, six months later, it is somehow still the permanent configuration).
Where the Secure Score Falls Short
Identity and Privileged Access
Secure Score has recommended actions covering your privileged accounts. It will nudge you towards least-privilege roles and flag if you have too few Global Administrators. What it won't tell you is that three of those admin accounts belong to people who left the business last year, or that permissions have been quietly accumulating on a service account nobody remembers creating. Access sprawl does not show up in a point-in-time score. It shows up in an incident report.
MFA and Conditional Access
Here is a subtle one. Most Secure Score actions are scored in a binary fashion. The policy exists; you get the points. A few awards partial credit based on the share of users covered. But nothing in Secure Score reads a policy's exclusion list. A policy quietly excluding a handful of “temporary” accounts can sit there for years without ever costing you a single point.1
Microsoft clearly knows this is a gap because it ships separate tooling to find it: a Conditional Access gap analyser workbook and a Conditional Access optimisation agent that runs on Security Copilot compute units, billed monthly.1 If coverage analysis were already part of the score, none of that would need to exist.
App Registrations and OAuth Consent
Every time someone clicks "Allow" on a third-party app requesting access to their mailbox or files, that is a new door into your data. Secure Score checks whether self-service consent is switched off tenant-wide. It does not tell you which apps already have access, what permissions they are holding, or whether any of them should be revoked.
To be fair, that information is available. Entra ID will show you every application, the permissions it holds, and who consented to them, and let you revoke a grant.2 The problem is not access to the data. It is that almost nobody has a standing process for reviewing it, and nothing in your Secure Score will remind you. Continuous behavioural monitoring of those apps is available in Defender for Cloud Apps App Governance, which many organisations either do not license or have never enabled.
Email Authentication (SPF, DKIM, DMARC)
Misconfigured or missing SPF, DKIM, and DMARC records are among the easiest ways for attackers to impersonate your domain and deliver convincing phishing emails to your customers' inboxes.
Secure Score recommends an action for SPF. Microsoft's published Secure Score actions include nothing equivalent for DKIM signing or DMARC, so neither is something you can rely on the score to surface. And the SPF check only confirms that a record is published, not that it is configured correctly, or that it is nowhere near the ten-lookup limit. There is a further catch: that SPF action arrived in a batch documented as available to customers with an active Defender for Cloud Apps licence, and the Office 365 connector switched on.3 A strong score does not guarantee your domain is well protected against spoofing.
SharePoint and OneDrive Sharing
Your tenant is not static. Sharing permissions tend to drift over time as projects wrap up, teams change, and external links once shared quietly become permanent. It’s a pattern well recognised in SharePoint security guidance. It's also worth knowing that some of Secure Score's SharePoint-related recommendations only appear once Defender for Cloud Apps is separately licensed, and its Office 365 connector is turned on.3 Out of the box, your score may not reflect the full sharing picture at all.2
Teams External Access
Guest access is great for collaboration, but it is genuinely easy to lose track of without active governance. Regular access reviews, expiry policies, and cleanup of orphaned teams do not happen by default. Secure Score's coverage here is limited, so ungoverned guest sprawl can build up quietly in the background.
Devices and Alert Backlog
Secure Score will tell you whether device compliance policies are in place. It will not tell you how many devices are actually failing them, whether disk encryption is genuinely on across the fleet, whether your Windows Update rings cover everyone, or how long that stack of unresolved high-severity Defender incidents has been sitting there. A control that exists and a control that is working are two different things, and only one of them is in the score.
Licensing Waste
This one isn't a security gap, but it's a budget one. Secure Score measures configuration, not cost, and has no visibility into license utilisation at all. That matters more than most IT leaders expect. Research into Microsoft 365 license management consistently finds that well over half of enterprise licenses are inactive, underutilised, oversized, or unassigned.3 That's money sitting on the table every single month, and Secure Score will never flag it.
So, should you ignore Secure Score?
No. Keep using it. It's a good habit and a useful trend line. Just don't mistake a high score for a completed security review. Think of Secure Score as your car's dashboard warning lights. Useful, easy to glance at, and genuinely important. But it is not the same as a mechanic actually putting the car on a hoist and looking under it.
What "Underneath the Score" Actually Looks Like
A proper Microsoft 365 tenant health assessment goes further than a dashboard. It uses Microsoft Graph, public DNS, and Azure Resource Manager to examine how your tenant is actually configured, not just whether a checkbox is ticked. Then it benchmarks that configuration against the frameworks your organisation is likely already answerable to: ASD Essential Eight, CIS Microsoft 365 Foundations, CISA SCuBA, NIST 800-53, ISO 27001, CMMC 2.0, EIDSCA, and MITRE ATT&CK.
That's the idea behind TenantRecon, Professional Advantage's Microsoft 365 Tenant Health Assessment. It is a deep review across identity and privileged access, Conditional Access, app registrations and OAuth consent, email authentication and domain health, SharePoint and Teams sharing, external and guest access, endpoint compliance, threat detection, Azure cost, and licensing utilisation. If you are weighing up Copilot, it also produces a readiness score across governance maturity, data cleanliness, and permissions posture so you know what needs fixing before you switch it on.
What you actually get
Every assessment produces a written report ranked by business impact, with a prioritised remediation sequence and the relevant compliance control mapped against each finding. Alongside it comes an executive summary deck designed for the people who approve the budget, not just those who do the work.
Two things we do differently:
- We tell you what we could not see. Anything outside the assessment's scope is explicitly listed, with a link to verify it yourself. We never invent a finding to fill a gap, and we never cite a control we have not actually checked.
- Every report is reviewed and signed off by a senior consultant before it reaches you. You get judgment about what matters for your business, not a wall of technical findings with no sense of what to fix first.
And because every finding is tracked against a stable identifier, a repeat assessment shows you what actually moved, rather than simply handing you a new number.
What it does to your tenant: nothing
Fair question, and it deserves a direct answer. TenantRecon reads. It cannot write.
- Every permission it uses is read-only, and Microsoft enforces that server-side. A read-only token cannot perform a write or a delete, even if the software tries.
- It collects settings, counts, and usage statistics. It never opens emails, documents, or chats.
- Nothing is installed in your tenant. Sign-in uses either Microsoft's own Graph Command Line Tools application, or an app registration your administrator can create and delete in one click.
- The output stays with the consultant. No tenant data is uploaded to a Professional Advantage service.
- You can revoke access in under a minute, and every sign-in and consent appears in your own audit logs.
We are happy to walk your security team through the full permission list and a sample output file before anything runs.
Is a Tenant Health Assessment Worth It for You?
It's worth a conversation if any of this sounds familiar:
- You want real visibility into your Microsoft 365 environment, not just a score.
- You're preparing for an audit or compliance review.
- Your tenant has grown quickly, and you're not entirely sure what's changed underneath.
- You're planning for Copilot or AI adoption and want a solid foundation before you build on it.
- You suspect you're paying for licences your organisation doesn't actually need.
Ready to see what's underneath your score?
Your Secure Score gives you a number. TenantRecon gives you the story behind it. Book a Microsoft 365 Tenant Health Assessment with TenantRecon.
Not ready for the full assessment?
Ask for a free Tenant Health Snapshot: a short, no-obligation view of the areas we assess and how your tenant is tracking across them. No commitment, and no tenant detail leaves your hands.
References
- Microsoft Learn, “Conditional Access gap analyzer workbook " and "Microsoft Entra Conditional Access optimization agent"
- Microsoft Learn, “Review permissions granted to enterprise applications"
- Microsoft Learn, “What's new in Microsoft Secure Score”, April 2023 and August 2023 releases.
- CoreView, “56% of Businesses' Microsoft Office 365 Licenses are Not Fully Exploited”,April 2020.


