3 min read

Five Microsoft Secure Score Improvements You Can Make Today

Five Microsoft Secure Score Improvements You Can Make Today
Five Microsoft Secure Score Improvements You Can Make Today
6:59

Five Microsoft Secure Score Improvements You Can Make Today

Most small and mid-sized businesses we assess start out somewhere between 40 and 60% on Microsoft Secure Score, and in our experience a focused month of targeted changes typically lifts that by 20 to 30 points. None of the five changes below require new licensing or additional budget. They're configuration changes sitting inside Microsoft 365 tenants right now, in most cases unused simply because nobody has worked through the list.

One important caveat before diving in: Secure Score is a prioritised work queue, not a target to hit for its own sake. A tenant sitting at 60% with every high-impact control genuinely in place is in a stronger position than one at 80% built from low-value actions that look good on the dashboard but do little against real attacks. Identity-related recommendations consistently carry the most points and close the most commonly exploited gaps, which is exactly why four of the five items below sit in that category.

1. Enable MFA for Every User, Not Just Admins

This is consistently the single highest-impact action available on Secure Score, and it's also the one most often left half-finished. Many businesses enforce MFA for administrators and assume that's sufficient, while standard user accounts, often the ones targeted first in a phishing campaign, remain protected by password alone.

Effort: Low. Can typically be rolled out tenant-wide within a day using a Conditional Access policy or, if Conditional Access isn't available, Security Defaults as an interim baseline.

Where to check it: Microsoft Defender portal → Secure Score → filter by "Identity" and look for the MFA-related recommended actions.

2. Block Legacy Authentication Protocols

Protocols like POP3, IMAP, and SMTP AUTH predate modern authentication and don't support MFA at all. That makes them one of the most reliable paths attackers use for password spraying, since a stolen or guessed password is enough on its own, with nothing else standing in the way.

Effort: Low. For most modern Microsoft 365 tenants, few if any legitimate services still rely on these protocols, meaning this change carries real security benefit with minimal disruption to users.

Where to check it: Microsoft Defender portal → Secure Score → the "Block legacy authentication" recommended action, or directly within Conditional Access policies.

3. Turn On Unified Audit Logging

Audit logging isn't a preventative control, but it's the difference between knowing exactly what happened during an incident and guessing. Without it enabled, investigating a compromised account after the fact becomes far harder, and in some cases impossible, since the activity trail simply doesn't exist.

Effort: Low. This is a single tenant-wide toggle, and Microsoft recommends leaving it permanently enabled going forward rather than switching it on only when needed.

Where to check it: Microsoft Purview compliance portal → Audit → Start recording user and admin activity (also listed as a recommended action within Secure Score).

4. Trim Standing Global Administrator Assignments

It's common to find far more permanent Global Administrator accounts than a business actually needs, often because access was granted for a one-off project and never removed. Every standing admin account is a high-value target, and each one left active without ongoing justification adds risk that provides no operational benefit.

Effort: Low to moderate. Requires reviewing current role assignments and removing anyone who doesn't need permanent, tenant-wide access, ideally replacing standing access with just-in-time elevation where available.

Where to check it: Microsoft Entra admin center → Roles and administrators → Global Administrator, cross-referenced against the relevant Secure Score identity recommendations.

5. Review Your Top Recommendations on a Monthly Cadence

The single biggest reason Secure Score improvements stall isn't difficulty, it's that nobody owns the list after the initial push. Microsoft continually adds new recommended actions as features ship, which means a tenant that was fully addressed six months ago can quietly develop new gaps without anyone noticing.

Effort: Low. This is a process change, not a technical one: assign a named owner, review the top 10 recommendations sorted by point value and effort each month, and document any item deliberately left unresolved with a clear reason why.

Where to check it: Microsoft Defender portal → Secure Score → History tab, to confirm previous actions are still correctly applied rather than assuming a past score increase is permanent.

At a Glance

Action Typical effort Category
MFA for all users Low Identity
Block legacy authentication Low Identity
Unified audit logging Low Data and apps
Trim standing Global Admin accounts Low to moderate Identity
Monthly recommendation review Low (process) Identity, ongoing

Frequently Asked Questions

How much can we realistically improve our score without new spending? Based on the tenants we've reviewed, a focused effort on identity-related quick wins alone typically lifts a score by 15 to 25 points within the first month, since identity recommendations tend to carry the most available points and the lowest implementation effort.

Is a higher Secure Score the same as being more secure? Not automatically. Some high-point actions involve significant operational disruption for limited real-world benefit, while some low-point actions close genuinely common attack vectors. Prioritise by actual risk reduction, not purely by point value.

Will enabling MFA or blocking legacy authentication disrupt our staff? For most modern Microsoft 365 environments, the disruption is minimal, since legacy protocols are rarely still needed and MFA can be rolled out with a phased pilot group before a full tenant-wide rollout.

How often should we check our Secure Score? Monthly, at minimum. Microsoft regularly adds new recommended actions, and previous improvements should also be periodically confirmed as still correctly applied rather than assumed permanent.

Can Protrona help us work through our current Secure Score recommendations? Yes. Our security consultancy services include a full Secure Score review, prioritised by real-world risk rather than point value alone, alongside the deeper Conditional Access and Identity Protection review we've covered separately.


Get a free Secure Score review

The fastest way to know which of these five changes will move the needle most for your business is to see your actual current score and configuration. Get in touch to arrange a review.