What is a good Microsoft Secure Score?
Short answer: there's no universal pass mark, because your maximum score depends on which licenses you own — a tenant with Defender and Intune has more available points than one on Business Basic. That's why the percentage, not the raw points, is the number to watch, alongside Microsoft's comparison to organizations of similar size.
Rough ranges we see in practice
Below 40%: foundational controls are missing — usually MFA isn't enforced for all users, legacy authentication is still open, or auditing is off. This is where most unassessed tenants sit, and where attackers expect you to be.
40–65%: the basics are partly done but unevenly — MFA for admins but not users, policies created but not assigned, device management half-rolled-out. Most of the remaining points here are configuration, not spend.
65%+ with identity controls closed: a genuinely strong posture for most organizations. Chasing 100% is rarely rational — some controls carry user friction that isn't worth it for every business. The goal is closing high-impact gaps deliberately, not maximizing a number.
Why the peer benchmark matters
Microsoft shows how your score compares to organizations of similar seat count. Attackers mass-scan for the easiest targets; being meaningfully below your peer average means you're in the soft part of the herd. Getting above it is often achievable in one remediation sprint.
The score is a map, not a grade
Each missing point links to a specific control with Microsoft's remediation steps, an effort rating, and the threats it mitigates. Read that way, Secure Score is a prioritized to-do list your tenant has been quietly writing for you.
How exposed is your tenant? Find out in two minutes with the free, read-only Microsoft 365 security assessment.
Run the free assessment