Agent Foskett Academy • Microsoft Defender for Cloud • Module 1 • Lesson 10

Lesson 10 — Secure Score Overview

Secure Score provides a numerical view of cloud security posture by measuring how well resources meet recommended security controls.

This lesson explains how the score is calculated, how improvement actions affect it, and why teams must look beyond the percentage to understand actual risk, business impact and remediation priority.

A higher Secure Score can indicate stronger posture, but the number only has value when it reflects genuine risk reduction.
Agent Foskett Secure Score Overview lesson
What you will learn

This lesson shows how Secure Score measures posture and supports remediation decisions.

Score calculation
Improvement actions
Prioritisation limits
Operational reporting

Secure Score calculation flow

Defender for Cloud discovers resources ↓ Assessments evaluate security controls ↓ Recommendations identify unhealthy resources ↓ Each control contributes available points ↓ Healthy resources earn points ↓ Partially remediated controls earn partial value ↓ Scores are aggregated across the selected scope ↓ The portal displays current and potential score ↓ Teams review improvement actions ↓ Remediation changes posture and score

Secure Score prioritisation flow

Review current Secure Score ↓ Open improvement actions ↓ Check maximum available score increase ↓ Review severity and affected resources ↓ Check internet exposure and attack paths ↓ Confirm data sensitivity and business criticality ↓ Estimate remediation effort ↓ Assign owner and due date ↓ Implement and validate the change ↓ Confirm assessment and score refresh

Secure Score components

ComponentPurposeOperational question
Current scoreShows points currently achieved.How much of the available posture value is being achieved?
Maximum scoreShows the total points available in the selected scope.What is the realistic scoring ceiling for this environment?
PercentageExpresses current points as a proportion of maximum points.Is the percentage improving because risk was reduced?
Improvement actionGroups related recommendations under a security control.Which control change will improve posture?
Affected resourcesLists assets that currently fail the control.Which critical systems remain exposed?
Potential increaseEstimates score gain from full remediation.Is the score gain aligned with meaningful risk reduction?

Agent Foskett investigation: “The score improved overnight…”

The Secure Score increased by 11 percent ↓ Management believed the environment had become safer ↓ No major remediation project had been completed ↓ Agent Foskett reviewed the improvement actions ↓ Several vulnerable resources had disappeared ↓ The resources had not been fixed ↓ A subscription had been moved outside the reporting scope ↓ The score improved because the denominator changed ↓ The exposed systems were still online ↓ The affected subscription was restored to scope ↓ The score dropped again ↓ The actual recommendations were assigned to owners ↓ Remediation was completed ↓ The score increased for the right reason ↓ Reporting was updated to track scope changes separately
The score changed, but the risk had not.

Key takeaways

  • Secure Score provides a posture measurement, not a complete risk assessment.
  • The score is based on available controls and assessed resources.
  • Improvement actions group related recommendations.
  • Partial remediation can produce partial score improvement.
  • Scope changes can alter the score without reducing risk.
  • High potential score gain does not always mean highest operational priority.
  • Internet exposure, identity privilege, sensitive data and business criticality must influence prioritisation.
  • Exemptions and unavailable data can affect visible posture.
  • Score trends should be reviewed with scope and resource-count changes.
  • Remediation must be validated through configuration and reassessment.

Learning objectives

After completing this lesson, you should be able to explain how Secure Score is calculated, interpret improvement actions and use the score responsibly.

What is Secure Score?

Secure Score is a posture metric that shows how many available security-control points are currently achieved.

Current score

The current score represents points earned from controls that are fully or partially satisfied.

Maximum score

The maximum score represents the total points available for the resources and controls in the selected scope.

Score percentage

The displayed percentage is calculated from current points divided by maximum available points.

Improvement actions

Improvement actions group one or more recommendations that address the same security objective.

Control weighting

Different improvement actions can contribute different amounts to the overall score.

Partial scoring

When only some affected resources are remediated, the control may contribute partial points.

Affected resources

Each improvement action should be reviewed at resource level to identify the systems still failing the control.

Potential score increase

The potential increase estimates the benefit of completing the improvement action across all affected resources.

Recommendation relationship

Secure Score depends on the health states produced by Defender for Cloud assessments and recommendations.

Severity relationship

Recommendation severity matters, but the score value and severity are not the same measurement.

Attack-path context

A recommendation on an active attack path can deserve priority even when its score contribution is modest.

Internet exposure

Publicly reachable resources should receive additional priority because they can be attacked directly.

Identity privilege

Controls affecting privileged identities or highly trusted workloads can carry greater real-world impact.

Data sensitivity

A low-point control affecting sensitive data may be more important than a high-point control affecting test systems.

Business criticality

Production and customer-facing workloads should be prioritised according to operational impact.

Scope selection

Secure Score can be reviewed across management groups, subscriptions and other supported scopes.

Scope changes

Adding or removing resources, subscriptions or connectors can change both current and maximum scores.

Multicloud scoring

Azure, AWS and Google Cloud resources can contribute to posture reporting when connectors and assessments are healthy.

Connector health

Stale or broken connectors can reduce assessment quality and make the score unreliable.

Assessment freshness

After remediation, allow time for reassessment before expecting the score to update.

Exemptions

Exemptions can remove findings from active posture calculations without removing the underlying technical condition.

Risk acceptance

Accepted risk should remain documented, approved, time-bound and visible in governance reporting.

Compensating controls

Alternative controls should be tested and should address the same risk rather than merely justify an exemption.

Score trend

Trend lines are useful only when interpreted alongside resource counts, scope and major environment changes.

Sudden improvement

A sudden increase should be investigated to confirm whether remediation, scope changes or data loss caused it.

Sudden decline

A sudden decrease may indicate new resources, new assessments, connector changes or configuration drift.

Ownership

Improvement actions should be assigned to accountable teams with due dates and validation criteria.

Remediation planning

Balance score gain, risk reduction, effort, change impact and business priorities.

Quick wins

Low-effort improvements can provide useful momentum, but should not displace urgent high-risk work.

Large-score actions

A high score opportunity may affect many low-risk resources and still require careful prioritisation.

Small-score actions

A small score opportunity may still close a serious exposure on a critical system.

Dashboard reporting

Report the score with context such as affected resources, open high-severity findings and remediation ageing.

Executive reporting

Executives need direction of travel, major risks, overdue actions and meaningful explanations for score movement.

Technical reporting

Technical teams need control details, affected resources, owners, due dates and validation evidence.

Historical comparison

Compare like-for-like scopes so trend analysis is not distorted by organisational or connector changes.

Score targets

Targets should be realistic, risk-based and supported by control ownership rather than selected as arbitrary percentages.

Do not chase 100 percent

A perfect score may be impractical, temporary or misleading if important risks sit outside the measured controls.

Validation

Confirm the underlying configuration, resource operation and assessment state before declaring an action complete.

Recurring findings

Repeated score loss often indicates insecure templates, configuration drift or weak policy enforcement.

Policy prevention

Azure Policy and equivalent cloud controls can help stop resolved recommendations from returning.

Infrastructure as code

Secure deployment templates reduce recurring posture problems and improve consistent scoring.

Ticketing integration

Improvement actions can be transferred into operational workflows with owners, due dates and resource identifiers.

Metrics

  • Current score and percentage
  • Potential score increase
  • Open high-severity recommendations
  • Affected critical resources
  • Overdue improvement actions
  • Mean time to remediate
  • Active exemptions
  • Recurring findings
  • Scope and resource-count changes

Common interpretation errors

  • Treating the percentage as proof of security
  • Ignoring changes to scope
  • Prioritising points instead of risk
  • Assuming exemptions remove exposure
  • Failing to validate reassessment
  • Comparing unlike environments

Operational lesson

Secure Score is most useful when it guides verified remediation rather than becoming a target that teams manipulate.

What Agent Foskett checked

Agent Foskett checked scope membership, subscription movement, resource counts, assessment freshness, exemptions and actual configuration changes.

Best practices

  • Use Secure Score as a guide, not a guarantee.
  • Review improvement actions at resource level.
  • Track scope changes separately.
  • Prioritise internet-facing and business-critical systems.
  • Assign owners and due dates.
  • Validate configuration and reassessment.
  • Review exemptions regularly.
  • Use policy and automation to prevent recurrence.
  • Report score trends with context.
  • Measure genuine risk reduction.

Continue learning

Continue into Module 2 by learning how to read and interpret Microsoft Defender for Cloud security recommendations.

What is Microsoft Defender for Cloud Secure Score?

Microsoft Defender for Cloud Secure Score measures cloud security posture by comparing achieved security-control points with the maximum points available across assessed resources.

Secure Score Overview Lesson

This Agent Foskett lesson explains Secure Score calculation, improvement actions, potential score increase, partial scoring, scope changes, multicloud posture, prioritisation, exemptions, reporting and remediation validation.