Lesson 10 — Secure Score Overview
Secure Score provides a numerical view of cloud security posture by measuring how well resources meet recommended security controls.
This lesson explains how the score is calculated, how improvement actions affect it, and why teams must look beyond the percentage to understand actual risk, business impact and remediation priority.

What you will learn
This lesson shows how Secure Score measures posture and supports remediation decisions.
Secure Score calculation flow
Secure Score prioritisation flow
Secure Score components
| Component | Purpose | Operational question |
|---|---|---|
| Current score | Shows points currently achieved. | How much of the available posture value is being achieved? |
| Maximum score | Shows the total points available in the selected scope. | What is the realistic scoring ceiling for this environment? |
| Percentage | Expresses current points as a proportion of maximum points. | Is the percentage improving because risk was reduced? |
| Improvement action | Groups related recommendations under a security control. | Which control change will improve posture? |
| Affected resources | Lists assets that currently fail the control. | Which critical systems remain exposed? |
| Potential increase | Estimates score gain from full remediation. | Is the score gain aligned with meaningful risk reduction? |
Agent Foskett investigation: “The score improved overnight…”
Key takeaways
- Secure Score provides a posture measurement, not a complete risk assessment.
- The score is based on available controls and assessed resources.
- Improvement actions group related recommendations.
- Partial remediation can produce partial score improvement.
- Scope changes can alter the score without reducing risk.
- High potential score gain does not always mean highest operational priority.
- Internet exposure, identity privilege, sensitive data and business criticality must influence prioritisation.
- Exemptions and unavailable data can affect visible posture.
- Score trends should be reviewed with scope and resource-count changes.
- Remediation must be validated through configuration and reassessment.
Learning objectives
After completing this lesson, you should be able to explain how Secure Score is calculated, interpret improvement actions and use the score responsibly.
What is Secure Score?
Secure Score is a posture metric that shows how many available security-control points are currently achieved.
Current score
The current score represents points earned from controls that are fully or partially satisfied.
Maximum score
The maximum score represents the total points available for the resources and controls in the selected scope.
Score percentage
The displayed percentage is calculated from current points divided by maximum available points.
Improvement actions
Improvement actions group one or more recommendations that address the same security objective.
Control weighting
Different improvement actions can contribute different amounts to the overall score.
Partial scoring
When only some affected resources are remediated, the control may contribute partial points.
Affected resources
Each improvement action should be reviewed at resource level to identify the systems still failing the control.
Potential score increase
The potential increase estimates the benefit of completing the improvement action across all affected resources.
Recommendation relationship
Secure Score depends on the health states produced by Defender for Cloud assessments and recommendations.
Severity relationship
Recommendation severity matters, but the score value and severity are not the same measurement.
Attack-path context
A recommendation on an active attack path can deserve priority even when its score contribution is modest.
Internet exposure
Publicly reachable resources should receive additional priority because they can be attacked directly.
Identity privilege
Controls affecting privileged identities or highly trusted workloads can carry greater real-world impact.
Data sensitivity
A low-point control affecting sensitive data may be more important than a high-point control affecting test systems.
Business criticality
Production and customer-facing workloads should be prioritised according to operational impact.
Scope selection
Secure Score can be reviewed across management groups, subscriptions and other supported scopes.
Scope changes
Adding or removing resources, subscriptions or connectors can change both current and maximum scores.
Multicloud scoring
Azure, AWS and Google Cloud resources can contribute to posture reporting when connectors and assessments are healthy.
Connector health
Stale or broken connectors can reduce assessment quality and make the score unreliable.
Assessment freshness
After remediation, allow time for reassessment before expecting the score to update.
Exemptions
Exemptions can remove findings from active posture calculations without removing the underlying technical condition.
Risk acceptance
Accepted risk should remain documented, approved, time-bound and visible in governance reporting.
Compensating controls
Alternative controls should be tested and should address the same risk rather than merely justify an exemption.
Score trend
Trend lines are useful only when interpreted alongside resource counts, scope and major environment changes.
Sudden improvement
A sudden increase should be investigated to confirm whether remediation, scope changes or data loss caused it.
Sudden decline
A sudden decrease may indicate new resources, new assessments, connector changes or configuration drift.
Ownership
Improvement actions should be assigned to accountable teams with due dates and validation criteria.
Remediation planning
Balance score gain, risk reduction, effort, change impact and business priorities.
Quick wins
Low-effort improvements can provide useful momentum, but should not displace urgent high-risk work.
Large-score actions
A high score opportunity may affect many low-risk resources and still require careful prioritisation.
Small-score actions
A small score opportunity may still close a serious exposure on a critical system.
Dashboard reporting
Report the score with context such as affected resources, open high-severity findings and remediation ageing.
Executive reporting
Executives need direction of travel, major risks, overdue actions and meaningful explanations for score movement.
Technical reporting
Technical teams need control details, affected resources, owners, due dates and validation evidence.
Historical comparison
Compare like-for-like scopes so trend analysis is not distorted by organisational or connector changes.
Score targets
Targets should be realistic, risk-based and supported by control ownership rather than selected as arbitrary percentages.
Do not chase 100 percent
A perfect score may be impractical, temporary or misleading if important risks sit outside the measured controls.
Validation
Confirm the underlying configuration, resource operation and assessment state before declaring an action complete.
Recurring findings
Repeated score loss often indicates insecure templates, configuration drift or weak policy enforcement.
Policy prevention
Azure Policy and equivalent cloud controls can help stop resolved recommendations from returning.
Infrastructure as code
Secure deployment templates reduce recurring posture problems and improve consistent scoring.
Ticketing integration
Improvement actions can be transferred into operational workflows with owners, due dates and resource identifiers.
Metrics
- Current score and percentage
- Potential score increase
- Open high-severity recommendations
- Affected critical resources
- Overdue improvement actions
- Mean time to remediate
- Active exemptions
- Recurring findings
- Scope and resource-count changes
Common interpretation errors
- Treating the percentage as proof of security
- Ignoring changes to scope
- Prioritising points instead of risk
- Assuming exemptions remove exposure
- Failing to validate reassessment
- Comparing unlike environments
Operational lesson
Secure Score is most useful when it guides verified remediation rather than becoming a target that teams manipulate.
What Agent Foskett checked
Agent Foskett checked scope membership, subscription movement, resource counts, assessment freshness, exemptions and actual configuration changes.
Best practices
- Use Secure Score as a guide, not a guarantee.
- Review improvement actions at resource level.
- Track scope changes separately.
- Prioritise internet-facing and business-critical systems.
- Assign owners and due dates.
- Validate configuration and reassessment.
- Review exemptions regularly.
- Use policy and automation to prevent recurrence.
- Report score trends with context.
- Measure genuine risk reduction.
Related Agent Foskett resources
Continue learning
What is Microsoft Defender for Cloud Secure Score?
Microsoft Defender for Cloud Secure Score measures cloud security posture by comparing achieved security-control points with the maximum points available across assessed resources.
Secure Score Overview Lesson
This Agent Foskett lesson explains Secure Score calculation, improvement actions, potential score increase, partial scoring, scope changes, multicloud posture, prioritisation, exemptions, reporting and remediation validation.
