August 19, 2025

What your 80%+ Microsoft Secure Score isn't telling you

What is MSS?

Originally known as ' Office 365 Secure Score' - Microsoft Secure Score ( MSS ) is a point based measurement of a 365 tenants security posture in Microsoft 365.

It has two features that really play well to our psychology as people interested in maximising the security of our 365 environment - a Score and a Target.

But here’s the uncomfortable truth: a 80%+ Secure Score does not guarantee that you’re safe.

In it's current iteration, you get a point score and a % value compared to the points it's currently possible to achieve in your environment with the licenses currently available in your subscription.


You can see the % for all of your tenants in Overe

Microsoft break the score down into Identity, Data and Apps.We break your configuration down further into attack vector categories in our own Smart Posture Value as above.

What is a good score?

By Implementing the relevant security tasks, you can make large jumps in your score, but a good score? That depends who you ask : Here are some opinions ;

We strongly recommend aiming for a secure score in the range of 60% to 80% for optimal protection

AztechIT

We believe that aiming for a Secure Score of at least 80% represents a realistic and achievable goal for most businesses

ITfoundations.com

Your score should be at least 75-80% and higher if possible — if not, then there is work to do.

CompexIT

Above 70% is strong for SMEs with good cyber hygiene, but ideally aim for 80% or higher. 40-69% is average — room for improvement. Below 40% means your organisation could be exposed.

TheHPBGroup

Great, so 80% and we can all go home?

While higher is better, an 80% tenant might actively be compromised while a 40% MSS tenant might have plenty of holes but avoid infiltration.

In one recent Microsoft 365 tenant we assessed - the  Secure Score was over 90%. On paper, that’s near perfect. In reality, Overe uncovered multiple critical risks

  • MFA gaps for admin accounts under certain login conditions
  • Risky applications with excessive permissions
  • Exfiltration risks from email forwarding rules
  • Inactive accounts with standing access rights
Not quite as secure as you might think

How does Overe help?

This interactive demo shows exactly how easy it is to run a deep scan in Overe


Overe looks beyond the percentage, running deep, automated scans that map your real security gaps in Microsoft 365. From policy weaknesses to active threat detection, we help MSPs and IT teams see the full picture not just the scorecard.

Click here to get started

Get Started Free

Assess the security posture of all your MSP's clients and get actionable remediation steps, in under 3 minutes. 100% free.

Overe Background image
Assess For Free

Get up and running in under 2 minutes, no credit card required.

Get Started Free  

Free audit worth £1000

Thank you!
Your submission has been received!
Oops!
Something went wrong! Try again later
Overe Background image
Overe icon
Is Your Organisation Vulnerable
To Phishing Attacks?

Claim your FREE phishing simulation to see how many of your staff fall victim to phishing emails (the results might shock you).

Free simulation worth £1,000

Thank you!
Your submission has been received!
Oops!
Something went wrong! Try again later