Forum Discussion
Brandon Koeller
Microsoft
Aug 12, 2016Announcement: Office 365 Secure Score Released to Public Preview
Microsoft is pleased to announce the preview availability of a new security analytics service called the Office 365 Secure Score. The Secure Score is a security analytics tool that will help you understand what you have done to reduce the risk to your data in Office 365, and show you what you can do to further reduce that risk. We think of it as a credit score for security. Our approach to this experience was very simple. First, we created a full inventory of all the security configurations and behaviors that our customers can do to mitigate risks to their data in Office 365 (there are about 77 total things that we identified). Then, we evaluated the extent to which each of those controls mitigated a specific set of risks and awarded the control some points. More points means a more effective control for that risk. Lastly, we measure the extent to which your service has adopted the recommended controls, add up your points, and present it as a single score.
The core idea is that it is useful to rationalize and contextualize all of your cloud security configuration and behavioral options into one simple, analytical framework, and to make it very easy for you to take incremental action to improve your score over time. Rather than constructing a model with findings slotted into critical, moderate, or low severity, we wanted to give you a non-reactive way to evaluate your risk and make incremental changes over time that add up to a very effective risk mitigation plan.
The Office 365 Secure Score is a preview experience, so you may find issues, and you will note that not all of the controls are being measured. Please share any issues on the Office Network Group for Security. You can access the Secure Score at https://securescore.office.com.
The Secure Score does not express an absolute measure of how likely you are to get breached. It expresses the extent to which you have adopted controls which can offset the risk of being breached. No service can guarantee that you will not be breached, and the Secure Score should not be interpreted as a guarantee in any way.
Your Secure Score Summary
The first, most important piece of the Secure Score experience is the Score Summary. This panel gives you your current Secure Score, and the total number of points that are available to you, given your subscription level, the date that your score was measured, as well as a simple pie chart of your score. The denominator of your score is not intended to be a goal number to achieve. The full set of controls includes several that are very aggressive and will potentially have an adverse impact on your users’ productivity. Your goal should be to optimize your action to take every possible risk mitigating action while preserving your users’ productivity.

As mentioned, the Office 365 Secure Score is in a preview release. Over the coming months you will see us continue to add new controls, new measurements, and improvements to the remediation experiences. If you like what you see, please share with your network. If you see something we can improve, please share it with us on the Office Network Group for Security. We’re looking forward to seeing your scores go up, and making the Secure Score experience as useful, simple, and easy as it can be.
Read More Here: https://blogs.technet.microsoft.com/office365security/new-security-analytics-service-finding-and-fixing-risk-in-office-365/
Another issue with Secure Score.
"You should require that all of your users reset their password at least every 60 days"
This is no longer current best practice where strong passphrases and 2FA are used since more rapid enforced change of passwords leads to the use of weaker ones.
- Admin SecuCopper Contributor
hi, do have or plan the ability to generate the report and mail them to determined recipients ? thanks
+1 : also for the ability to give the role to specific account without global admin role
- Brandon Koeller
Microsoft
Hey! Thanks for reaching out. There isn't a built in mailer feature, but the content on the Score Analyzer can be exported or screenshotted to stick into an email. Also, I'm pleased to report that we have made the Secure Score experience available to users that hold any administrative role (user admin, security admin, etc.).
Thanks!
Brandon Koeller
- admin testCopper Contributor
greats news !
so service admin role would be sufficiant ? is it available already on all tenants ?
- Carol Co
Microsoft
- Brandon Koeller
Microsoft
Hey Carol,
Thanks for reaching out. You will need to be some kind of administrator for the tenancy that you wish to see the secure score for. I would suggest creating a demo tenant and working from there.
Thanks!
Brandon Koeller
- Carol Co
Microsoft
- Cian AllnerSilver Contributor
Just a quick note, as well as writing about Office 365 Secure Score on my personal blog, which I have linked to previously, I have written a more comprehensive article on the Technet Wiki - Office 365 Secure Score - Find and Fix Risks in Office 365.
I'll keep an eye on the content as things change but it's open for contributions in general from the community. It's my first Wiki article, so it been an interesting experience, it's harder than it looks. I'm looking forward to Secure Score reaching GA and more people benefiting from this service.
- Brandon KoellerCopper ContributorAwesome! Thanks for sharing and for the community support! Look for the GA announcement in the very near future (along with a couple of new features, like an API!). Thanks, Brandon Koeller
- Julian KnightSteel Contributor
Another issue with Secure Score.
"You should require that all of your users reset their password at least every 60 days"
This is no longer current best practice where strong passphrases and 2FA are used since more rapid enforced change of passwords leads to the use of weaker ones.
- Brandon KoellerCopper ContributorHey Julian,
Thanks for the feedback. We 100% agree, and have been working on 'flipping' this control to award points for /not/ setting a password expiration policy. Microsoft and NIST both recently released research that supports this change on our policies. Thanks again for the feedback!
As Per Microsoft's Recommendation: https://www.microsoft.com/en-us/research/wp-content/uploads/2016/06/Microsoft_Password_Guidance-1.pdf
And updated NIST standards: https://pages.nist.gov/800-63-3/sp800-63-3.html
Brandon Koeller- Dean_GrossSilver Contributor
That password recommendations document contains a lot of good info. Can you get it copied from the Research org over into some public places, such as docs.microsoft.com and support.office.com?
- PsouthwayCopper ContributorHi Brandon/Karsten, I have the same issue, but it seemed to work fine yesterday (9th)
- Paul NutterfieldCopper Contributor
Great service and it's really helped secure and understand Office 365!
One of the items counts the number of Exchange mailboxes with auditing enabled and the action is to enable auditing. The mailbox count and number of mailboxes with auditing enabled varies has not matched my mailbox count and their audit status. We're new to Office 365 so we may be overlooking a system database or some other setting. We're simply using get-mailbox and also with the -SoftDeletedMailbox and -Migration switches and check the AuditEnabled status.
Thank you!
- Reza_Ameri-ArchivedBronze Contributor
It is nice tool and this is what we really need, we couldn't expect to teach everyone about security issue and threats and they just want to press one key to see what is going on and we are the one in background working to make sure that key is working fine.
- Dean_GrossSilver Contributor
My client is not using Exchange Online. It would be helpful if there was some way to exclude the actions related to exchange from the Secure Score recommendations
- Brandon Koeller
Microsoft
Hi Dean,
Thanks for the feedback. Long term, we will definitely exclude controls for services that you don't have. For now, we've opted to include all of the controls since several are not scored to help users understand the full range of options. We also plan to give you the ability to exclude specific controls that you know you will never be able to enact, even if they pertain to services you own.
Thanks!
Brandon Koeller
- adm-Mark ZigadloCopper Contributor
Great tool.
I made some updates to improve my score.
When will I see my score updated?
- Brandon Koeller
Microsoft
Hi Mark,
Thanks for reaching out. The Secure Score is calculated once per day (at 1am PST). Please note that not all of the controls are instrumented, so some actions might not reflect an improvement in your score yet (those controls are labeled [Not Scored]). Otherwise, you should see your score reflect your actions within a maximum of 24 hours!
Thanks,
Brandon Koeller