Microsoft Secure Score in 2026: Why We Target 80%+

Hayden Kirk
Hayden Kirk
August 4, 2026

Nearly two years ago, I wrote about the importance of Microsoft Secure Score and how it can help organisations understand and improve their Microsoft 365 security. Since then, we have made Secure Score a more active part of how we manage and review our customers’ environments.

Our goal is straightforward: we try to align every managed customer to a Microsoft Secure Score of at least 80%, wherever their licensing and operational requirements allow.

We have now achieved this with a number of customers. More importantly, we are helping them maintain that position as Microsoft 365, their businesses and the threats they face continue to change.

What does Microsoft Secure Score actually measure?

Microsoft Secure Score measures how closely an organisation’s Microsoft environment follows Microsoft’s recommended security practices.

A higher score means that more recommended actions have been completed across areas such as user identities, administrative accounts, email, applications and devices. Microsoft also allows organisations to monitor changes over time and compare their position with similar organisations.

It is helpful to think of Secure Score as a dashboard rather than an exam result.

It shows which protections are already in place, where gaps remain and which improvements could make the greatest difference. It also gives management and IT teams a common way to discuss security without needing to work through hundreds of individual settings.

Secure Score is not a guarantee that an organisation will never experience a cyber incident. Microsoft is clear that it is not an absolute measurement of the likelihood of a breach. It measures the extent to which relevant security controls have been implemented within the Microsoft environment.

Why have we chosen 80% as our target?

Microsoft does not publish 80% as an official pass mark. It is a benchmark that Layer3 has chosen for the customers we manage.

We believe 80% represents a strong and realistic security position. Reaching it normally requires an organisation to have addressed most of the important and practical recommendations available within its Microsoft environment.

We do not blindly pursue a score of 100%.

Some recommendations may not be appropriate for a particular organisation, may require additional licensing or could create an unreasonable impact on how people work. Microsoft itself advises that security must be balanced with usability and that not every recommendation will suit every environment.

Our aim is therefore not to collect every available point. It is to implement the right controls, understand any exceptions and ensure that accepted risks are properly documented.

The controls behind the number are what matter

The percentage is useful, but the protections behind it are far more important.

Secure Score recommendations can include measures such as:

  • Requiring multifactor authentication, particularly for administrators.
  • Blocking outdated sign-in methods.
  • Strengthening access and identity policies.
  • Protecting email and collaboration services.
  • Improving device security.
  • Reviewing administrative access and unnecessary permissions.
  • Blocking non-work devices from accesssing work resources

Microsoft awards points based on whether these actions have been completed. For some recommendations, partial points are awarded when only some users or devices are protected. This makes the score more meaningful than a simple yes-or-no questionnaire because it can highlight incomplete deployments.

For example, saying that your organisation “uses MFA” does not tell you whether it protects every account, only administrators or a small group of users. Secure Score helps expose that difference.

Why this is not a box-ticking exercise

Security frameworks and checklists are valuable, but they can become ineffective when they are treated as paperwork that only needs to be reviewed once a year.

Secure Score is useful because it is connected to the configuration of the Microsoft environment. It can help show whether recommended protections have actually been implemented and whether they remain in place.

That does not mean it covers every part of cybersecurity. Microsoft notes that Secure Score recommendations do not cover every possible attack surface. Backups, network security, non-Microsoft applications, staff awareness, vulnerability management and incident response also need to be considered.

At Layer3, Secure Score is therefore one benchmark within a broader security programme. We use it to measure progress, prioritise work and identify changes that require attention. We do not use it as a replacement for good security judgement.

Getting above 80% is only the first step

Reaching 80% is an achievement, but the harder task is staying there.

Microsoft continually updates its services and recommendations. New users, devices and applications are added. Policies are changed, sometimes intentionally and sometimes accidentally. A customer can have a strong security position today and gradually move away from it without anyone noticing.

This is often referred to as configuration or policy drift.

One of the tools Layer3 uses to manage this is inforcer. It allows us to define Microsoft 365 security baselines, deploy policies consistently and identify customers that have moved out of alignment.

It can also alert us when a policy is changed, maintain backups of Microsoft 365 policy settings and provide an audit trail of what has happened.

This helps us maintain a consistent standard across our customers rather than relying on an engineer to manually check every setting in every Microsoft tenant.

The technology does not replace our engineers. Layer3 still determines which controls are appropriate, tests changes, manages customer-specific exceptions and considers how a security policy will affect the people using it.

What does Secure Score have to do with cyber insurance?

Cyber insurers increasingly want evidence that organisations understand and actively manage their cyber risk.

There is no universal Microsoft Secure Score requirement for obtaining cyber insurance. An insurer is unlikely to approve or decline a policy based only on whether a business has reached 80%.

However, insurers assess many of the same controls that influence a strong security posture. These commonly include multifactor authentication, identity and access management, endpoint protection, backups, staff training, firewalls, incident response planning and regular security assessments.

AIG New Zealand, for example, describes using security posture information and risk-reducing controls to help organisations prioritise improvements and support more tailored policy terms and conditions.

This is where Secure Score becomes valuable. It provides a measurable record of the controls implemented within Microsoft 365 and shows whether the organisation is continuing to manage them.

It will not replace an insurance application, guarantee coverage or automatically reduce a premium. It can, however, provide useful supporting evidence that security is being actively managed rather than reviewed only when an insurance renewal is due.

Making security visible to the business

One of the greatest benefits of Secure Score is that it makes a complex technical subject easier to discuss.

Instead of telling a board or leadership team that dozens of Microsoft policies have been reviewed, we can explain:

  • The organisation’s current position.
  • Whether it is improving or declining.
  • How it compares with the agreed baseline.
  • Which risks still need attention.
  • Why an exception has been accepted.

This creates accountability and allows security improvements to be planned and measured over time.

Our target is not really about the number

Layer3’s 80% target is not about chasing a green indicator on a dashboard.

It is about reducing avoidable risk, applying a consistent Microsoft 365 security baseline and giving customers clear evidence that important protections are in place.

We have demonstrated with a number of customers that an 80% or higher Secure Score is achievable. Maintaining it requires ongoing monitoring, sensible policies and a willingness to respond when Microsoft or the customer’s environment changes.

That is what turns Secure Score from another box-ticking exercise into a useful business security benchmark.

Would you like to understand how your Microsoft 365 environment measures up? Layer3 can assess your current Secure Score, explain the findings in plain language and develop a practical roadmap towards a stronger security baseline. Contact Layer3.

Want better IT?

Layer3 Logo
Layer3 is an ISO 27001 certified MSP in Wellington with offices across New Zealand. Get strategy-first IT, security and managed support from Layer3.
ADDRESS
Level 2 CBD Towers 84-90 Main Street Upper Hutt Wellington, 5018 New Zealand
© 2026 Copyright Layer3.
Layer3 is a Silver Microsoft partner as well as an Authorised SPLA partner.
SMB1001 BronzeSMB1001 SilverSMB1001 GoldISO27001