Microsoft Secure Score in 2026: Why We Target 80%+
Layer3 aims to align every managed customer to a Microsoft Secure Score of at least 80%, wherever licensing and operational requirements allow. This benchmark represents a strong and realistic security position.
Security
Layer3 aims to align every managed customer to a Microsoft Secure Score of at least 80%, wherever licensing and operational requirements allow. This benchmark represents a strong and realistic security position.
What does Microsoft Secure Score actually measure?
Microsoft Secure Score indicates how closely an organisation follows Microsoft’s recommended security practices. Higher scores reflect completed actions across user identities, administrative accounts, email, applications, and devices. The platform enables organisations to monitor changes over time and compare performance with similar organisations.
The score functions as a dashboard rather than an exam result, showing existing protections, remaining gaps, and high-impact improvements. It provides management and IT teams common language for security discussions without addressing hundreds of individual settings.
Microsoft clarifies that Secure Score is not a breach likelihood guarantee — it measures implementation extent of relevant security controls within the Microsoft environment.
Why have we chosen 80% as our target?
Microsoft hasn’t published 80% as an official pass mark. Layer3 selected this benchmark for managed customers because it represents achievable security requiring organisations to address most important, practical recommendations within their Microsoft environment.
The company deliberately avoids pursuing 100% because some recommendations may be inappropriate, require additional licensing, or create unreasonable workplace disruption. Security must be balanced with usability, and not every recommendation will suit every environment, Microsoft advises.
The percentage carries less importance than underlying protections. Secure Score recommendations include:
Requiring multifactor authentication, particularly for administrators
Blocking outdated sign-in methods
Strengthening access and identity policies
Protecting email and collaboration services
Improving device security
Reviewing administrative access and unnecessary permissions
Blocking non-work devices from accessing work resources
Microsoft awards points based on action completion. Some recommendations grant partial points for incomplete deployments, making scores more meaningful than yes-or-no questionnaires by highlighting deployment gaps.
For example, stating your organisation “uses MFA” doesn’t clarify whether protection extends to every account, only administrators, or a small user group. Secure Score exposes these differences.
Why this is not a box-ticking exercise
Security frameworks and checklists hold value but become ineffective when treated as annual paperwork reviews.
Secure Score’s usefulness stems from connection to Microsoft environment configuration, helping demonstrate whether recommended protections were implemented and remain active.
However, Secure Score doesn’t cover all cybersecurity aspects. Microsoft notes recommendations don’t address every attack surface. Backups, network security, non-Microsoft applications, staff awareness, vulnerability management, and incident response also require consideration.
Layer3 treats Secure Score as one benchmark within broader security programmes, using it to measure progress, prioritise work, and identify changes requiring attention — not as a replacement for sound security judgment.
Getting above 80% is only the first step
Reaching 80% represents achievement, but maintaining that position presents greater challenges.
Microsoft continuously updates services and recommendations. New users, devices, and applications appear. Policies change — sometimes intentionally, sometimes accidentally. A strong current security position can gradually deteriorate without notice, a phenomenon called “configuration or policy drift.”
Layer3 manages this through inforcer, which defines Microsoft 365 security baselines, deploys policies consistently, and identifies misaligned customers. It alerts when policies change, maintains Microsoft 365 policy backups, and provides audit trails.
This ensures consistent customer standards rather than relying on manual engineer reviews of every Microsoft tenant setting.
Technology doesn’t replace engineers. Layer3 determines appropriate controls, tests changes, manages customer-specific exceptions, and considers security policy impacts on users.
Microsoft Secure Score’s recommended actions, grouped by control category
What does Secure Score have to do with cyber insurance?
Cyber insurers increasingly demand evidence that organisations understand and actively manage cyber risk.
No universal Microsoft Secure Score requirement exists for obtaining cyber insurance. Insurers unlikely approve or deny policies based solely on reaching 80%.
However, insurers assess many controls influencing strong security postures, commonly including multifactor authentication, identity and access management, endpoint protection, backups, staff training, firewalls, incident response planning, and regular security assessments.
AIG New Zealand describes using “security posture information and risk-reducing controls” to help organisations prioritise improvements and support tailored policy terms.
Secure Score becomes valuable here, providing measurable records of Microsoft 365-implemented controls and demonstrating ongoing management.
It won’t replace insurance applications, guarantee coverage, or automatically reduce premiums. However, it provides useful supporting evidence that security receives active management rather than renewal-only reviews.
Making security visible to the business
Secure Score simplifies complex technical discussions for boards and leadership teams. Rather than explaining dozens of reviewed Microsoft policies, organisations can communicate:
Current organisational position
Whether performance is improving or declining
Comparison with agreed baselines
Remaining risks requiring attention
Reasons for accepted exceptions
This creates accountability and enables measured, planned security improvements over time.
Our target is not really about the number
Layer3’s 80% target isn’t about pursuing green dashboard indicators.
It focuses on reducing avoidable risk, applying consistent Microsoft 365 security baselines, and providing customers clear evidence that important protections exist.
The company has demonstrated that 80%+ Secure Scores are achievable across multiple customers. Maintenance requires ongoing monitoring, sensible policies, and responsiveness when Microsoft or customer environments change.
This transforms Secure Score from another box-ticking exercise into a useful business security benchmark.