You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/reports-monitoring/concept-identity-secure-score.md
+35-25Lines changed: 35 additions & 25 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,62 +1,72 @@
1
1
---
2
-
title: What is identity secure score?
3
-
description: Learn how to use the identity secure score to improve the security posture of your directory.
2
+
title: What is the identity secure score?
3
+
description: Learn how to use the identity secure score to improve the security posture of your Microsoft Entra tenant.
4
4
5
5
services: active-directory
6
6
ms.service: active-directory
7
7
ms.subservice: fundamentals
8
8
ms.topic: conceptual
9
-
ms.date: 09/12/2023
9
+
ms.date: 10/03/2023
10
10
11
-
ms.author: joflore
12
-
author: MicrosoftGuyJFlo
11
+
ms.author: sarahlipsey
12
+
author: shlipsey3
13
13
manager: amycolannino
14
14
ms.reviewer: guptashi
15
+
16
+
# Customer intent: As an IT admin, I want to know how to use the identity secure score and related recommendations to improve the security posture of my Microsoft Entra tenant.
17
+
15
18
---
16
19
# What is identity secure score?
17
20
18
21
The identity secure score is shown as a percentage that functions as an indicator for how aligned you are with Microsoft's recommendations for security. Each improvement action in identity secure score is tailored to your configuration.
- Objectively measure your identity security posture
25
28
- Plan identity security improvements
26
29
- Review the success of your improvements
27
30
28
-
You can access the score and related information on the identity secure score dashboard. On this dashboard, you find:
31
+
You can access the score and view individual recommendations related to your score in Microsoft Entra recommendations. You can also view the score and the full identity secure score dashboard, which compares your score to other tenants in the same industry and of a similar size. The dashboard also shows how your score has changed over time.
29
32
30
-
- Your identity secure score
31
-
- A comparison graph showing how your Identity secure score compares to other tenants in the same industry and similar size
32
-
- A trend graph showing how your Identity secure score has changed over time
33
-
- A list of possible improvements
34
-
35
-
By following the improvement actions, you can:
33
+
By following the improvement actions in the Microsoft Entra recommendations, you can:
36
34
37
35
- Improve your security posture and your score
38
36
- Take advantage the features available to your organization as part of your identity investments
39
37
40
38
## How do I get my secure score?
41
39
42
-
Identity secure score is available to free and paid customers.
40
+
Identity secure score is available to free and paid customers.
43
41
44
42
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Global Reader](../roles/permissions-reference.md#global-reader).
45
-
1. Browse to **Protection** > **Identity Secure Score**.
43
+
1. Browse to **Protection** > **Identity Secure Score** to view the dashboard.
44
+
45
+
The score and related recommendations are also found at **Identity** > **Overview** > **Recommendations**.
46
46
47
47
## How does it work?
48
48
49
-
Every 48 hours, we look at your security configuration and compare your settings with the recommended best practices. Based on the outcome of this evaluation, a new score is calculated for your directory. It’s possible that your security configuration isn’t fully aligned with the best practice guidance and the improvement actions are only partially met. In these scenarios, you're awarded a portion of the max score available for the control.
49
+
Every 24 hours, we look at your security configuration and compare your settings with the recommended best practices. Based on the outcome of this evaluation, a new score is calculated for your directory. It’s possible that your security configuration isn’t fully aligned with the best practice guidance and the improvement actions are only partially met. In these scenarios, you're awarded a portion of the max score available for the control.
50
+
51
+
### Working with improvement actions on the dashboard
50
52
51
53
Each recommendation is measured based on your configuration. If you're using third-party products to enable a best practice recommendation, you can indicate this configuration in the settings of an improvement action. You may set recommendations to be ignored if they don't apply to your environment. An ignored recommendation doesn't contribute to the calculation of your score.
52
54
53
-

55
+

54
56
55
57
-**To address** - You recognize that the improvement action is necessary and plan to address it at some point in the future. This state also applies to actions that are detected as partially, but not fully completed.
56
-
-**Planned** - There are concrete plans in place to complete the improvement action.
57
58
-**Risk accepted** - Security should always be balanced with usability, and not every recommendation works for everyone. When that is the case, you can choose to accept the risk, or the remaining risk, and not enact the improvement action. You aren't awarded any points, and the action isn't visible in the list of improvement actions. You can view this action in history or undo it at any time.
59
+
-**Planned** - There are concrete plans in place to complete the improvement action.
58
60
-**Resolved through third party** and **Resolved through alternate mitigation** - The improvement action has already been addressed by a third-party application or software, or an internal tool. You're awarded the points the action is worth, so your score better reflects your overall security posture. If a third party or internal tool no longer covers the control, you can choose another status. Keep in mind, Microsoft has no visibility into the completeness of implementation if the improvement action is marked as either of these statuses.
59
61
62
+
### Working with secure score recommendations
63
+
64
+
Identity secure score improvement actions also appear in Microsoft Entra recommendations. They both appear in the same list, but the secure score recommendations show the score.
65
+
66
+

67
+
68
+
To address a secure score recommendation, select it from the list to view the details and action plan. If you take the appropriate action, the status changes automatically the next time the service runs. You can also mark the recommendation as *dismissed* or *postponed*. For more information on working with recommendations, see [How to use recommendations](./howto-use-recommendations.md).
69
+
60
70
## How does it help me?
61
71
62
72
The secure score helps you to:
@@ -67,6 +77,8 @@ The secure score helps you to:
67
77
68
78
## What you should know
69
79
80
+
There are several things to consider when working with your identity secure score.
81
+
70
82
### Who can use the identity secure score?
71
83
72
84
To access identity secure score, you must be assigned one of the following roles in Microsoft Entra ID.
@@ -101,7 +113,9 @@ Actions labeled as [Not Scored] are ones you can perform in your organization bu
101
113
102
114
### How often is my score updated?
103
115
104
-
The score is calculated once per day (around 1:00 AM PST). If you make a change to a measured action, the score will automatically update the next day. It takes up to 48 hours for a change to be reflected in your score.
116
+
The score is calculated once per day (around 1:00 AM PST). If you make a change to a measured action, the score will automatically update the next day. It may take up to 48 hours for a change to be reflected in your score.
117
+
118
+

105
119
106
120
### My score changed. How do I figure out why?
107
121
@@ -113,7 +127,7 @@ No, secure score doesn't express an absolute measure of how likely you're to get
113
127
114
128
### How should I interpret my score?
115
129
116
-
Your score improves for configuring recommended security features or performing security-related tasks (like reading reports). Some actions are scored for partial completion, like enabling multi-factor authentication (MFA) for your users. Your secure score is directly representative of the Microsoft security services you use. Remember that security must be balanced with usability. All security controls have a user impact component. Controls with low user impact should have little to no effect on your users' day-to-day operations.
130
+
Your score improves for configuring recommended security features or performing security-related tasks (like reading reports). Some actions are scored for partial completion, like enabling multifactor authentication (MFA) for your users. Your secure score is directly representative of the Microsoft security services you use. Remember that security must be balanced with usability. All security controls have a user impact component. Controls with low user impact should have little to no effect on your users' day-to-day operations.
117
131
118
132
To see your score history, head over to the [Microsoft 365 Defender portal](https://security.microsoft.com/) and review your overall Microsoft secure score. You can review changes to your overall secure score be clicking on View History. Choose a specific date to see which controls were enabled for that day and what points you earned for each one.
119
133
@@ -127,8 +141,4 @@ The [Microsoft secure score](/office365/securitycompliance/microsoft-secure-scor
127
141
- Infrastructure
128
142
- Apps
129
143
130
-
The identity secure score represents the identity part of the Microsoft secure score. This overlap means that your recommendations for the identity secure score and the identity score in Microsoft are the same.
131
-
132
-
## Next steps
133
-
134
-
[Find out more about Microsoft secure score](/office365/securitycompliance/microsoft-secure-score)
144
+
The identity secure score represents the identity part of the Microsoft secure score. This overlap means that your recommendations for the identity secure score and the identity score in Microsoft are the same.
description: Provides a general overview of Microsoft Entra recommendations.
3
+
description: Provides a general overview of Microsoft Entra recommendations so you can keep your tenant secure and healthy.
4
4
services: active-directory
5
5
author: shlipsey3
6
6
manager: amycolannino
7
7
ms.service: active-directory
8
8
ms.topic: overview
9
-
ms.tgt_pltfrm: na
10
9
ms.workload: identity
11
10
ms.subservice: report-monitor
12
-
ms.date: 09/21/2023
11
+
ms.date: 10/03/2023
13
12
ms.author: sarahlipsey
14
13
ms.reviewer: hafowler
15
14
@@ -19,30 +18,36 @@ ms.reviewer: hafowler
19
18
20
19
# What are Microsoft Entra recommendations?
21
20
22
-
Keeping track of all the settings and resources in your tenant can be overwhelming. The Microsoft Entra recommendations feature helps monitor the status of your tenant so you don't have to. The Microsoft Entra recommendations feature helps ensure your tenant is in a secure and healthy state while also helping you maximize the value of the features available in Microsoft Entra ID.
21
+
Keeping track of all the settings and resources in your tenant can be overwhelming. The Microsoft Entra recommendations feature helps monitor the status of your tenant so you don't have to. These recommendations help ensure your tenant is in a secure and healthy state while also helping you maximize the value of the features available in Microsoft Entra ID.
23
22
24
-
The Microsoft Entra recommendations feature provides you with personalized insights with actionable guidance to:
23
+
Microsoft Entra recommendations now include *identity secure score* recommendations. These recommendations provide similar insights into the security of your tenant. Identity secure score recommendations include *secure score points*, which are calculated as an overall score based on several security factors. For more information, see [What is Identity Secure Score](concept-identity-secure-score.md).
24
+
25
+
All these Microsoft Entra recommendations provide you with personalized insights with actionable guidance to:
25
26
26
27
- Help you identify opportunities to implement best practices for Microsoft Entra ID-related features.
27
28
- Improve the state of your Microsoft Entra tenant.
28
29
- Optimize the configurations for your scenarios.
29
30
30
-
This article gives you an overview of how you can use Microsoft Entra recommendations. As an administrator, you should review your tenant's Microsoft Entra recommendations, and their associated resources periodically.
31
-
32
-
## What it is
31
+
This article gives you an overview of how you can use Microsoft Entra recommendations.
33
32
34
-
The Microsoft Entra recommendations feature is the Microsoft Entra specific implementation of [Azure Advisor](../../advisor/advisor-overview.md), which is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. Azure Advisor analyzes your resource configuration and usage data to recommend solutions that can help you improve the cost effectiveness, performance, reliability, and security of your Azure resources.
33
+
## How does it work?
35
34
36
-
*Microsoft Entra recommendations* use similar data to support you with the roll-out and management of Microsoft's best practices for Microsoft Entra tenants to keep your tenant in a secure and healthy state. The Microsoft Entra recommendations feature provides a holistic view into your tenant's security, health, and usage.
35
+
On a daily basis, Microsoft Entra ID analyzes the configuration of your tenant. During this analysis, Microsoft Entra ID compares the configuration of your tenant with security best practices and recommendation data. If a recommendation is flagged as applicable to your tenant, the recommendation appears in the **Recommendations** section of the Microsoft Entra identity overview area. The recommendations are listed in order of priority so you can quickly determine where to focus first.
37
36
38
-
## How it works
37
+

39
38
40
-
On a daily basis, Microsoft Entra ID analyzes the configuration of your tenant. During this analysis, Microsoft Entra ID compares the data of a recommendation with the actual configuration of your tenant. If a recommendation is flagged as applicable to your tenant, the recommendation appears in the **Recommendations** section of the Identity Overview area. The recommendations are listed in order of priority so you can quickly determine where to focus first.
39
+
Your identity secure score, which appears at the top of the page, is a numerical representation of the health of your tenant. Recommendations that apply to the Identity Secure Score are given individual scores in the table at the bottom of the page. These scores are added up to generate your Identity Secure Score. For more information, see [What is identity secure score](concept-identity-secure-score.md).
41
40
42
-

41
+

43
42
44
43
Each recommendation contains a description, a summary of the value of addressing the recommendation, and a step-by-step action plan. If applicable, impacted resources associated with the recommendation are listed, so you can resolve each affected area. If a recommendation doesn't have any associated resources, the impacted resource type is *Tenant level*, so your step-by-step action plan impacts the entire tenant and not just a specific resource.
45
44
45
+
## Are Microsoft Entra recommendations related to Azure Advisor?
46
+
47
+
The Microsoft Entra recommendations feature is the Microsoft Entra specific implementation of [Azure Advisor](../../advisor/advisor-overview.md), which is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. Azure Advisor analyzes your resource configuration and usage data to recommend solutions that can help you improve the cost effectiveness, performance, reliability, and security of your Azure resources.
48
+
49
+
Microsoft Entra recommendations use similar data to support you with the roll-out and management of Microsoft's best practices for Microsoft Entra tenants to keep your tenant in a secure and healthy state. The Microsoft Entra recommendations feature provides a holistic view into your tenant's security, health, and usage.
50
+
46
51
## Recommendation availability and license requirements
47
52
48
53
The recommendations listed in the following table are currently available in public preview or general availability. The license requirements for recommendations in public preview are subject to change. The table provides the impacted resources and links to available documentation.
@@ -60,8 +65,3 @@ The recommendations listed in the following table are currently available in pub
60
65
|[Renew expiring service principal credentials](recommendation-renew-expiring-service-principal-credential.md)| Applications |[Microsoft Entra Workload ID Premium](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-id)| Preview |
61
66
62
67
Microsoft Entra-only displays the recommendations that apply to your tenant, so you may not see all supported recommendations listed.
63
-
64
-
## Next steps
65
-
66
-
*[Learn how to use Microsoft Entra recommendations](howto-use-recommendations.md)
67
-
*[Explore the details of the "Turn off per-user MFA" recommendation](recommendation-turn-off-per-user-mfa.md)
0 commit comments