Skip to content

Commit 17cdba4

Browse files
Merge pull request #253337 from shlipsey3/recommendations-092923
recommendations-092923
2 parents 58ee47e + 5cc813e commit 17cdba4

File tree

9 files changed

+58
-43
lines changed

9 files changed

+58
-43
lines changed

.openpublishing.redirection.active-directory.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5460,6 +5460,11 @@
54605460
"redirect_url": "/azure/active-directory/fundamentals/concept-fundamentals-security-defaults",
54615461
"redirect_document_id": true
54625462
},
5463+
{
5464+
"source_path_from_root": "/articles/active-directory/fundamentals/identity-secure-score.md",
5465+
"redirect_url": "/azure/active-directory/reports-monitoring/concept-identity-secure-score",
5466+
"redirect_document_id": true
5467+
},
54635468
{
54645469
"source_path_from_root": "/articles/active-directory/reports-monitoring/reference-azure-ad-sla-performance.md",
54655470
"redirect_url": "/azure/active-directory/reports-monitoring/reference-sla-performance",

articles/active-directory/fundamentals/identity-secure-score.md renamed to articles/active-directory/reports-monitoring/concept-identity-secure-score.md

Lines changed: 35 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -1,62 +1,72 @@
11
---
2-
title: What is identity secure score?
3-
description: Learn how to use the identity secure score to improve the security posture of your directory.
2+
title: What is the identity secure score?
3+
description: Learn how to use the identity secure score to improve the security posture of your Microsoft Entra tenant.
44

55
services: active-directory
66
ms.service: active-directory
77
ms.subservice: fundamentals
88
ms.topic: conceptual
9-
ms.date: 09/12/2023
9+
ms.date: 10/03/2023
1010

11-
ms.author: joflore
12-
author: MicrosoftGuyJFlo
11+
ms.author: sarahlipsey
12+
author: shlipsey3
1313
manager: amycolannino
1414
ms.reviewer: guptashi
15+
16+
# Customer intent: As an IT admin, I want to know how to use the identity secure score and related recommendations to improve the security posture of my Microsoft Entra tenant.
17+
1518
---
1619
# What is identity secure score?
1720

1821
The identity secure score is shown as a percentage that functions as an indicator for how aligned you are with Microsoft's recommendations for security. Each improvement action in identity secure score is tailored to your configuration.
1922

20-
![Secure score](./media/identity-secure-score/identity-secure-score-overview.png)
23+
![Secure score](./media/concept-identity-secure-score/recommendations-identity-secure-score.png)
2124

2225
This score helps to:
2326

2427
- Objectively measure your identity security posture
2528
- Plan identity security improvements
2629
- Review the success of your improvements
2730

28-
You can access the score and related information on the identity secure score dashboard. On this dashboard, you find:
31+
You can access the score and view individual recommendations related to your score in Microsoft Entra recommendations. You can also view the score and the full identity secure score dashboard, which compares your score to other tenants in the same industry and of a similar size. The dashboard also shows how your score has changed over time.
2932

30-
- Your identity secure score
31-
- A comparison graph showing how your Identity secure score compares to other tenants in the same industry and similar size
32-
- A trend graph showing how your Identity secure score has changed over time
33-
- A list of possible improvements
34-
35-
By following the improvement actions, you can:
33+
By following the improvement actions in the Microsoft Entra recommendations, you can:
3634

3735
- Improve your security posture and your score
3836
- Take advantage the features available to your organization as part of your identity investments
3937

4038
## How do I get my secure score?
4139

42-
Identity secure score is available to free and paid customers.
40+
Identity secure score is available to free and paid customers.
4341

4442
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Global Reader](../roles/permissions-reference.md#global-reader).
45-
1. Browse to **Protection** > **Identity Secure Score**.
43+
1. Browse to **Protection** > **Identity Secure Score** to view the dashboard.
44+
45+
The score and related recommendations are also found at **Identity** > **Overview** > **Recommendations**.
4646

4747
## How does it work?
4848

49-
Every 48 hours, we look at your security configuration and compare your settings with the recommended best practices. Based on the outcome of this evaluation, a new score is calculated for your directory. It’s possible that your security configuration isn’t fully aligned with the best practice guidance and the improvement actions are only partially met. In these scenarios, you're awarded a portion of the max score available for the control.
49+
Every 24 hours, we look at your security configuration and compare your settings with the recommended best practices. Based on the outcome of this evaluation, a new score is calculated for your directory. It’s possible that your security configuration isn’t fully aligned with the best practice guidance and the improvement actions are only partially met. In these scenarios, you're awarded a portion of the max score available for the control.
50+
51+
### Working with improvement actions on the dashboard
5052

5153
Each recommendation is measured based on your configuration. If you're using third-party products to enable a best practice recommendation, you can indicate this configuration in the settings of an improvement action. You may set recommendations to be ignored if they don't apply to your environment. An ignored recommendation doesn't contribute to the calculation of your score.
5254

53-
![Ignore or mark action as covered by third party](./media/identity-secure-score/identity-secure-score-ignore-or-third-party-reccomendations.png)
55+
![Ignore or mark action as covered by third party](./media/concept-identity-secure-score/identity-secure-score-ignore-or-third-party-reccomendations.png)
5456

5557
- **To address** - You recognize that the improvement action is necessary and plan to address it at some point in the future. This state also applies to actions that are detected as partially, but not fully completed.
56-
- **Planned** - There are concrete plans in place to complete the improvement action.
5758
- **Risk accepted** - Security should always be balanced with usability, and not every recommendation works for everyone. When that is the case, you can choose to accept the risk, or the remaining risk, and not enact the improvement action. You aren't awarded any points, and the action isn't visible in the list of improvement actions. You can view this action in history or undo it at any time.
59+
- **Planned** - There are concrete plans in place to complete the improvement action.
5860
- **Resolved through third party** and **Resolved through alternate mitigation** - The improvement action has already been addressed by a third-party application or software, or an internal tool. You're awarded the points the action is worth, so your score better reflects your overall security posture. If a third party or internal tool no longer covers the control, you can choose another status. Keep in mind, Microsoft has no visibility into the completeness of implementation if the improvement action is marked as either of these statuses.
5961

62+
### Working with secure score recommendations
63+
64+
Identity secure score improvement actions also appear in Microsoft Entra recommendations. They both appear in the same list, but the secure score recommendations show the score.
65+
66+
![Screenshot of the recommendations list with the secure score recommendations highlighted.](./media/concept-identity-secure-score/secure-score-recommendations-list.png)
67+
68+
To address a secure score recommendation, select it from the list to view the details and action plan. If you take the appropriate action, the status changes automatically the next time the service runs. You can also mark the recommendation as *dismissed* or *postponed*. For more information on working with recommendations, see [How to use recommendations](./howto-use-recommendations.md).
69+
6070
## How does it help me?
6171

6272
The secure score helps you to:
@@ -67,6 +77,8 @@ The secure score helps you to:
6777

6878
## What you should know
6979

80+
There are several things to consider when working with your identity secure score.
81+
7082
### Who can use the identity secure score?
7183

7284
To access identity secure score, you must be assigned one of the following roles in Microsoft Entra ID.
@@ -101,7 +113,9 @@ Actions labeled as [Not Scored] are ones you can perform in your organization bu
101113

102114
### How often is my score updated?
103115

104-
The score is calculated once per day (around 1:00 AM PST). If you make a change to a measured action, the score will automatically update the next day. It takes up to 48 hours for a change to be reflected in your score.
116+
The score is calculated once per day (around 1:00 AM PST). If you make a change to a measured action, the score will automatically update the next day. It may take up to 48 hours for a change to be reflected in your score.
117+
118+
![Screenshot of the secure score with the last updated date and time highlighted.](./media/concept-identity-secure-score/secure-score-refresh-time.png)
105119

106120
### My score changed. How do I figure out why?
107121

@@ -113,7 +127,7 @@ No, secure score doesn't express an absolute measure of how likely you're to get
113127

114128
### How should I interpret my score?
115129

116-
Your score improves for configuring recommended security features or performing security-related tasks (like reading reports). Some actions are scored for partial completion, like enabling multi-factor authentication (MFA) for your users. Your secure score is directly representative of the Microsoft security services you use. Remember that security must be balanced with usability. All security controls have a user impact component. Controls with low user impact should have little to no effect on your users' day-to-day operations.
130+
Your score improves for configuring recommended security features or performing security-related tasks (like reading reports). Some actions are scored for partial completion, like enabling multifactor authentication (MFA) for your users. Your secure score is directly representative of the Microsoft security services you use. Remember that security must be balanced with usability. All security controls have a user impact component. Controls with low user impact should have little to no effect on your users' day-to-day operations.
117131

118132
To see your score history, head over to the [Microsoft 365 Defender portal](https://security.microsoft.com/) and review your overall Microsoft secure score. You can review changes to your overall secure score be clicking on View History. Choose a specific date to see which controls were enabled for that day and what points you earned for each one.
119133

@@ -127,8 +141,4 @@ The [Microsoft secure score](/office365/securitycompliance/microsoft-secure-scor
127141
- Infrastructure
128142
- Apps
129143

130-
The identity secure score represents the identity part of the Microsoft secure score. This overlap means that your recommendations for the identity secure score and the identity score in Microsoft are the same.
131-
132-
## Next steps
133-
134-
[Find out more about Microsoft secure score](/office365/securitycompliance/microsoft-secure-score)
144+
The identity secure score represents the identity part of the Microsoft secure score. This overlap means that your recommendations for the identity secure score and the identity score in Microsoft are the same.
Loading
Loading
12.4 KB
Loading
7.42 KB
Loading
Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,14 @@
11
---
22
title: What are Microsoft Entra recommendations?
3-
description: Provides a general overview of Microsoft Entra recommendations.
3+
description: Provides a general overview of Microsoft Entra recommendations so you can keep your tenant secure and healthy.
44
services: active-directory
55
author: shlipsey3
66
manager: amycolannino
77
ms.service: active-directory
88
ms.topic: overview
9-
ms.tgt_pltfrm: na
109
ms.workload: identity
1110
ms.subservice: report-monitor
12-
ms.date: 09/21/2023
11+
ms.date: 10/03/2023
1312
ms.author: sarahlipsey
1413
ms.reviewer: hafowler
1514

@@ -19,30 +18,36 @@ ms.reviewer: hafowler
1918

2019
# What are Microsoft Entra recommendations?
2120

22-
Keeping track of all the settings and resources in your tenant can be overwhelming. The Microsoft Entra recommendations feature helps monitor the status of your tenant so you don't have to. The Microsoft Entra recommendations feature helps ensure your tenant is in a secure and healthy state while also helping you maximize the value of the features available in Microsoft Entra ID.
21+
Keeping track of all the settings and resources in your tenant can be overwhelming. The Microsoft Entra recommendations feature helps monitor the status of your tenant so you don't have to. These recommendations help ensure your tenant is in a secure and healthy state while also helping you maximize the value of the features available in Microsoft Entra ID.
2322

24-
The Microsoft Entra recommendations feature provides you with personalized insights with actionable guidance to:
23+
Microsoft Entra recommendations now include *identity secure score* recommendations. These recommendations provide similar insights into the security of your tenant. Identity secure score recommendations include *secure score points*, which are calculated as an overall score based on several security factors. For more information, see [What is Identity Secure Score](concept-identity-secure-score.md).
24+
25+
All these Microsoft Entra recommendations provide you with personalized insights with actionable guidance to:
2526

2627
- Help you identify opportunities to implement best practices for Microsoft Entra ID-related features.
2728
- Improve the state of your Microsoft Entra tenant.
2829
- Optimize the configurations for your scenarios.
2930

30-
This article gives you an overview of how you can use Microsoft Entra recommendations. As an administrator, you should review your tenant's Microsoft Entra recommendations, and their associated resources periodically.
31-
32-
## What it is
31+
This article gives you an overview of how you can use Microsoft Entra recommendations.
3332

34-
The Microsoft Entra recommendations feature is the Microsoft Entra specific implementation of [Azure Advisor](../../advisor/advisor-overview.md), which is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. Azure Advisor analyzes your resource configuration and usage data to recommend solutions that can help you improve the cost effectiveness, performance, reliability, and security of your Azure resources.
33+
## How does it work?
3534

36-
*Microsoft Entra recommendations* use similar data to support you with the roll-out and management of Microsoft's best practices for Microsoft Entra tenants to keep your tenant in a secure and healthy state. The Microsoft Entra recommendations feature provides a holistic view into your tenant's security, health, and usage.
35+
On a daily basis, Microsoft Entra ID analyzes the configuration of your tenant. During this analysis, Microsoft Entra ID compares the configuration of your tenant with security best practices and recommendation data. If a recommendation is flagged as applicable to your tenant, the recommendation appears in the **Recommendations** section of the Microsoft Entra identity overview area. The recommendations are listed in order of priority so you can quickly determine where to focus first.
3736

38-
## How it works
37+
![Screenshot of the Overview page of the tenant with the Recommendations option highlighted.](./media/overview-recommendations/recommendations-overview.png)
3938

40-
On a daily basis, Microsoft Entra ID analyzes the configuration of your tenant. During this analysis, Microsoft Entra ID compares the data of a recommendation with the actual configuration of your tenant. If a recommendation is flagged as applicable to your tenant, the recommendation appears in the **Recommendations** section of the Identity Overview area. The recommendations are listed in order of priority so you can quickly determine where to focus first.
39+
Your identity secure score, which appears at the top of the page, is a numerical representation of the health of your tenant. Recommendations that apply to the Identity Secure Score are given individual scores in the table at the bottom of the page. These scores are added up to generate your Identity Secure Score. For more information, see [What is identity secure score](concept-identity-secure-score.md).
4140

42-
![Screenshot of the Overview page of the tenant with the Recommendations option highlighted.](./media/overview-recommendations/recommendations-overview.png)
41+
![Screenshot of the identity secure score.](./media/overview-recommendations/identity-secure-score.png)
4342

4443
Each recommendation contains a description, a summary of the value of addressing the recommendation, and a step-by-step action plan. If applicable, impacted resources associated with the recommendation are listed, so you can resolve each affected area. If a recommendation doesn't have any associated resources, the impacted resource type is *Tenant level*, so your step-by-step action plan impacts the entire tenant and not just a specific resource.
4544

45+
## Are Microsoft Entra recommendations related to Azure Advisor?
46+
47+
The Microsoft Entra recommendations feature is the Microsoft Entra specific implementation of [Azure Advisor](../../advisor/advisor-overview.md), which is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. Azure Advisor analyzes your resource configuration and usage data to recommend solutions that can help you improve the cost effectiveness, performance, reliability, and security of your Azure resources.
48+
49+
Microsoft Entra recommendations use similar data to support you with the roll-out and management of Microsoft's best practices for Microsoft Entra tenants to keep your tenant in a secure and healthy state. The Microsoft Entra recommendations feature provides a holistic view into your tenant's security, health, and usage.
50+
4651
## Recommendation availability and license requirements
4752

4853
The recommendations listed in the following table are currently available in public preview or general availability. The license requirements for recommendations in public preview are subject to change. The table provides the impacted resources and links to available documentation.
@@ -60,8 +65,3 @@ The recommendations listed in the following table are currently available in pub
6065
| [Renew expiring service principal credentials](recommendation-renew-expiring-service-principal-credential.md) | Applications | [Microsoft Entra Workload ID Premium](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-id) | Preview |
6166

6267
Microsoft Entra-only displays the recommendations that apply to your tenant, so you may not see all supported recommendations listed.
63-
64-
## Next steps
65-
66-
* [Learn how to use Microsoft Entra recommendations](howto-use-recommendations.md)
67-
* [Explore the details of the "Turn off per-user MFA" recommendation](recommendation-turn-off-per-user-mfa.md)

0 commit comments

Comments
 (0)