Skip to content

Commit eeb11e9

Browse files
committed
Update microsoft-secure-score.md
1 parent 2945356 commit eeb11e9

File tree

1 file changed

+28
-24
lines changed

1 file changed

+28
-24
lines changed

defender-xdr/microsoft-secure-score.md

Lines changed: 28 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.topic: conceptual
1717
search.appverid:
1818
- MOE150
1919
- MET150
20-
ms.date: 08/03/2023
20+
ms.date: 06/28/2024
2121
---
2222

2323
# Microsoft Secure Score
@@ -43,15 +43,15 @@ Organizations gain access to robust visualizations of metrics and trends, integr
4343

4444
## How it works
4545

46-
You're given points for the following actions:
46+
You get points for the following actions:
4747

4848
- Configuring recommended security features
4949
- Doing security-related tasks
5050
- Addressing the recommended action with a non-Microsoft application or software, or an alternate mitigation
5151

52-
Some recommended actions only give points when fully completed. Some give partial points if they're completed for some devices or users. If you can't or don't want to enact one of the recommended actions, you can choose to accept the risk or remaining risk.
52+
Some recommended actions only give points when fully completed. Some actions result in partial points if tasks are completed for some devices or users. If you can't or don't want to enact one of the recommended actions, you can choose to accept the risk or remaining risk.
5353

54-
If you have a license for one of the supported Microsoft products, then you'll see recommendations for those products. We show you the full set of possible recommendations for a product, regardless of license edition, subscription, or plan. This way, you can understand security best practices and improve your score. Your absolute security posture, represented by Secure Score, stays the same no matter what licenses your organization owns for a specific product. Keep in mind that security should be balanced with usability, and not every recommendation can work for your environment.
54+
If you have a license for one of the supported Microsoft products, then you see recommendations for those products. We show you the full set of possible recommendations for a product, regardless of license edition, subscription, or plan. This way, you can understand security best practices and improve your score. Your absolute security posture, represented by Secure Score, stays the same no matter what licenses your organization owns for a specific product. Keep in mind that security should be balanced with usability, and not every recommendation can work for your environment.
5555

5656
Your score is updated in real time to reflect the information presented in the visualizations and recommended action pages. Secure Score also syncs daily to receive system data about your achieved points for each action.
5757

@@ -69,7 +69,7 @@ Your score is updated in real time to reflect the information presented in the v
6969

7070
Each recommended action is worth 10 points or less, and most are scored in a binary fashion. If you implement the recommended action, like create a new policy or turn on a specific setting, you get 100% of the points. For other recommended actions, points are given as a percentage of the total configuration.
7171

72-
For example, a recommended action states you get 10 points by protecting all your users with multi-factor authentication. You only have 50 of 100 total users protected, so you'd get a partial score of five points (50 protected / 100 total * 10 max pts = 5 pts).
72+
For example, a recommended action states you get 10 points by protecting all your users with multifactor authentication. You only have 50 of 100 total users protected, so you'd get a partial score of five points (50 protected / 100 total * 10 max pts = 5 pts).
7373

7474
### Products included in Secure Score
7575

@@ -85,38 +85,41 @@ Currently there are recommendations for the following products:
8585
- Exchange Online
8686
- GitHub
8787
- Microsoft Defender for Cloud Apps
88-
- Microsoft Information Protection
88+
- Microsoft Purview Information Protection
8989
- Microsoft Teams
9090
- Okta
9191
- Salesforce
9292
- ServiceNow
9393
- SharePoint Online
9494
- Zoom
9595

96-
Recommendations for other security products are coming soon. The recommendations won't cover all the attack surfaces associated with each product, but they're a good baseline. You can also mark the recommended actions as covered by a third party or alternate mitigation.
96+
Recommendations for other security products are coming soon. The recommendations don't cover all the attack surfaces associated with each product, but they're a good baseline. You can also mark the recommended actions as covered by a non-Microsoft solution or alternate mitigation.
9797

9898
### Security defaults
9999

100-
Microsoft Secure Score has updated recommended actions to support [security defaults in Microsoft Entra ID](/azure/active-directory/fundamentals/concept-fundamentals-security-defaults), which make it easier to help protect your organization with pre-configured security settings for common attacks.
100+
Microsoft Secure Score includes updated recommended actions to support [security defaults in Microsoft Entra ID](/azure/active-directory/fundamentals/concept-fundamentals-security-defaults), which make it easier to help protect your organization with preconfigured security settings for common attacks.
101101

102-
If you turn on security defaults, you'll be awarded full points for the following recommended actions:
102+
If you turn on security defaults, you are awarded full points for the following recommended actions:
103103

104-
- Ensure all users can complete multi-factor authentication for secure access (9 points)
104+
- Ensure all users can complete multifactor authentication for secure access (nine points)
105105
- Require MFA for administrative roles (10 points)
106-
- Enable policy to block legacy authentication (7 points)
106+
- Enable policy to block legacy authentication (seven points)
107107

108108
> [!IMPORTANT]
109109
> Security defaults include security features that provide similar security to the "sign-in risk policy" and "user risk policy" recommended actions. Instead of setting up these policies on top of the security defaults, we recommend updating their statuses to "Resolved through alternative mitigation."
110110
111111
## Secure Score permissions
112112

113+
> [!IMPORTANT]
114+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
115+
113116
<a name='manage-permissions-with-microsoft-365-defender-unified-role-based-access-controlrbac'></a>
114117

115118
### Manage permissions with Microsoft Defender XDR Unified role-based access control(RBAC)
116119

117-
With [Microsoft Defender XDR Unified role-based access control(RBAC)](manage-rbac.md), you can create custom roles with specific permissions for Secure Score. This allows you to control which users have access to Secure Score data, the products for which they'll see Secure Score data (for example, Microsoft Defender for Endpoint) and their permission level to the data.
120+
With [Microsoft Defender XDR Unified role-based access control(RBAC)](manage-rbac.md), you can create custom roles with specific permissions for Secure Score. Unified RBAC allows you to control which users have access to Secure Score data, the products for which they see Secure Score data (for example, Microsoft Defender for Endpoint) and their permission level to the data.
118121

119-
You can also manage user permissions to access Secure Score data from additional data sources, such as the other products supported by Secure Score, for more information, see [Products included in Secure Score](#products-included-in-secure-score). You can view the Secure Score data from the additional data sources either alone or alongside the other data sources.
122+
You can also manage user permissions to access Secure Score data from additional data sources, such as the other products supported by Secure Score, for more information, see [Products included in Secure Score](#products-included-in-secure-score). You can view the Secure Score data from the other data sources either alone or alongside the other data sources.
120123

121124
To start using Microsoft Defender XDR Unified RBAC to manage your Secure Score permissions, see [Microsoft Defender XDR Unified role-based access control(RBAC)](manage-rbac.md).
122125

@@ -131,26 +134,26 @@ Microsoft Entra global roles (for example, Global Administrator) can still be us
131134

132135
The following roles have read and write access and can make changes, directly interact with Secure Score, and can assign read-only access to other users:
133136

134-
- Global administrator
135-
- Security administrator
136-
- Exchange administrator
137-
- SharePoint administrator
137+
- Global Administrator
138+
- Security Administrator
139+
- Exchange Administrator
140+
- SharePoint Administrator
138141

139142
The following roles have read-only access and aren't able to edit status or notes for a recommended action, edit score zones, or edit custom comparisons:
140143

141-
- Helpdesk administrator
142-
- User administrator
143-
- Service support administrator
144-
- Security reader
145-
- Security operator
146-
- Global reader
144+
- Helpdesk Administrator
145+
- User Administrator
146+
- Service Support Administrator
147+
- Security Reader
148+
- Security Operator
149+
- Global Reader
147150

148151
> [!NOTE]
149152
> If you want to follow the principle of least privilege access (where you only give users and groups the permissions, they need to do their job), Microsoft recommends that you remove any existing elevated Microsoft Entra global roles for users and/or security groups assigned a custom role with Secure Score permissions. This will ensure that the custom Microsoft Defender XDR Unified RBAC roles will take effect.
150153
151154
## Risk awareness
152155

153-
Microsoft Secure Score is a numerical summary of your security posture based on system configurations, user behavior, and other security-related measurements. It isn't an absolute measurement of how likely your system or data will be breached. Rather, it represents the extent to which you have adopted security controls in your Microsoft environment that can help offset the risk of being breached. No online service is immune from security breaches, and secure score shouldn't be interpreted as a guarantee against security breach in any manner.
156+
Microsoft Secure Score is a numerical summary of your security posture based on system configurations, user behavior, and other security-related measurements. It isn't an absolute measurement of how likely your system or data could be breached. Rather, it represents the extent to which you have adopted security controls in your Microsoft environment that can help offset the risk of being breached. No online service is immune from security breaches, and secure score shouldn't be interpreted as a guarantee against security breach in any manner.
154157

155158
## We want to hear from you
156159

@@ -162,4 +165,5 @@ If you have any issues, let us know by posting in the [Security, Privacy & Compl
162165
- [Track your Microsoft Secure Score history and meet goals](microsoft-secure-score-history-metrics-trends.md)
163166
- [What's coming](whats-new.md)
164167
- [What's new](microsoft-secure-score-whats-new.md)
168+
165169
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]

0 commit comments

Comments
 (0)