A Conditional Access policy switched off
Disabled to troubleshoot a sign-in issue and never re-enabled. The tenant looks fine in the portal until you check policy state.
Security posture
Security posture is the ongoing state of Microsoft 365 configuration, identity controls, and monitored assets across your customer tenants. It is not a checklist you complete once. SecurityScore.me tracks posture on a schedule and surfaces regressions as severity-ranked findings.
A one-time hardening pass tells you where a tenant stood on the day someone looked. Posture management is about the days in between.
The value of an audit decays from the moment it is finished. An administrator disables a Conditional Access policy to troubleshoot a login, adds an MFA exclusion "for now", or re-enables a legacy protocol for one device, and the clean report you delivered last month no longer describes reality.
A posture program replaces the annual snapshot with a schedule: re-assess, compare against the last run, and raise what changed.
Most tenants do not get breached because someone designed them badly. They drift — a series of small, individually reasonable changes that add up to a weaker configuration than anyone intended.
Catching drift means storing a baseline and diffing every subsequent assessment against it, so a control that was enforced in January and is report-only in April becomes a finding rather than a surprise.
Posture data is only useful if a technician can act on it. Every issue carries a severity, remediation guidance, and the customer context, so work is prioritised by risk instead of by whichever tenant was looked at most recently.
With a baseline per tenant, the organization view can rank customers by how far they have moved from their own known-good state, not just by an absolute score. A small regression in a well-configured tenant can matter more than a low score that has been low and accepted for a year.
Posture is broader than any single Microsoft metric. SecurityScore.me assembles it from several read-only Graph signals plus the external assets registered in the workspace.
Policy coverage and exclusions, MFA registration versus enforcement, admin-specific protection, session controls, and legacy authentication. Identity gaps are the most common source of posture regressions between reviews.
Secure Score is tracked as one input, with its trend and any regression, rather than treated as the whole picture. Improvement actions become findings your team can assign and close.
Defender for Endpoint posture and alerts where the customer is licensed, so endpoint state sits alongside identity and configuration in the same view.
External sharing settings, admin role assignments and whether they are standing or time-bound, and the tenant-level controls a hardening baseline would check — verified continuously instead of once.
Domains, DNS and email authentication, TLS certificates, and exposed services for the customer’s internet-facing infrastructure, so posture is not artificially bounded at the edge of the tenant.
Disabled to troubleshoot a sign-in issue and never re-enabled. The tenant looks fine in the portal until you check policy state.
One account excluded from the MFA policy and included in nothing else, so it now has no second factor at all.
SMTP AUTH turned back on for a single device or app, reopening a path that bypasses Conditional Access entirely.
A TLS certificate approaching expiry on a discovered subdomain, or external sharing loosened for a project and left open.
The point-in-time tenant review that seeds a posture baseline.
Secure Score tracked as one posture input, with regression alerting.
The severity-ranked queue posture regressions land in.
The scheduled re-assessment that detects drift between reviews.
The identity controls behind most posture regressions.
The per-tenant identity checklist a posture program runs on repeat.
See baselines, drift detection, findings, and portfolio ranking in a demo.