Security posture

Microsoft 365 security posture management for MSP portfolios

Security posture is the ongoing state of Microsoft 365 configuration, identity controls, and monitored assets across your customer tenants. It is not a checklist you complete once. SecurityScore.me tracks posture on a schedule and surfaces regressions as severity-ranked findings.

Posture is a state, not a checklist

A one-time hardening pass tells you where a tenant stood on the day someone looked. Posture management is about the days in between.

Point-in-time audits go stale immediately

The value of an audit decays from the moment it is finished. An administrator disables a Conditional Access policy to troubleshoot a login, adds an MFA exclusion "for now", or re-enables a legacy protocol for one device, and the clean report you delivered last month no longer describes reality.

A posture program replaces the annual snapshot with a schedule: re-assess, compare against the last run, and raise what changed.

Drift is the failure mode

Most tenants do not get breached because someone designed them badly. They drift — a series of small, individually reasonable changes that add up to a weaker configuration than anyone intended.

Catching drift means storing a baseline and diffing every subsequent assessment against it, so a control that was enforced in January and is report-only in April becomes a finding rather than a surprise.

Severity makes it actionable

Posture data is only useful if a technician can act on it. Every issue carries a severity, remediation guidance, and the customer context, so work is prioritised by risk instead of by whichever tenant was looked at most recently.

Baselines make drift visible across a portfolio

With a baseline per tenant, the organization view can rank customers by how far they have moved from their own known-good state, not just by an absolute score. A small regression in a well-configured tenant can matter more than a low score that has been low and accepted for a year.

What posture covers across a tenant

Posture is broader than any single Microsoft metric. SecurityScore.me assembles it from several read-only Graph signals plus the external assets registered in the workspace.

Identity and Conditional Access

Policy coverage and exclusions, MFA registration versus enforcement, admin-specific protection, session controls, and legacy authentication. Identity gaps are the most common source of posture regressions between reviews.

Secure Score and Microsoft controls

Secure Score is tracked as one input, with its trend and any regression, rather than treated as the whole picture. Improvement actions become findings your team can assign and close.

Defender and endpoint signals

Defender for Endpoint posture and alerts where the customer is licensed, so endpoint state sits alongside identity and configuration in the same view.

Sharing and admin configuration

External sharing settings, admin role assignments and whether they are standing or time-bound, and the tenant-level controls a hardening baseline would check — verified continuously instead of once.

External assets

Domains, DNS and email authentication, TLS certificates, and exposed services for the customer’s internet-facing infrastructure, so posture is not artificially bounded at the edge of the tenant.

Org-wide posture

Running a posture program across a portfolio

Baseline every tenant
Onboard with read-only Graph consent and run a first assessment to capture the known-good state.
Re-assess on a schedule
Scheduled assessments and asset scans diff against the baseline and the previous run.
Rank the portfolio
The organization view orders customers by open critical and high findings and by drift from baseline.
Alert on regression
Notification policies route a control that has regressed to the right technician while the change is recent.
Report the trend
Customer reports show posture state and what moved since the last review, not just a point score.
Needs attention

Common posture regressions MSPs see

A Conditional Access policy switched off

Disabled to troubleshoot a sign-in issue and never re-enabled. The tenant looks fine in the portal until you check policy state.

An MFA exclusion added "temporarily"

One account excluded from the MFA policy and included in nothing else, so it now has no second factor at all.

Legacy authentication re-enabled

SMTP AUTH turned back on for a single device or app, reopening a path that bypasses Conditional Access entirely.

A certificate or sharing setting drifting

A TLS certificate approaching expiry on a discovered subdomain, or external sharing loosened for a project and left open.

Related pages

Frequently asked questions

Next steps

Manage Microsoft 365 posture across your portfolio

See baselines, drift detection, findings, and portfolio ranking in a demo.