Medium - Microsoft Secure Score, Microsoft Entra (AAD), Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Exchange Online, Microsoft SharePoint, Microsoft Forms, Microsoft Sway, Atlassian, Zendesk, Meta Workplace, Dropbox, Microsoft 365 Lighthouse - Microsoft primary source
Updates and Enhancements in Microsoft Secure Score (Aug 2023 - Feb 2024)
Microsoft Secure Score has been continuously updated with new security improvement actions across multiple Microsoft products including Microsoft Entra (AAD), Defender for Identity, Exchange Online, SharePoint, and third-party integrations like Atlassian and Zendesk. Key enhancements include new recommendations for phishing-resistant MFA, custom banned passwords, certificate services improvements, and granular role-based access control (RBAC) permissions integration for Secure Score.
What changed
Between August 2023 and February 2024, Microsoft introduced new Secure Score improvement actions covering a broad set of Microsoft and third-party security controls. Notable changes include the addition of phishing-resistant MFA enforcement for administrators, custom banned password lists, limitations on administrative roles for certain APIs, expanded SharePoint and Microsoft Forms sharing restrictions, recommendations related to Active Directory Certificate Services, Defender for Cloud Apps multi-instance support, and integration of Secure Score with Microsoft 365 Lighthouse for MSPs. Additionally, Secure Score access is now managed via Microsoft Defender unified RBAC allowing finer permission granularity.
Why it matters operationally
Organizations using Microsoft Secure Score will need to review and implement new improvement actions to maximize security posture. Security teams and administrators may require updates to policies such as MFA configurations, password policies, certificate templates, and external sharing restrictions. MSPs managing multiple tenants can leverage Secure Score integration with Microsoft 365 Lighthouse for consolidated visibility. The new RBAC support enables more controlled access to Secure Score data, improving governance.
What the SOC should check
Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.
Recommended actions
- Review all newly added Secure Score improvement actions since August 2023 and assess applicability within your environment.
- Implement phishing-resistant MFA for administrators and enforce custom banned password lists in Microsoft Entra ID.
- Monitor and configure Active Directory Certificate Services recommendations to prevent certificate misuse.
- Leverage Defender for Cloud Apps new capabilities for managing multiple SaaS app instances individually.
- If you are an MSP, utilize the Microsoft Secure Score integration within Microsoft 365 Lighthouse to monitor and improve customer tenants' security postures.
- Adopt Microsoft Defender unified RBAC permissions model to assign granular Secure Score access to appropriate security personnel.
- Enable and configure external sharing restrictions and anti-phishing policies in SharePoint, Teams, and Forms.
- Ensure all relevant security settings in Exchange Online, Atlassian, Zendesk, Meta Workplace, and Dropbox are aligned with new improvement actions.
Source links
https://learn.microsoft.com/en-us/defender-xdr/microsoft-secure-score-whats-new