Azure

Monitor Azure Secure Score

DoubleCheck reads the Microsoft Defender for Cloud secure score of all your Azure subscriptions every day, shows it as one percentage, and alerts you when it falls below the level you set.

The problem

The secure score in Defender for Cloud goes down quietly. A new subscription without the recommended settings, a storage account opened up for a quick test, a virtual machine that misses its updates: each one costs points, and nothing tells you unless someone opens the portal.

With several subscriptions, or several customer tenants, nobody opens all of those portals every week.

Why it matters

The secure score is Microsoft's own measure of how many of its security recommendations you follow. A drop is an early sign that a setting changed or a new resource was deployed without the usual baseline.

For an MSP it is also something to show: a score that is watched and kept above an agreed level is easier to discuss with a customer than a screenshot taken once a quarter.

How to check it manually

In the Azure portal, open Microsoft Defender for Cloud and go to Security posture. The secure score is shown per subscription and for your whole environment.

To read the same numbers yourself across subscriptions, run this query in Azure Resource Graph Explorer:

securityresources
| where type == "microsoft.security/securescores"
| where name == "ascScore"
| extend current = todouble(properties.score.current),
         max = todouble(properties.score.max)
| project subscriptionId, current, max

Repeat that for every tenant you manage, and write the result down somewhere to see the trend.

How DoubleCheck checks it

DoubleCheck runs the same Resource Graph query once a day, for every subscription your app registration can read. It adds up the current and maximum scores of all subscriptions and turns that into one percentage, so a large subscription weighs more than an empty one.

The per-subscription scores are kept with each result, so you can see which subscription pulled the total down.

Measures
The Microsoft Defender for Cloud secure score of every subscription the app registration can read, taken from Azure Resource Graph and combined into one percentage (total current score divided by total maximum score).
Runs
Once a day by default
Status
  • Higher is better.
  • Warning when the secure score is below 70% (default advice).
  • Error when the secure score is below 60% (default advice).
  • You can change the levels per check.
What you need
  • An app registration in your tenant with a client secret.
  • The Azure role Reader on each subscription that should count. No Microsoft Graph permission and no admin consent needed.
FAQ

Frequently asked questions

Does DoubleCheck need write access to my Azure subscriptions?

No. The app registration only needs the built-in Reader role on the subscriptions you want to include. It cannot change anything.

Do I need Microsoft Graph permissions or admin consent for this check?

No. Unlike the Microsoft 365 checks, this check works through an Azure role on the subscriptions, not through a Graph permission.

How is the score of several subscriptions combined?

DoubleCheck adds up the current score and the maximum score of all subscriptions and divides the two. It is a weighted total, not an average of percentages.

Is this the same as the Microsoft Secure Score?

No. The Azure secure score comes from Defender for Cloud and covers your Azure resources. The Microsoft Secure Score covers Microsoft 365 and Entra ID, and has its own check.

How are my credentials stored?

The tenant ID, application ID and client secret are kept in a dedicated, encrypted secrets vault, separate from the DoubleCheck database. Access to it is restricted to DoubleCheck's own services under strict access policies.

Get started

Start monitoring with DoubleCheck

Alerts by email, SMS, Slack, Microsoft Teams or Discord. You pay per check run: cost management in the app shows what every check costs, and a longer interval lowers it.

Start monitoring