Monitor Microsoft Secure Score
DoubleCheck reads the Microsoft Secure Score of your Microsoft 365 tenant every day and alerts you when the percentage falls below your warning or error level.
The problem
The Microsoft Secure Score changes without anyone touching it. Microsoft adds new recommendations, which raises the maximum score and lowers your percentage. A changed policy or a new admin account can cost points too.
The score is only visible in the Microsoft Defender portal, one tenant at a time. If you manage several tenants, a drop can go unnoticed for weeks.
Why it matters
The secure score is Microsoft's measure of how well your identity, device, app and data settings follow its recommendations. A falling score usually means a gap opened up, such as an account without MFA or a weaker policy.
An agreed minimum score is an easy way to make security measurable in a service agreement, as long as someone actually watches it.
How to check it manually
Sign in to the Microsoft Defender portal (security.microsoft.com) and open Secure score. The overview shows the current score, the maximum and the history.
With Microsoft Graph PowerShell you can read the same numbers:
Connect-MgGraph -Scopes SecurityEvents.Read.All
Get-MgSecuritySecureScore -Top 1 |
Select-Object CreatedDateTime, CurrentScore, MaxScore
Divide the current score by the maximum score to get the percentage, and repeat that for every tenant.
How DoubleCheck checks it
Once a day DoubleCheck asks Microsoft Graph for the secure score history of your tenant, takes the newest entry and turns it into a percentage. The history comes along with each result, so you can see when the score changed.
Because DoubleCheck uses the percentage, a drop caused by Microsoft adding recommendations shows up too, not only a drop in your own points.
- Measures
- The latest Microsoft Secure Score of your Microsoft 365 tenant from Microsoft Graph (
/security/secureScores), as current score divided by maximum score. - Runs
- Once a day by default
- Status
-
- Higher is better.
- Warning when the secure score is below 70% (default advice).
- Error when the secure score is below 60% (default advice).
- You can change the levels per check.
- What you need
-
- An app registration in your tenant with a client secret.
- Microsoft Graph application permission
SecurityEvents.Read.All, with admin consent. Read only.
Frequently asked questions
Which permission does DoubleCheck need?
The Microsoft Graph application permission SecurityEvents.Read.All, approved by a Global Administrator or Privileged Role Administrator. It only reads the score and cannot change anything in the tenant.
Why did my score drop when nothing changed?
Microsoft regularly adds recommendations, which raises the maximum score. Your points stay the same, but the percentage goes down.
How often does the score change?
Microsoft calculates the score about once a day, so DoubleCheck checks it once a day as well.
Can I use one app registration for all Microsoft 365 checks?
Yes. Add the permissions of the other checks, such as Reports.Read.All for mailbox usage, to the same app registration and use the same secret.
Is this the same as the Azure secure score?
No. The Azure secure score comes from Defender for Cloud and covers Azure resources. It has its own check.
How are my credentials stored?
The tenant ID, application ID and client secret are kept in a dedicated, encrypted secrets vault, separate from the DoubleCheck database. Access to it is restricted to DoubleCheck's own services under strict access policies.
Start monitoring with DoubleCheck
Alerts by email, SMS, Slack, Microsoft Teams or Discord. You pay per check run: cost management in the app shows what every check costs, and a longer interval lowers it.