What Is Microsoft Secure Score? A Guide for UK Charities
-
24/08/2026
- 7 minutes Read
Microsoft Secure Score is a measurement within Microsoft 365 that helps organisations understand their current security posture and identify actions that could improve it.
Think of it as a security health check for your Microsoft 365 environment.
Microsoft assesses which recommended security controls have been implemented, awards points for completed actions and highlights further improvements your organisation could make.
For UK charities, Secure Score can be particularly useful because it provides a practical way to identify security gaps in Microsoft 365 without immediately investing in additional security products.
How Does Microsoft Secure Score Work?
Microsoft Secure Score reviews security settings across your Microsoft environment and compares them against Microsoft’s recommended security actions.
Points can be awarded for implementing controls such as:
- Multi-Factor Authentication (MFA)
- Conditional Access policies
- Identity protection
- Microsoft Defender security settings
- Email protection
- Device and endpoint security
- Data protection controls
Your Secure Score is then shown as a percentage of the points currently achieved against the points available to your organisation.
The important thing to understand is that Secure Score isn’t simply a pass or fail test.
Instead, it provides a prioritised list of actions that can help you progressively strengthen your Microsoft 365 security.
What Is a Good Microsoft Secure Score?

There isn’t one Secure Score percentage that every charity should aim for.
The available points depend on your Microsoft licences, services and configuration, and some recommendations may not be appropriate for the way your organisation operates.
For that reason, charities shouldn’t treat 100% as the objective.
A better approach is to use Secure Score as a continuous improvement tool.
For example, if your charity currently has a Secure Score of 45%, the immediate question shouldn’t necessarily be:
“How do we get to 100%?”
It should be:
“Which available improvements would reduce our greatest risks?”
That distinction matters.
What Does Microsoft Secure Score Measure?
Secure Score brings recommendations from several areas of Microsoft security into one place.
These can include:
- Identity
Recommendations designed to protect Microsoft 365 accounts and administrator access. Examples can include MFA, authentication methods and privileged account protection. - Devices
Actions relating to the security and management of computers, laptops and mobile devices accessing organisational data. - Applications
Recommendations that help control how users and applications access Microsoft 365 services and organisational information. - Data
Controls designed to reduce the risk of sensitive information being accidentally or deliberately exposed.
Secure Score therefore provides a useful high-level view across several of the controls that form part of Bunker’s Microsoft 365 Security Framework for UK Charities.
Why Does Secure Score Matter for UK Charities?
Charities can hold significant amounts of sensitive information, including donor details, financial records, employee information, beneficiary data and confidential communications.
At the same time, many charities have limited internal IT and cyber security resources.
Secure Score helps make Microsoft 365 security more manageable by identifying specific improvements rather than simply telling an organisation that it needs to “improve cyber security”.
For example, a charity might discover that:
- MFA isn’t consistently enforced
- administrator accounts require additional protection
- security policies haven’t been fully configured
- devices aren’t meeting expected security standards
- email security settings could be strengthened
That gives the organisation a practical list of areas to investigate.
A Simple Secure Score Example

Imagine a charity with 75 employees using Microsoft 365.
Its Secure Score identifies several outstanding recommendations.
Rather than attempting to implement every recommendation immediately, the charity could prioritise improvements using a simple framework:
- Identify the highest-risk gaps
Start with controls protecting identities, administrator accounts and access to Microsoft 365. - Assess the operational impact
Understand how each change could affect staff, volunteers and existing working practices. - Implement the priority controls
Introduce changes in a controlled way, testing them before organisation-wide deployment where appropriate. - Review the result
Monitor Secure Score to see how the changes affect the organisation’s security posture. - Repeat
Review new recommendations and continue improving over time.This makes Secure Score much more useful than simply chasing a percentage.
Should Charities Try to Achieve a 100% Secure Score?
Generally, no.
A 100% Secure Score shouldn’t automatically be treated as evidence that an organisation is completely secure.
Some recommendations may not be relevant to your environment, while implementing others could introduce unnecessary complexity or affect how staff and volunteers work.
Secure Score also represents only part of an organisation’s wider cyber security posture.
For example, charities still need to consider areas such as independent backups, staff awareness, incident response, governance and other security controls.
The objective should therefore be to achieve an appropriate level of security for your organisation’s risks, rather than pursuing a perfect number.
How Often Should a Charity Review Microsoft Secure Score?
We recommend treating Secure Score as an ongoing security management tool rather than a one-off exercise.
A practical approach is to review it at least monthly, as well as following significant changes to your Microsoft 365 environment.
This allows your organisation to identify new recommendations, track improvements and prevent security configuration from gradually falling behind.
Bunker’s Recommended Approach
We recommend that charities use Microsoft Secure Score as part of a wider Microsoft 365 security review.
Start by establishing your current score and reviewing the recommended improvement actions.
Then prioritise them according to:
- Security risk
- Potential impact
- Implementation complexity
- Licensing requirements
- How your charity actually works
Secure Score shouldn’t dictate your security strategy.
It should inform it.
Combined with controls such as MFA, Conditional Access, Microsoft Defender and Identity Protection, it provides a useful way to measure progress and identify where attention should be focused next.
Review Your Microsoft 365 Security
Microsoft Secure Score can tell you where improvements may be possible. The harder part is deciding which recommendations matter most and how they should be implemented safely.
Bunker’s Microsoft 365 Security Framework for UK Charities covers 10 essential security controls we recommend charities review to reduce cyber risk, strengthen governance and make better use of the Microsoft 365 security capabilities available to them.
What is Microsoft Secure Score?
Microsoft Secure Score is a measurement of your organisation’s security posture across Microsoft services. It awards points for implementing recommended security controls and highlights actions that could further improve your security.
What is a good Microsoft Secure Score for a charity?
There isn’t a single percentage every charity should achieve. Your available score depends on your Microsoft licensing, services and configuration. Rather than chasing 100%, charities should prioritise the recommendations that reduce their most significant security risks.
Should we aim for a 100% Microsoft Secure Score?
Not necessarily. Some recommendations may not be appropriate for your organisation, licensing or working practices. Secure Score should be used as a continuous improvement tool rather than treated as a pass-or-fail security test.
How often should we review Microsoft Secure Score?
We recommend reviewing Secure Score at least monthly and after significant changes to your Microsoft 365 environment. This helps identify new recommendations and track whether your security posture is improving over time.
Does a high Microsoft Secure Score mean our charity is secure?
No. A high Secure Score is a positive indicator, but it doesn’t cover every aspect of cyber security. Charities should also consider areas such as independent backup, staff awareness, incident response, governance and ongoing security monitoring.
How can Bunker help improve our Microsoft Secure Score?
Bunker can review your Microsoft 365 environment, identify priority Secure Score recommendations and help implement appropriate improvements.
We focus on reducing genuine security risk rather than simply increasing the percentage displayed on the dashboard.
What Is Microsoft Secure Score? A Guide for UK Charities
Charity Commission Risk Assessment 2026: What Trustees Need to Know About Cyber Security and Ai
Why Remote Staff and Volunteers Increase Cyber Risk for Charities – And What You Can Do About It
Cyber Essentials Isn’t Enough: Why Charities Need a Microsoft 365 Security Strategy
Microsoft Copilot vs ChatGPT: Which Is Better for Charities? Make Ai work for your mission

