Identity Secure Score Regression without making any changes

LM-5132 100 Reputation points
2024-10-18T12:46:11.64+00:00

Hello,

Our Identity Secure Score in Entra ID has dropped from 79.98% to 50.36% without any changes made on our part. Using Microsoft Defender, we can view the Microsoft Secure Score, which is different from the Entra Identity Secure Score. However, we can filter to see the Identity Secure Score in Defender and examine the regressed actions.

The actions that caused our score to decline indicate that we are missing four policies. However, we have these policies in place.

I suspect the issue may stem from our creation of conditional access policies in Entra ID without utilizing the Microsoft templates for these policies.

Below is a screenshot listing the four policies that regressed in the past 90 days, which we have enabled.

We observed a regression of 16.82 points in October, despite not making any changes.

Additionally, I have included another screenshot with further details on the regressions, and a screenshot showing the policies we have in place.

One thing to note is that we have not completed the MFA migration process from the Microsoft 365 Admin Center to Entra ID. We are in the migration process, however, MFA is enabled for all users.

Below is a screenshot of the four policies that regressed in the past 90 days, however we have them enabled

User's image

Below is a screenshot showing that we regressed 16.82 points in October, however we made no changes.

User's image

Below is a screenshot with more details on the regressions.

User's image

Below is a screenshot of the enabled policies we have configured in Entra ID.

User's image

Thank you very much for your help.

We appreciate all the feedback we have received in the past and it has helped increase the security posture of our organization.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,063 questions
{count} votes

Accepted answer
  1. Raja Pothuraju 7,365 Reputation points Microsoft Vendor
    2024-10-28T19:09:36.58+00:00

    Hello @LM-5132,

    Thank you for posting your query on Microsoft Q&A.

    Based on your description, I see that Secure Score for certain recommendations have been regressed in your tenant. This issue occurred with many other customers since 4th October, affecting all users in the tenant. Affected recommendations with score regression is mentioned below:

    • Use least privileged administrative roles
    • Designate more than one global admin
    • Ensure multifactor authentication is enabled for all users in administrative roles
    • Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
    • Ensure user consent to apps accessing company data on their behalf is not allowed

    The root cause has been identified and a hotfix is being rolled out. Correct data has been released. Please check and confirm me if you are able to see the correct data on your end.

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,
    Raja Pothuraju.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.