{"id":15644,"date":"2025-12-15T13:07:51","date_gmt":"2025-12-15T00:07:51","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=15644"},"modified":"2025-12-15T13:07:51","modified_gmt":"2025-12-15T00:07:51","slug":"understanding-your-microsoft-secure-score-why-your-percentage-may-drop-while-your-security-improves","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=15644","title":{"rendered":"Understanding Your Microsoft Secure Score: Why Your Percentage May Drop (While Your Security Improves)"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Important Update for KARE Foundation Subscribers<\/strong><\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">If you&#8217;ve noticed your Microsoft Secure Score percentage decreasing recently, don&#8217;t be alarmed. Your security hasn&#8217;t weakened.\u00a0 In fact, Microsoft is making significant enhancements that will ultimately make your organisation more secure. Here&#8217;s what you need to know.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">What&#8217;s Happening with Microsoft Secure Score?<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Throughout 2025, Microsoft has been rolling out a substantial wave of new security recommendations across their security platform. These additions are dramatically increasing the total possible Secure Score points available, which has a direct mathematical impact on your score percentage, even when your actual security controls remain unchanged or improved.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">The Numbers Behind the Change<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Think of it this way: if you previously scored 800 out of 1,000 possible points (80%), and Microsoft adds 500 new recommended security controls, your total possible score jumps to 1,500 points. Your 800 points of implemented security now represents approximately 53%\u2014despite no reduction in your actual protection.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">This is exactly what&#8217;s happening across Microsoft 365 environments globally.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Recent Microsoft Secure Score Enhancements<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Microsoft has introduced dozens of new security recommendations in recent months, including:<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Microsoft Defender for Endpoint (December 2025)<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">New recommendations to block common attack techniques, including:<\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Disabling NTLM authentication for Windows workstations<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Disabling Remote Registry Service on Windows devices<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Advanced endpoint protection configurations<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Microsoft Defender for Identity (Ongoing Throughout 2025)<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Comprehensive identity security enhancements covering:<\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Active Directory Certificate Services (ADCS) security assessments<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Identification and remediation of privileged service accounts<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Removal of stale Active Directory accounts<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Password management for managed service accounts<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Enhanced monitoring across ADCS, Entra Connect, and ADFS servers<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Detection of accounts with potentially leaked credentials<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Microsoft Information Protection<\/h3>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Data loss prevention policy implementations<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Sensitivity label configurations<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Protection across SharePoint, Exchange, Teams, and end-points<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Additional Security Controls<\/h3>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Phishing-resistant multi-factor authentication for administrators<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Legacy authentication blocking (critical for modern security)<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Enhanced Exchange Online protection<\/li>\n<li class=\"whitespace-normal break-words pl-2\">SharePoint and OneDrive external sharing controls<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Custom banned password lists<\/li>\n<\/ul>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Why This Matters: The Good News<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">While seeing your percentage drop can be concerning, these changes represent a significant positive development for several reasons:<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">1. <strong>More Comprehensive Security Coverage<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Microsoft is identifying security gaps that weren&#8217;t previously measured. These new recommendations address real-world attack vectors that threat actors actively exploit.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">2. <strong>Industry-Leading Security Standards<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The expanded recommendations align with frameworks including NIST CSF, ISO 27001, CIS Controls, and Australia&#8217;s Essential Eight. Organisations implementing these controls demonstrate security maturity.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">3. <strong>Proactive Threat Protection<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Many new recommendations specifically target techniques used in recent high-profile security incidents, including ransomware attacks and identity compromise.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">4. <strong>Better Visibility<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The enhanced Secure Score provides more granular insight into your security posture, helping identify areas for improvement that were previously invisible.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">What Kinetics is Doing: Your Protection is Our Priority<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">As your trusted IT partner, Kinetics is actively managing this transition for all KARE Foundation subscribers:<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Ongoing Evaluation<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Our security team is systematically reviewing each new recommendation as it rolls out, assessing:<\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Relevance to your specific business environment<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Potential impact on daily operations<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Priority level based on threat landscape<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Implementation complexity and timeline<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Strategic Implementation<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">We&#8217;re not simply chasing a percentage\u2014we&#8217;re implementing security controls that provide genuine protection for your organisation. This means:<\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\"><strong>Risk-based prioritisation<\/strong>: Addressing the most critical security gaps first<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Business-aligned deployment<\/strong>: Ensuring security doesn&#8217;t impede productivity<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Testing and validation<\/strong>: Confirming controls work as intended before full rollout<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Documentation and communication<\/strong>: Keeping you informed of changes<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Enhanced Protection for KARE Foundation<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">These new security controls will be evaluated and, where appropriate, added to the KARE Foundation service to provide even stronger protection against evolving cyber threats.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Understanding Your Score: A Balanced Perspective<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Your Microsoft Secure Score is one indicator of security health, but it&#8217;s not the complete picture. Here&#8217;s what matters most:<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">What Your Score Indicates<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">\u2705 <strong>Implementation of Microsoft&#8217;s recommended security controls<\/strong><br \/>\u2705 <strong>Relative security posture compared to similar organisations<\/strong><br \/>\u2705 <strong>Progress tracking over time<\/strong><\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">What Your Score Doesn&#8217;t Indicate<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">\u274c <strong>Absolute protection against all threats<\/strong><br \/>\u274c <strong>Guarantee against security incidents<\/strong><br \/>\u274c <strong>Complete security maturity assessment<\/strong><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">A comprehensive security program includes elements that Secure Score doesn&#8217;t measure: employee security awareness, incident response capabilities, backup and recovery procedures, third-party risk management, and security governance.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Looking Ahead: The Security Landscape in 2025<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The cyber threat environment continues to evolve rapidly. Recent trends include:<\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Sophisticated AI-powered phishing attacks<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Identity-based compromises replacing traditional malware<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Supply chain and third-party security risks<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Ransomware groups targeting small and medium businesses<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Exploitation of configuration weaknesses<\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Microsoft&#8217;s expanded Secure Score recommendations directly address many of these emerging threats, particularly around identity security and endpoint protection.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">What You Should Do<\/h2>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">For All Clients<\/h3>\n<ol class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1.5 [li_&amp;]:gap-1.5 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-2 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\"><strong>Don&#8217;t panic about percentage decreases<\/strong>: Your security hasn&#8217;t weakened; the measurement scale has expanded<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Review your Secure Score trends<\/strong>: Look at the pattern over time rather than absolute numbers<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Trust your security partner<\/strong>: Kinetics is managing these changes systematically<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Maintain security fundamentals<\/strong>: Continue following security best practices, especially around passwords and email awareness<\/li>\n<\/ol>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">For KARE Foundation Subscribers<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">These changes are being rolled out right now.\u00a0 Your Kinetics team is handling the technical evaluation and implementation. We&#8217;ll reach out if we identify high-priority controls that require business decisions or changes to your environment.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Questions or Concerns?<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">If you&#8217;d like to discuss your specific Secure Score or security posture, contact your Kinetics account manager or our security team.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">The Bottom Line<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The recent expansion of Microsoft Secure Score recommendations is ultimately positive for your organisation&#8217;s security. While you may see temporary percentage decreases, Kinetics is working behind the scenes to evaluate and implement these enhanced security controls, ensuring your organisation benefits from Microsoft&#8217;s latest security innovations.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Your security is much more than a simple percentage.<\/strong>\u00a0 It&#8217;s a comprehensive program of people, processes, and technology working together to protect your business. With Kinetics managing your Microsoft 365 security through KARE Foundation, you have a dedicated team focused on that protection every day.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Refer: <a href=\"https:\/\/mc.merill.net\/message\/MC1192254\">MC1192254 &#8211; Microsoft Defender for Endpoint: New Microsoft Secure Score recommendations | Microsoft 365 Message Center Archive<\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Important Update for KARE Foundation Subscribers If you&#8217;ve noticed your Microsoft Secure Score percentage decreasing recently, don&#8217;t be alarmed. Your security hasn&#8217;t weakened.\u00a0 In fact, Microsoft is making significant enhancements that will ultimately make your organisation more secure. Here&#8217;s what you need to know. What&#8217;s Happening with Microsoft Secure Score? Throughout 2025, Microsoft has been [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":15650,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-15644","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/15644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15644"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/15644\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}