@msftsecurity score ( http://securescore.microsoft.com ) is a great start for improving security but did you know your true security score is probably 3x higher than it reports? This is a multi-tweet thread on why that is. 1) Lack of Telemetry causes a 30% point reduction (keep scrolling)
This is because 28 out of the 82 controls lack telemetry- so you get zero points even if you were doing all the right things. With no ability to “self score”, it makes you think you suck even though you might be doing okay in those areas. The next one will really surprise you!
2) the two biggest areas of point value is enabling MFA for admins and end-users, and rightly so, but if you use conditional access to apply MFA, you don’t get full points. You only get points for using the old MFA “always-on” portal, again due to lack of telemetry.
You can follow @ITguySoCal.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.