Forum Discussion
Announcement: Office 365 Secure Score Released to Public Preview
- Dec 15, 2016
Another issue with Secure Score.
"You should require that all of your users reset their password at least every 60 days"
This is no longer current best practice where strong passphrases and 2FA are used since more rapid enforced change of passwords leads to the use of weaker ones.
Hey Chris,
Sorry for the trouble. The most likely cause is that the acocunt you are using has not been assigned the global administrator role. The Secure Score requires that privilege level at the moment.
Thanks!
Brandon Koeller
- BrandonKoellerApr 12, 2017
Microsoft
Hey John,
Thanks for the feedback. So, the way the access model is implemented users of the tool are only able to perform actions that align with their assigned role. So, if a control requires global admin permissions and the user is assigned an Exchange Online Admin role, they won't be able to make the change. This leaves some roles such as Security Administrator as functionally read-only roles. Most of the read-only state and configuration data is already accessible to all those roles anyway (although it would take more work to get the state data). We tried to strike a balance between exposure of the recommendations to the right set of company stakeholders while respecting the constraints of their assigned roles.
Thanks!
Brandon Koeller
- Aaron HawrylukOct 19, 2017Copper Contributor
Hi Brandon,
I've granted all my InfoSec guys access in the Security and Compliance center as Security Administrators and Compliance Admins, but that doesn't seem to allow them to access SecureScore.
I then gave them Custom Administrator/Reports Reader, but they still got 403 when accessing the page. Will try going up to Service Admins and see if that allows them in. I also noticed that Compliance Admin is not listed in the available admin roles for Office 365 users. Am I missing a preview feature or something?- Greg HayMar 15, 2018Copper Contributor
Secure score is great. We have slowly been tracking up as we fix the items that have been shown.
I seem to get incorrect scores for all the mobile options. I assume this is due to us using intune. Any idea when the secure secure will reflect the intune mobile settings and security?
- Greg HaySep 14, 2017Brass Contributor
I have the same issue with Intune scores not reflecting. We have been moved to intune on azure with Office 365 and dont get any scores showing up.