Forum Discussion
SecureScore bugs
There needs to be a way to submit feedback for SecureScore. There's so many outdated links within the 'implementation' tab, and so many quirks. For example, the 'enable safe attachments' policy will fail if you use a custom Quarantine policy, even if it IS admin-only. Feels kinda sketchy to be setting these to 'Resolved through Alternate Mitigation' when you actually haven't.
Another example - the Outbound Spam filter specifies no limits for emails. However the documentation DOES. This should be part of the SecureScore recommendation, no?
Not sure if this is the right hub - but this is where the doc links for feedback.
1 Reply
- Ankit365Iron Contributor
You are absolutely right. As of October 2025, there is still no consistent and straightforward way to submit feedback directly from the Microsoft 365 Secure Score portal, despite the fact that many of the recommendations and links clearly need to be updated. Your examples are accurate. The Safe Attachments recommendation often fails when using a custom quarantine policy, even if it is restricted to admins only. The Outbound Spam filter guidance still shows incomplete criteria compared to the real documentation.
The main issue is that Secure Score checks for particular configurations rather than functional equivalents. If you apply a custom setting that meets the same security intent, the system does not recognize it and flags it as noncompliant. That is why many admins have to mark items as resolved through alternate mitigation even when they are correctly configured. It is not misleading on your part. It is simply how the scoring logic works.
The best way to share this feedback is from inside the Defender portal. On the Secure Score page, open the settings menu and select Give feedback. That message goes to the product group. You can also submit detailed notes through the Microsoft Feedback Hub under Security and Compliance, or leave a comment at the bottom of the related Microsoft Learn pages. The documentation team monitors those comments, which often lead to internal updates. Your examples provide solid feedback that the Secure Score team takes seriously once they receive enough reports. Please hit like if you like the solution.