Sep 11 2019 10:50 PM
Hello there,
With the new secure scoring model using the controls group, I can see that MS has assigned max secure score for each control.
So, is there any specific reasoning for MS to assign those specific max scoring for each control?
For example, the control of Enable MFA is assigned max score of 50, while the control of Enable Auditing and logging is assigned max score of 5.
I thought that auditing and logging is also very important but, it has max score of 5 only. so, I am wondering what is the rationale of assigning different max scores.
Sep 16 2019 03:28 PM
We would like to provide a prioritized score for the controls so customers can focus first on the most important security configurations.
While auditing is important mainly to investigate an attack; enabling MFA is an improtant first to do protection layer to prevent a breach of account or resources ; hence we prioritize it higher.