Secure Score Summary value wrong direction?

%3CLINGO-SUB%20id%3D%22lingo-sub-286394%22%20slang%3D%22en-US%22%3ESecure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286394%22%20slang%3D%22en-US%22%3E%3CP%3EWe've%20come%20in%20today%20(UK)%20to%20find%20our%20Secure%20Score%20value%20has%20decreased%20from%20108%20to%2042%20even%20though%20we%20have%20made%20steps%20forward%20since%20the%20108%20was%20registered.%20Secure%20Score%20isn't%20validating%20things%20like%20MFA%20enablement%20for%20admins%2C%20nor%20recognising%20that%20we%20do%20in%20fact%20have%20global%20admins.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20just%20for%20our%20tenancy%20or%20is%20this%20a%20global%20issue%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-287207%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287207%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20back%20to%20where%20we%20were%20before%20we%20made%20all%20the%20changes%20so%20at%20least%20that%20is%20a%20step%20forward.%20Still%20not%20registering%26nbsp%3Bour%20recent%20changes%20so%20maybe%20we%20will%20get%20them%20on%20the%20next%20update%26nbsp%3B%40%209am%20PST.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-287126%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287126%22%20slang%3D%22en-US%22%3E%3CP%3EMy%20score%20went%20up%20overnight.%26nbsp%3B%20Still%2040%20points%20lower%20than%20earlier%20in%20the%20week.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-287095%22%20slang%3D%22en-US%22%3ERE%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287095%22%20slang%3D%22en-US%22%3ENow%20it%20shows%20the%20correct%20values%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-287037%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-287037%22%20slang%3D%22en-US%22%3E%3CP%3EThere%20seems%20to%20be%20some%20issue%20with%20the%20api.%20We%20have%20that%20problem%20too.%20Using%20the%20graph%20api%2C%20you%20can%20see%20with%20%2Fsecurity%2FsecureScores%20that%20since%2013-nov-2018%20it's%20not%20returning%20data%20from%20many%20controls.%20Checking%20against%20%2Fsecurity%2FsecureScoreControlProfiles%2C%20those%20controls%20are%20NOT%20deprecated%20so%26nbsp%3Bit%20suggest%20something%20on%20MS%20dailyprocesing%20is%20broken.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe've%20alse%20created%20a%20post%20in%20the%20graph%20api%20community%20(secure%20score%20api%20now%20technically%20belongs%20there)%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FUsing-Microsoft-Graph-Security%2FSecure-Score-Identity%2Fm-p%2F286434%23M72%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FUsing-Microsoft-Graph-Security%2FSecure-Score-Identity%2Fm-p%2F286434%23M72%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286920%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286920%22%20slang%3D%22en-US%22%3EThat's%20a%20negative%20Norm.%20Nada%20from%20the%20big%20M%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286919%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286919%22%20slang%3D%22en-US%22%3E%3CP%3EChecking%20back%20to%20see%20if%20anyone%20got%20a%20response%20from%20Microsoft%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286741%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286741%22%20slang%3D%22en-US%22%3E%3CP%3EMy%20Score%20dropped%20on%20Nov%202nd%20when%20Microsoft%20added%20the%20Compliance%20Control%20Information%20to%20MS%20Secure%20Score.%26nbsp%3B%20Some%20of%20the%20items%20that%20I%20had%20implemented%20and%20are%20still%20active%20now%20have%20a%20score%20of%200.%20%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286646%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286646%22%20slang%3D%22en-US%22%3E%3CP%3EI%20agree%2C%20we%20were%20quite%20excited%20to%20find%20the%20feature%20and%20thought%20it%20would%20be%20of%20great%20use%20to%20help%20us%20ensure%20we%20were%20filling%20the%20holes.%20Now%20it%20has%20started%20failing%20to%20detect%20our%20changes%20it%20has%20taken%20the%20shine%20off%20somewhat.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286645%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286645%22%20slang%3D%22en-US%22%3E%3CP%3EThat%20echoes%20my%20worry%2C%20we%20tout%20the%20scores%20as%20being%20a%20sign%20of%20how%20we%20are%20looking%20to%20be%26nbsp%3Bsecurity%20conscious%20but%20then%20a%20telemetry%20goes%20offline%20etc%20and%20we%20look%20like%20we%20have%20broken%20stuff!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286639%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286639%22%20slang%3D%22en-US%22%3E%3CP%3EI%20had%20a%20100%20point%20drop%20in%201%20day.%26nbsp%3B%20Based%20on%20the%20discussion%2C%20it%20seems%20there%20should%20be%20some%20form%20of%20alerting%20or%20notices%20with%20with%20telemetry%20changes%20or%20risks.%26nbsp%3B%20I%20share%20the%20score%20with%20our%20C-Level%20executives.%26nbsp%3B%20But%20I%20may%20have%20to%20change%20due%20to%20the%20un-controlled%20variability.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20a%20Microsoft%20professional%20weight%20in%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286581%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286581%22%20slang%3D%22en-US%22%3E%3CP%3EI%20was%20once%20at%20435%20before%20plateauing%20at%20399.%26nbsp%3B%20Just%20in%20the%20last%202%20weeks%2C%20I%20have%20seen%20it%20drop%20down%20to%20314%20(today).%26nbsp%3B%20I%20wish%20that%20if%20the%20telemetry%20cannot%20be%20confirmed%2C%20then%20the%20points%20should%20not%20be%20deducted.%26nbsp%3B%20Obviously%2C%20there%20is%20some%20sort%20of%20error%20occurring%20that%20I%20would%20get%20dinged%20for%20not%20having%20more%20than%20one%20global%20administrator%20(we%20have%209...%20complicated%20reasons%20and%20also%20due%20to%20some%20apps%20needing%20global%20administrator%20in%20order%20to%20administer%20them)%2C%20use%20non-global%20administrative%20roles%20(we%20have%20a%20whole%20bunch)%2C%20enable%20data%20loss%20prevention%20policies%20(even%20the%26nbsp%3Bdescription%20says%20we%20have%209%20enabled)%2C%20user%20alternate%20contact%20info%20says%20we%20have%200%20people%20who%20have%20not%20completed%20it%2C%20store%20documents%20in%20OneDrive%20for%20Business%20says%20we%20have%20it%20set%20to%20True%20(but%20someone%20stated%20that%20there%20was%20another%20reason%20why%20this%20was%20taken%20away%2C%20even%20though%20I%20personally%20store%20documents%20in%20there)%2C%20etc.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESecure%20Score%20is%20a%20great%20concept%20and%20I%20use%20it%20to%20remind%20me%20of%20the%20administrative%20tasks%20that%20I%20should%20take.%26nbsp%3B%20It%20is%20kind%20of%20fun%20to%20try%20and%20get%20the%20score%20to%20inch%20up.%26nbsp%3B%20But%2C%20if%20the%20checks%20are%20not%20reliably%20being%20made%2C%20then%20the%20secure%20score%20does%20not%20have%20much%20meaning.%26nbsp%3B%20Hopefully%2C%20they%20will%20be%20able%20to%20fix%20the%20issues%20soon.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286420%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20Summary%20value%20wrong%20direction%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286420%22%20slang%3D%22en-US%22%3E%3CP%3Ethere%20must%20be%20some%20telemetry%20reporting%20issue%20as%20the%20scores%20are%20going%20down%20in%20the%20last%203%20days.%20We%20went%20from%20470%20to%20230%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

We've come in today (UK) to find our Secure Score value has decreased from 108 to 42 even though we have made steps forward since the 108 was registered. Secure Score isn't validating things like MFA enablement for admins, nor recognising that we do in fact have global admins.

 

Is this just for our tenancy or is this a global issue?

 

 

12 Replies

there must be some telemetry reporting issue as the scores are going down in the last 3 days. We went from 470 to 230

I was once at 435 before plateauing at 399.  Just in the last 2 weeks, I have seen it drop down to 314 (today).  I wish that if the telemetry cannot be confirmed, then the points should not be deducted.  Obviously, there is some sort of error occurring that I would get dinged for not having more than one global administrator (we have 9... complicated reasons and also due to some apps needing global administrator in order to administer them), use non-global administrative roles (we have a whole bunch), enable data loss prevention policies (even the description says we have 9 enabled), user alternate contact info says we have 0 people who have not completed it, store documents in OneDrive for Business says we have it set to True (but someone stated that there was another reason why this was taken away, even though I personally store documents in there), etc.  

 

Secure Score is a great concept and I use it to remind me of the administrative tasks that I should take.  It is kind of fun to try and get the score to inch up.  But, if the checks are not reliably being made, then the secure score does not have much meaning.  Hopefully, they will be able to fix the issues soon.

I had a 100 point drop in 1 day.  Based on the discussion, it seems there should be some form of alerting or notices with with telemetry changes or risks.  I share the score with our C-Level executives.  But I may have to change due to the un-controlled variability.  

 

Can a Microsoft professional weight in?

That echoes my worry, we tout the scores as being a sign of how we are looking to be security conscious but then a telemetry goes offline etc and we look like we have broken stuff!

I agree, we were quite excited to find the feature and thought it would be of great use to help us ensure we were filling the holes. Now it has started failing to detect our changes it has taken the shine off somewhat.

My Score dropped on Nov 2nd when Microsoft added the Compliance Control Information to MS Secure Score.  Some of the items that I had implemented and are still active now have a score of 0.  

Checking back to see if anyone got a response from Microsoft?

That's a negative Norm. Nada from the big M

There seems to be some issue with the api. We have that problem too. Using the graph api, you can see with /security/secureScores that since 13-nov-2018 it's not returning data from many controls. Checking against /security/secureScoreControlProfiles, those controls are NOT deprecated so it suggest something on MS dailyprocesing is broken.

 

We've alse created a post in the graph api community (secure score api now technically belongs there) https://techcommunity.microsoft.com/t5/Using-Microsoft-Graph-Security/Secure-Score-Identity/m-p/2864...

Now it shows the correct values

My score went up overnight.  Still 40 points lower than earlier in the week.  

We are back to where we were before we made all the changes so at least that is a step forward. Still not registering our recent changes so maybe we will get them on the next update @ 9am PST. :)