What Secure Score doesn't tell you — and why it matters now
Your Microsoft Secure Score displays 72%. Good news? Not so fast. This number doesn't tell you how many accounts have privileged Entra ID roles without enhanced MFA, it translates no risk into budgetary amount, and it produces no readable document for a COMEX or board of directors. For a CISO or CIO summoned before management in 2025, this score alone is no longer sufficient — especially with regulatory deadlines tightening.
Regulatory deadline
The French transposition of the NIS2 directive sets the effective entry into force on October 17, 2026. Personal responsibility of leaders is explicitly engaged in case of non-compliance. DORA already applies to the financial sector as of January 2025.
NIS2, DORA, EU AI Act: the timeline that applies to CIOs
Three European texts converge toward the same requirement: prove, document, and correct.
-
NIS2 (French transposition expected on October 17, 2026) broadens the scope to essential and important entities, imposes cyber risk management measures, and engages the personal responsibility of leaders in case of non-compliance — not just that of the organization.
-
DORA (Digital Operational Resilience Act) is in effect for financial entities since January 2025. It requires operational resilience testing and third-party risk traceability, including those related to cloud identities.
-
EU AI Act gradually introduces governance requirements on AI systems, which includes identities used by automated agents in your tenant.
In all three cases, Entra ID identity management is on the front line: who accesses what, with what protections, and with what proof.
Why Secure Score is insufficient as an audit foundation
Microsoft Secure Score is a useful configuration indicator for prioritizing quick actions. But it has three structural limitations for a regulatory audit approach:
- Absence of exploitable normative mapping: the score doesn't link its recommendations to NIS2 articles, CIS M365 controls, or DORA requirements. The administrator must make the correspondence manually.
- No decision-maker deliverable: the Microsoft 365 Defender portal produces lists of technical recommendations, not a 40-page Word report ready for an executive committee with estimated financial exposure.
- Partial identity coverage: service accounts, applications with delegated consent, and — increasingly critical — AI agent identities (Entra Agent ID) don't appear in the standard score.
Open source tools like Maester or ScubaGear partially fill these gaps, but their output is raw PowerShell or JSON — unreadable for a DPO or board member without significant reprocessing.
The 8 dimensions of true identity posture
A complete evaluation of identity posture on a Microsoft 365 / Entra ID tenant covers at minimum these eight axes:
-
MFA: coverage, methods (TOTP vs. FIDO2 key vs. SMS), exclusions and backup accounts
-
Account hygiene: inactive accounts, orphaned guest accounts, passwords never expired on hybrid accounts
-
Privilege management: permanent vs. eligible Entra ID roles (PIM), over-privilege, global administrators without justification
-
Applications and consents: third-party applications with overly broad Graph permissions, unsupervised delegated consents
-
Directory structure: dynamic groups, administrative units, role delegation
-
Licenses: alignment between available security features (P1/P2) and their actual activation
-
CIS / EIDSCA alignment: compliance with CIS Microsoft 365 v7 benchmarks and EIDSCA (Entra ID Security Config Analyzer)
-
Passwordless: progress toward passwordless authentication, coverage of priority users
Info
Good to know
The EIDSCA (Entra ID Security Config Analyzer) is an open source benchmark maintained by the Microsoft MVP community. It evaluates Entra ID security configuration independently of Secure Score.
Linking your gaps to frameworks: the exercise nobody does
Identifying a weakness is one thing. Linking it to a specific regulatory article is another — yet that's what a NIS2 auditor or a client subject to DORA can ask.
Crosswalks (correspondences) between technical controls and normative frameworks allow you to answer the question: "This absence of MFA on administration accounts, to which NIS2 article or CIS control does it correspond?"
Attention
These mappings are indicative correspondences (crosswalks), not certified article-by-article audits. They guide remediation and facilitate discussion with auditors, but don't replace a formal compliance audit conducted by an accredited organization.
Common frameworks cross-referenced in this context:
-
CIS Microsoft 365 Foundations Benchmark v7
-
EIDSCA
-
SCuBA (CISA)
-
NIST CSF 2.0
-
NIS2 / DORA
-
ISO 27001:2022
-
SOC 2 Type II
-
Zero Trust Architecture (NIST SP 800-207)
-
MITRE ATT&CK (identity attack techniques)
-
Passwordless readiness
From score to plan: what a board-grade deliverable must contain
Once gaps are identified across the 8 dimensions and linked to frameworks, the issue becomes operational: producing a document that management can read, understand, and sign.
A useful report for an executive committee includes:
-
A global score and 8 sub-scores readable without technical training
-
An estimate of financial exposure related to identified risks (indicative, based on incident cost models)
-
A prioritized remediation plan with estimated effort and score impact
-
PowerShell or Python remediation scripts directly usable by the technical team
-
Drift tracking: if a secured configuration regresses after correction, the alert surfaces
Info
Tip
Estimated financial exposure is an argument that resonates better with financial management and boards of directors than any technical score. Even indicative, this estimate structures the budget conversation.
The new attack surface: AI agent identities
Since the emergence of AI agents in Microsoft 365 (Copilot Studio, Azure AI Foundry, third-party agents), a new category of identities has appeared in Entra ID: Entra Agent ID.
These non-human identities can have Graph permissions, access sensitive data, and act autonomously in your tenant. They often escape traditional access reviews and don't appear in standard hygiene dashboards.
Questions to ask yourself now:
-
How many Entra Agent IDs exist in your tenant?
-
What Graph permissions have been granted to them?
-
Are they subject to periodic access review?
-
Are they included in your NIS2 audit scope?
The EU AI Act strengthens this traceability requirement for automated systems as its obligations progressively enter into application.
Audit your identity posture in 5 minutes with SentinelID365
If the exercise described in this article seems long and manual to you, that's because it is — without dedicated tooling. SentinelID365 (available at sentinelid365.minerva-ia.com) is a SaaS service that automates this audit.
The operation relies on a Microsoft connection via MSAL, read-only via Microsoft Graph — no data is written to your tenant. In less than 5 minutes, the tool produces:
-
A global score + 8 sub-scores covering the dimensions listed above
-
Mapping to 11 frameworks (CIS M365 v7, EIDSCA, SCuBA, NIST CSF 2.0, NIS2, DORA, ISO 27001, SOC 2, Zero Trust, MITRE ATT&CK, Passwordless)
-
Deliverables ready for committee: 40 to 80-page Word report, Excel export, CISO-format PDF
-
Estimated financial exposure
-
PowerShell and Python remediation scripts
-
Drift detection between two audits
-
AI agent identity audit via Entra Agent ID
Info
Good to know
Mappings to NIS2, DORA, ISO 27001 and other frameworks are indicative crosswalks. SentinelID365 helps structure compliance and dialogue with auditors — it doesn't deliver certification.
What this concretely changes for the M365 administrator
-
Before an external audit: having a structured report reduces preparation time and avoids surprises on identity controls.
-
Before a COMEX or board of directors: a 40 to 80-page Word document with financial exposure replaces a raw export of technical recommendations.
-
To justify a security budget: linking each gap to a normative framework and estimated cost makes budget arbitration more objective.
-
For MSPs: producing this deliverable for multiple clients without significant manual effort is a direct commercial differentiator.
-
Facing NIS2: having a documented inventory of cyber risk management measures on identities constitutes evidence in case of ANSSI inspection.



