The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 5: The Identity Threat Protection Scorecard
- Derek Morgan

- Aug 12
- 4 min read
Part 1 of this series argued that authentication proves identity, not trust. Part 2 showed that your tenant holds more identities than employees. Part 3 drew the line around what Conditional Access actually stops. Part 4 asked whether Defender XDR actually sees an attack, or only appears deployed. Each argument stands on its own. None of them answers the question every CISO eventually asks in a budget meeting: are we better off than we were 6 months ago, and can you show me?
Most security teams can't answer that question with a number. They can describe what's been configured. They can point to a dashboard. What they usually can't do is connect four separate categories of work, prevention, detection, governance, and ownership, into a single measurement that moves over time and that a non-technical executive can actually read.

What the scorecard actually measures
Four dimensions, not one score. Preventive controls are Conditional Access, PIM, and authentication strength, the territory Part 3 covered. Detective capabilities are Defender XDR coverage and validated alerting, the territory Part 4 covered. Governance processes are access reviews, identity lifecycle, and ownership of the non-human identities Part 2 introduced. Operational ownership is the answer to a specific question: when one of these controls degrades, whose job is it to notice? A maturity score built from only one of these four measures a quarter of the picture.
Where Microsoft Secure Score stops. Microsoft's own Identity Secure Score is useful and worth tracking, but it measures one thing: how closely your tenant's configuration matches Microsoft's recommended settings. Microsoft's own documentation states directly that the score doesn't express your risk of being breached, it expresses the extent to which you've adopted features that can offset risk. That's a configuration-alignment score. It says nothing about whether Defender XDR would actually catch an attack against those identities, and nothing about who owns the access review when it lapses. The Identity Secure Score is one useful input into a scorecard. It isn't the scorecard.

From four scores to one maturity read. The four dimensions each get scored independently, then roll up into a single maturity tier your executive sponsor can track quarter over quarter. The tier is the number leadership sees. The four underlying scores are what the engineer or architect actually acts on. Keeping both layers visible is what makes the scorecard useful to two audiences reading the same document for different reasons.
Business case
A budget request backed by "we're a 40 out of 100 on detection validation, here's what closes the gap" gets funded differently than one backed by "we should do more Defender work." The first has a before, a target, and a cost attached to the distance between them. The second is an opinion competing against every other opinion asking for the same budget. Measurement is what turns a technical ask into a line item with a before-and-after, which is the format finance conversations respond to.
What this looks like without a scorecard
I worked with a client where leadership couldn't move forward on security investment decisions, not because they disagreed with the recommendations, but because they had no way to see the current posture. Nobody could say what share of the user population actually had MFA enforced versus assumed to be enforced. There was no data connecting the cost of additional email security features to the risk those features would reduce. Every proposal competed for budget as an opinion instead of a measured gap, and every proposal lost to whichever initiative had a clearer number attached to it, regardless of which one actually reduced more risk. A scorecard closes that gap. It gives leadership a baseline they can see, and it gives the next investment request a before-and-after instead of a guess.
Building your own scorecard this week
Score your tenant across the four dimensions using what you already have: Identity Secure Score for configuration, Defender XDR's Coverage and maturity page for detection (Part 4), a quick access review audit for governance, a one-page ownership matrix for accountability
Convert the four scores into one maturity read your executive sponsor can track quarter over quarter
Attach a dollar or risk-reduction estimate to the single highest-impact gap, not all of them at once
Put a date on the next measurement before you leave the room, an unscheduled remeasurement doesn't happen

The takeaway
What gets measured gets funded. What gets funded gets improved. That's true of the scorecard itself and it was true of every control this series covered before it: Conditional Access, Defender XDR coverage, non-human identity governance, all of it competes for the same budget, and the version of the argument backed by a number wins more often than the version backed by conviction.
Five articles, one argument: proving who someone is doesn't finish the security work, and none of the controls that follow matter if you can't measure and communicate whether they're working. The GitHub companion to this series, the Identity Threat Protection Scorecard, turns this article into something you can actually run against your own tenant.
Identity Threat Protection Scorecard: M365-Security-Frameworks/Frameworks/Identity-Threat-Protection-Scorecard at main · Cloud-Harbor-Consulting-LLC/M365-Security-Frameworks



Comments