4.6 KiB
title, description, keywords, search.product, search.appverid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, ms.author, author, ms.localizationpriority, manager, audience, ms.collection, ms.topic, ms.date
title | description | keywords | search.product | search.appverid | ms.prod | ms.mktglfcycl | ms.sitesec | ms.pagetype | ms.author | author | ms.localizationpriority | manager | audience | ms.collection | ms.topic | ms.date |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Overview of Configuration score in Microsoft Defender Security Center | Expand your visibility into the overall security configuration posture of your organization | configuration score, mdatp configuration score, secure score, security controls, improvement opportunities, security configuration score over time, security posture, baseline | eADQiWindows 10XVcnh | met150 | w10 | deploy | library | security | dolmont | DulceMontemayor | medium | dansimp | ITPro | M365-security-compliance | conceptual | 04/11/2019 |
Configuration score
Applies to:
Note
Secure score is now part of Threat & Vulnerability Management as Configuration score. The secure score page will be available for a few weeks.
The Microsoft Defender Advanced Threat Protection Configuration score gives you visibility and control over the security posture of your organization based on security best practices. High configuration score means your endpoints are more resilient from cybersecurity threat attacks.
Your configuration score widget shows the collective security configuration state of your machines across the following categories:
- Application
- Operating system
- Network
- Accounts
- Security controls
How it works
Note
Configuration score currently supports configurations set via Group Policy. Due to the current partial Intune support, configurations which might have been set through Intune might show up as misconfigured. Contact your IT Administrator to verify the actual configuration status in case your organization is using Intune for secure configuration management.
The data in the configuration score widget is the product of meticulous and ongoing vulnerability discovery process aggregated with configuration discovery assessments that continuously:
- Compare collected configurations to the collected benchmarks to discover misconfigured assets
- Map configurations to vulnerabilities that can be remediated or partially remediated (risk reduction) by remediating the misconfiguration
- Collect and maintain best practice configuration benchmarks (vendors, security feeds, internal research teams)
- Collect and monitor changes of security control configuration state from all assets
From the widget, you'd be able to see which security aspect requires attention. You can click the configuration score categories and it will take you to the Security recommendations page to see more details and understand the context of the issue. From there, you can act on them based on security benchmarks.
Improve your configuration score
The goal is to remediate the issues in the security recommendations list to improve your configuration score. You can filter the view based on:
- Related component — Accounts, Application, Network, OS, or Security controls
- Remediation type — Configuration change or Software update
See how you can improve your security configuration, for details.
Important
To boost your vulnerability assessment detection rates, download the following mandatory security updates and deploy them in your network:
- 19H1 customers | KB 4512941
- RS5 customers | KB 4516077
- RS4 customers | KB 4516045
- RS3 customers | KB 4516071
To download the security updates:
- Go to Microsoft Update Catalog.
- Key-in the security update KB number that you need to download, then click Search.