M365.FM - Modern work, security, and productivity with Microsoft 365

Microsoft Secure Score - Simply Explained

14 min · 22 jul 2026
aflevering Microsoft Secure Score - Simply Explained artwork

Beschrijving

Welcome to another episode of Knowledge Nuggets with Mirko Peters. In this episode, we're exploring Microsoft Secure Score—one of the simplest yet most misunderstood security features in Microsoft 365. Many administrators log into the Microsoft Defender portal, see a percentage like 35% or 50%, and immediately wonder whether their organization is at risk. Others spend months trying to reach a perfect score of 100%, believing that's the ultimate goal. The reality is very different. Secure Score isn't a cybersecurity grade or a guarantee against attacks. Instead, it's a practical roadmap that helps organizations understand how many of Microsoft's recommended security controls have been implemented and where improvements can have the biggest impact. WHAT IS MICROSOFT SECURE SCORE? Microsoft Secure Score measures how many recommended security controls are enabled within your Microsoft 365 tenant. It evaluates configuration rather than real-world security effectiveness. Think of it as a checklist rather than a vulnerability scanner. The score answers questions such as: * Is Multi-Factor Authentication enabled? * Are security policies configured? * Are recommended protections implemented? * Have important security settings been activated? Secure Score lives inside the Microsoft Defender portal under Exposure Management and provides organizations with a continuously updated view of their Microsoft security configuration. HOW SECURE SCORE IS CALCULATED Secure Score follows a simple formula: Points Earned ÷ Total Available Points = Secure Score Organizations earn points in two ways. Binary Controls Some recommendations are either enabled or disabled. For example: * Multi-Factor Authentication * Legacy Authentication blocking * Security Defaults If the control is enabled, full points are awarded. If not, no points are earned. Proportional Controls Other recommendations award partial credit. For example, if BitLocker encryption is enabled on 80% of managed devices, Secure Score awards approximately 80% of the available points. This allows organizations to receive recognition while gradually expanding security across their environment. WHAT IS A GOOD SECURE SCORE? One of the biggest misconceptions is that every organization should achieve 100%. In reality, Microsoft itself recognizes that this isn't always practical. Reasons include: * Different licensing levels * Features not relevant to every organization * Business requirements * Legacy systems * Accepted business risks Many Microsoft 365 environments begin between 30% and 45%, while organizations with mature security programs often maintain scores between 70% and 85%. Rather than chasing perfection, Secure Score should help organizations prioritize meaningful security improvements without negatively affecting productivity. THE FOUR PILLARS OF SECURE SCORE Secure Score organizes recommendations into four primary categories. Identity Identity focuses on: * Multi-Factor Authentication * Conditional Access * Password protection * Blocking legacy authentication Since compromised identities remain one of the most common attack vectors, this category carries significant weight. Devices Device recommendations include: * BitLocker * Microsoft Defender Antivirus * Attack Surface Reduction * Tamper Protection These settings strengthen endpoint security across managed devices. Data Data recommendations focus on: * Sensitivity Labels * Data Loss Prevention * Encryption * Microsoft Purview These controls help protect sensitive organizational information. Apps Application security evaluates: * App governance * Third-party application permissions * Cloud application security * OAuth management Together, these four pillars provide a broad overview of Microsoft's recommended security controls across the Microsoft ecosystem. COMMON MISCONCEPTIONS Secure Score is frequently misunderstood. A high score does not mean an organization cannot be compromised. It simply indicates that recommended security configurations have been implemented. Likewise, a lower score doesn't necessarily indicate an insecure organization. Another misconception is believing every recommendation should always be implemented. Some recommendations may: * Conflict with business requirements * Require licenses that aren't available * Break legacy applications * Introduce unnecessary operational complexity Organizations can document accepted risks or alternative mitigations when recommendations aren't appropriate for their environment. Secure Score supports these decisions instead of forcing every recommendation to be implemented. USING SECURE SCORE AS A ROADMAP The greatest value of Secure Score comes from its Recommended Actions. Instead of treating the score as a report card, administrators should use it as a prioritized work queue. Each recommendation includes: * Security impact * Required configuration * Implementation guidance * Direct links to configuration pages Administrators can mark recommendations as: * Planned * Risk Accepted * Resolved through Alternative Mitigation This creates both technical progress and valuable documentation for future administrators and auditors. Small monthly improvements often provide greater long-term value than trying to complete dozens of recommendations simultaneously. PART OF A LARGER SECURITY STRATEGY Secure Score represents only one component of Microsoft's overall security ecosystem. It complements solutions including: * Microsoft Defender XDR * Microsoft Sentinel * Microsoft Entra ID * Microsoft Defender for Endpoint * Microsoft Defender for Office 365 While Secure Score measures configuration coverage, these additional products provide: * Threat detection * Incident response * Identity protection * Security monitoring * Vulnerability management A strong Secure Score improves an organization's security posture, but effective cybersecurity also requires continuous monitoring, user awareness, patch management, and operational security practices. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support [https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support?utm_source=rss&utm_medium=rss&utm_campaign=rss].

Reacties

0

Wees de eerste die een reactie plaatst

Meld je nu aan en word lid van de M365.FM - Modern work, security, and productivity with Microsoft 365 community!

Probeer gratis

Probeer 14 dagen gratis

€ 9,99 / maand na proefperiode. · Elk moment opzegbaar

  • Podcasts die je alleen op Podimo hoort
  • 20 uur luisterboeken / maand
  • Gratis podcasts

Alle afleveringen

827 afleveringen

aflevering Microsoft Loop Workspaces - Simply Explained artwork

Microsoft Loop Workspaces - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're taking a closer look at Microsoft Loop Workspaces, one of the newest collaboration experiences in Microsoft 365 that's changing how teams organize projects and work together. If you've ever found yourself jumping between Microsoft Teams, Outlook, OneNote, SharePoint, Planner, and Microsoft To Do just to keep a single project moving, you're not alone. Modern work is more connected than ever, yet the information we need is often scattered across multiple applications. Notes live in OneNote, conversations happen in Teams, documents are stored in SharePoint, and tasks are managed somewhere else entirely. Every application does its job well, but switching between them interrupts focus and makes collaboration harder than it needs to be. Microsoft Loop Workspaces were created to solve exactly this problem. Instead of treating documents, conversations, and tasks as separate pieces, Loop brings them together into one flexible collaborative workspace where teams can plan, brainstorm, assign work, and make decisions in real time. In this episode we'll explore how Loop Workspaces are structured, how they integrate with the rest of Microsoft 365, and when they're the right tool for your next project. WHAT IS A MICROSOFT LOOP WORKSPACE? The easiest way to understand a Loop Workspace is to imagine a dedicated project room inside your office. Every project has its own whiteboards, notes, action lists, meeting minutes, reference documents, and ideas pinned to the walls. Anyone working on that project knows exactly where to go to see the latest information. A Microsoft Loop Workspace brings that same concept into the digital world. It acts as a shared space where everything related to a project lives together. Instead of searching through Teams conversations, Outlook emails, Planner boards, and SharePoint folders, your team opens one workspace and immediately sees the latest notes, tasks, documents, and decisions. Unlike Microsoft Teams, which primarily focuses on conversations, or SharePoint, which concentrates on document management, Loop Workspaces provide a flexible canvas for collaboration. Teams continue chatting, brainstorming, updating tasks, embedding files, and documenting decisions inside the same workspace without constantly changing applications. Every workspace belongs to a specific team or initiative and includes its own members, cover image, pages, and collaborative content, making it easy to separate different projects while keeping everyone aligned.  UNDERSTANDING THE BUILDING BLOCKS OF LOOP Microsoft Loop is built around three core concepts that work together to organize information naturally. At the highest level sits the Workspace. This represents an entire project, department, or business initiative and acts as the container for everything related to that work. Inside each workspace are Pages. These are where the actual collaboration happens. A page might contain meeting notes, project timelines, brainstorming sessions, documentation, checklists, or planning information. As projects grow, additional subpages can be created to organize more detailed topics without making the main workspace feel cluttered. Perhaps the most innovative feature of Loop is its Components. Components are portable pieces of content that remain synchronized wherever they appear. A task list created inside a Loop page can be copied into a Microsoft Teams chat or an Outlook email while remaining connected to its original source. When someone updates the task list in Teams, those changes automatically appear inside the Loop Workspace. Likewise, edits made in Loop immediately appear wherever that component has been shared. This synchronization removes one of the biggest frustrations in modern collaboration: maintaining multiple versions of the same information across different applications.  CREATING A LOOP WORKSPACE Getting started with Microsoft Loop is surprisingly straightforward, especially for organizations already using Microsoft Teams. A Loop Workspace can be created directly inside a Teams channel by adding a new Loop tab. Once the workspace receives a name and optional cover image, it immediately becomes available to everyone who already has access to that Teams channel. There is no need to manually invite every team member or configure separate permissions because membership automatically follows the existing Teams channel. While basic collaboration can happen directly inside Microsoft Teams, opening the workspace in the dedicated Loop application unlocks additional capabilities including richer navigation, page management, version history, and enhanced meeting experiences. The result is a living collaboration hub where project information remains organized and continuously updated instead of being scattered across several disconnected Microsoft 365 services.  REAL-TIME COLLABORATION ACROSS MICROSOFT 365 One of Loop's greatest strengths is how naturally it supports teamwork. Just like Microsoft Teams and Outlook, Loop supports @mentions, allowing team members to notify colleagues directly within a page. When someone is mentioned, they receive notifications together with the relevant collaborative content, making it easy to understand the context before responding. Comments remain attached directly to specific blocks of content rather than existing as separate email conversations. Team members can discuss ideas exactly where the work is happening instead of creating disconnected chat threads or forwarding long email chains. Multiple people can edit the same page simultaneously while seeing each other's cursors in real time. Changes appear instantly for everyone, creating an experience that feels much closer to working together around the same whiteboard than editing traditional documents. By keeping conversations, edits, and project content together, Loop significantly reduces context switching and helps teams stay focused on the work itself.  TASK MANAGEMENT THAT SYNCS AUTOMATICALLY Another area where Loop stands out is task management. Task lists created inside a Loop Workspace are not isolated within the application. Instead, they integrate directly with Microsoft Planner and Microsoft To Do, allowing assignments to follow users wherever they already manage their work. When a task is assigned inside Loop, it automatically appears in the assigned person's Microsoft To Do list. At the same time, project managers can monitor those same tasks inside Microsoft Planner using familiar board, timeline, or calendar views. Marking a task complete in one application immediately updates it everywhere else. This synchronization eliminates duplicate data entry while ensuring everyone sees the same information regardless of whether they prefer working inside Loop, Planner, or Microsoft To Do. For many smaller projects, this also means Loop can provide lightweight project management capabilities without introducing another dedicated project management platform.  BETTER MEETINGS WITH LOOP Loop also improves one of the most common business activities: meetings. Meeting agendas can be created directly inside Microsoft Teams using Loop components before the meeting even begins. Team members contribute agenda items, assign presenters, and prepare discussion topics collaboratively instead of relying on one organizer to distribute updates. During the meeting, everyone contributes notes to the same shared workspace in real time. Decisions, action items, and meeting summaries remain visible to every participant as they're created. After the meeting finishes, assigned tasks already exist inside Planner and Microsoft To Do without anyone manually copying notes or rewriting action lists. Because recurring meetings reuse the same collaborative structure, teams build a continuous knowledge base instead of starting from scratch every week. This integrated workflow dramatically reduces administrative work while ensuring that decisions and responsibilities are immediately visible to everyone involved.  WHEN SHOULD YOU USE LOOP? Although Microsoft Loop is incredibly flexible, it isn't designed to replace every Microsoft 365 application. Loop performs best when teams need fast-moving collaboration, brainstorming sessions, project planning, meeting notes, lightweight task management, or shared working documents that evolve continuously throughout a project. OneNote remains the better choice for personal notebooks, handwritten notes, and long-term personal knowledge management. SharePoint continues to excel at document libraries, formal records management, compliance, and structured file storage. Microsoft Word and Excel are still the preferred tools for formal reports, contracts, financial models, and documents requiring advanced formatting. Rather than replacing these applications, Loop acts as the collaborative layer that connects them. It becomes the central workspace where ideas are captured, tasks are coordinated, and projects move forward while the specialized Microsoft applications continue handling the work they were designed for. Thinking of Loop as the glue between Microsoft 365 applications is often the easiest way to understand its role within the broader ecosystem.  Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support [https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support?utm_source=rss&utm_medium=rss&utm_campaign=rss].

22 jul 20268 min
aflevering Microsoft Cloud Solution Provider (CSP) - Simply Explained artwork

Microsoft Cloud Solution Provider (CSP) - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring one of the most important programs in Microsoft's partner ecosystem: the Microsoft Cloud Solution Provider (CSP) program. If you've ever purchased Microsoft 365, Azure, Dynamics 365, or Microsoft Security services through a local IT provider, there's a very good chance you've already used the CSP program without even realizing it. While many organizations believe they are buying directly from Microsoft, in reality a trusted partner often manages the entire relationship—from licensing and billing to technical support and ongoing services. In this episode, we'll break down exactly how the CSP program works, why Microsoft relies so heavily on its partner network, and what the program means for customers, IT providers, and software partners. Whether you're evaluating licensing options for your own business or considering becoming a Microsoft partner yourself, understanding CSP helps explain how most organizations consume Microsoft cloud services today. WHAT IS THE MICROSOFT CLOUD SOLUTION PROVIDER PROGRAM? The Cloud Solution Provider program is Microsoft's commercial model that allows certified partners to sell, manage, and support Microsoft cloud services on behalf of Microsoft. Instead of purchasing Microsoft 365, Azure, Dynamics 365, or Enterprise Mobility and Security directly from Microsoft, many businesses purchase these services through a trusted partner who becomes their primary point of contact. A useful way to think about CSP is to imagine a wholesale distribution model. Microsoft develops and operates the cloud platforms, while CSP partners package those services together with consulting, deployment, migration, support, and managed services. Rather than simply acting as resellers, partners become long-term advisors responsible for helping customers successfully adopt Microsoft's cloud technologies. For customers, this means they often receive a single monthly invoice, one support contact, and ongoing technical guidance instead of having to manage multiple Microsoft portals and support channels themselves. In many cases, the relationship with the partner becomes far more important than the direct relationship with Microsoft because the partner handles nearly every aspect of the customer's cloud environment. HOW THE CSP ECOSYSTEM WORKS The CSP ecosystem is built around three key participants that each play a different role. Microsoft develops and operates the cloud services, including Microsoft 365, Azure, Dynamics 365, Microsoft Security, and many other cloud offerings. The CSP partner purchases access to these services, provisions customer subscriptions, manages licensing, provides support, and often delivers additional consulting or managed services. Finally, the customer consumes the technology without needing to interact directly with Microsoft for most day-to-day activities. This separation of responsibilities allows Microsoft to scale globally while enabling thousands of partners to build their own businesses around Microsoft's cloud platform. Instead of Microsoft supporting every individual organization directly, partners provide localized expertise, customer relationships, and industry-specific knowledge that Microsoft alone could never deliver at the same scale. For many businesses, this creates a much more personal experience. When employees need assistance, they contact a partner who already understands their infrastructure, licensing, and business requirements instead of opening a generic support case with Microsoft. DIRECT-BILL VS. INDIRECT RESELLER Although every CSP partner participates in the same overall program, there are two very different operating models. Direct-Bill partners purchase cloud services directly from Microsoft and are responsible for everything themselves, including billing platforms, customer support, infrastructure, and Microsoft relationship management. Becoming a Direct-Bill partner requires significant investment and experience, including substantial annual revenue, an established Microsoft partnership history, Microsoft support contracts, and Solutions Partner designations. Because of these demanding requirements, relatively few organizations operate as Direct-Bill CSP partners. Most organizations instead become Indirect Resellers. Rather than working directly with Microsoft, they partner with a distributor such as Pax8, Ingram Micro, or other authorized indirect providers. These distributors handle the complex Microsoft relationship while allowing resellers to focus on what they do best—serving customers. This model dramatically lowers the barrier to entry for smaller IT providers. Instead of investing millions into billing infrastructure and support operations, they can leverage their distributor's platform while concentrating on consulting, migrations, managed services, and customer success. As a result, the overwhelming majority of CSP partners operate under the indirect model.  WHERE CSP PARTNERS CREATE VALUE One of the biggest misconceptions about CSP is that partners simply resell Microsoft licenses. In reality, licensing is usually only a small part of the overall customer relationship. Most partners differentiate themselves by delivering services that surround the Microsoft subscription. These may include tenant setup, identity management, Microsoft Entra configuration, device enrollment with Microsoft Intune, security baselines, Microsoft Defender deployment, user adoption workshops, migration projects, help desk services, monitoring, backup, compliance consulting, and ongoing managed IT support. Interestingly, the licensing margin itself is relatively modest. The real business opportunity comes from the additional expertise and services partners provide after the licenses have been sold. Customers are rarely paying more simply for a Microsoft subscription—they're investing in an ongoing relationship with experts who understand their environment and can help them maximize the value of Microsoft's cloud platform. This approach creates recurring revenue for partners while giving customers access to experienced professionals who continuously optimize and secure their Microsoft environment.  UNDERSTANDING THE NEW COMMERCE EXPERIENCE (NCE) One of the biggest changes to the CSP program arrived with Microsoft's New Commerce Experience (NCE), which fundamentally changed how cloud subscriptions are purchased and managed. Before NCE, organizations enjoyed considerable flexibility. Licenses could often be added or removed with minimal restrictions, making it easy to respond to changing business requirements. Under the New Commerce Experience, customers now select subscription terms that typically span one month, one year, or even three years, with pricing varying depending on the level of commitment. Monthly subscriptions provide the greatest flexibility but generally carry a higher price. Annual commitments reduce costs while requiring organizations to plan their licensing more carefully. Three-year commitments offer additional savings but significantly reduce flexibility because subscriptions cannot simply be adjusted whenever staffing levels change. Another important aspect of NCE is the limited cancellation period. After a subscription has been ordered, organizations only have a short window to make changes before the commitment becomes binding. This means businesses should carefully forecast their licensing requirements before placing large orders, particularly if workforce numbers are expected to fluctuate during the subscription term.  WHY ORGANIZATIONS CHOOSE CSP For many organizations, especially small and medium-sized businesses, the biggest advantage of CSP is simplicity. Rather than managing Microsoft licensing independently, customers gain access to an experienced technology partner who handles purchasing, provisioning, billing, support, and ongoing optimization. Instead of juggling multiple invoices or trying to navigate Microsoft's licensing programs themselves, organizations receive one consolidated experience designed around their business needs. Many CSP partners also become strategic advisors rather than simple resellers. They recommend security improvements, assist with Microsoft 365 adoption, deploy Azure workloads, implement Microsoft Intune, and continuously monitor customers' cloud environments. This allows businesses without large internal IT departments to benefit from enterprise-grade expertise without building those capabilities internally. For larger organizations, Enterprise Agreements may still provide financial advantages under specific circumstances. However, Microsoft has gradually shifted much of its commercial focus toward CSP and the New Commerce Experience, making CSP the default purchasing model for many modern organizations entering the Microsoft ecosystem today.  THE RESPONSIBILITIES OF A CSP PARTNER Becoming a CSP partner involves far more than selling licenses. Partners are responsible for first-line customer support, ongoing technical guidance, secure tenant management, and maintaining Microsoft's required security standards. They must implement strong identity protection, multi-factor authentication, secure operational practices, and comply with Microsoft's Partner Center security requirements. Microsoft has also continued raising the expectations placed on partners by introducing new support models, partner designations, and security requirements. This reflects Microsoft's broader strategy of ensuring that partners deliver measurable value rather than acting purely as licensing intermediaries.  Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support [https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support?utm_source=rss&utm_medium=rss&utm_campaign=rss].

22 jul 202614 min
aflevering Microsoft Marketplace - Simply Explained artwork

Microsoft Marketplace - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Marketplace, one of the most important platforms in the Microsoft ecosystem—and one that's often misunderstood. When most people hear the word Marketplace, they imagine something similar to an app store where you browse a few applications, click Buy, and you're done. While that's certainly part of the story, Microsoft Marketplace has evolved into something much bigger. Today it's a global commerce platform that connects customers, software vendors, consultants, AI solutions, and cloud services through a single purchasing experience. Whether you're an IT administrator looking for infrastructure, a business leader searching for a Power Platform solution, or a software vendor trying to reach millions of Microsoft customers, Marketplace plays a central role. By the end of this episode, you'll understand what Microsoft Marketplace actually is, why it exists, how it simplifies software procurement, and why it's becoming one of Microsoft's most important growth platforms. WHY MICROSOFT CREATED MARKETPLACE Before cloud marketplaces existed, buying enterprise software was surprisingly complicated. Every vendor had its own website, its own pricing model, its own contract, and its own billing process. If an organization wanted a security platform from one company, a reporting solution from another, and an AI tool from a third, procurement quickly became a project of its own. IT departments spent weeks evaluating vendors, finance teams had to process multiple invoices every month, and legal departments reviewed countless contracts that often covered very similar services. Even after the software had been purchased, deployment could still involve manual licensing, configuration, and user provisioning. Microsoft recognized that the buying experience itself had become a problem. Organizations didn't necessarily need fewer software vendors—they needed a simpler way to discover, evaluate, purchase, and manage them. That's exactly what Microsoft Marketplace delivers. Instead of maintaining dozens of independent vendor relationships, organizations can purchase solutions through the same Microsoft relationship they already use for Azure and Microsoft 365. The result is a procurement process that's dramatically simpler, faster, and easier to manage.  WHAT IS MICROSOFT MARKETPLACE? At its core, Microsoft Marketplace is Microsoft's unified commercial platform for cloud solutions. Rather than being limited to applications, Marketplace offers an enormous range of commercial products including SaaS solutions, Azure infrastructure, virtual machines, managed applications, AI agents, consulting services, business applications, and Power Platform extensions. Every solution published on the platform has gone through Microsoft's validation process before becoming available to customers. A useful way to think about Marketplace is as a digital shopping mall. Instead of every software company building its own storefront, Microsoft provides the building. Customers enter through a single front door, compare products, read documentation, start free trials, purchase subscriptions, and deploy solutions without ever leaving the Microsoft ecosystem. Because everything integrates with Microsoft accounts, Azure subscriptions, and Microsoft 365 tenants, customers spend less time managing vendors and more time deploying technology that actually solves business problems.  TWO STOREFRONTS, ONE PLATFORM One area that often causes confusion is the relationship between Azure Marketplace and AppSource. Although Microsoft now presents one unified Marketplace experience, the platform still serves two different audiences. Azure Marketplace is primarily designed for technical buyers. Cloud architects, developers, infrastructure engineers, and Azure administrators typically visit Azure Marketplace when searching for virtual machines, managed applications, containers, security appliances, databases, or cloud-native SaaS services that integrate directly with Azure. AppSource, on the other hand, focuses on business users. Marketing departments, HR teams, finance professionals, sales organizations, and operations managers generally discover business applications, Microsoft Teams extensions, Dynamics 365 solutions, and Power Platform applications through AppSource. The important point is that customers don't need to understand this distinction. A software vendor can publish a single solution, and Microsoft automatically presents it through the most appropriate storefront depending on who is searching and what they're looking for. This unified experience removes unnecessary complexity while ensuring both technical and business audiences discover relevant solutions.  BUYING SOFTWARE HAS NEVER BEEN EASIER One of Marketplace's biggest strengths is how dramatically it simplifies procurement. Instead of contacting vendors individually, customers search Marketplace, compare available products, review documentation, examine customer ratings, and often start a free trial within minutes. If the solution meets their requirements, purchasing becomes equally straightforward. Marketplace supports several commercial models, including subscription licensing, pay-as-you-go services, bring-your-own-license scenarios, and private offers for enterprise agreements. Perhaps even more valuable is the integration with Microsoft's existing billing infrastructure. Organizations don't receive another vendor invoice or need another purchasing workflow. Instead, Marketplace purchases are added to their existing Microsoft agreement, allowing Azure services, Microsoft 365 subscriptions, and Marketplace solutions to appear together on consolidated billing. For procurement and finance teams, this eliminates significant administrative overhead while giving IT departments much faster access to new technology.  WHY SOFTWARE VENDORS LOVE MARKETPLACE Marketplace doesn't only benefit customers—it has become one of the most important sales channels for Microsoft partners. Publishing a solution on Marketplace immediately exposes it to millions of organizations already working inside Microsoft's cloud ecosystem. Instead of convincing customers to visit another website, partners appear directly where purchasing decisions are already being made. Their applications can be discovered through Azure, Microsoft Teams, Microsoft 365, Copilot, and Microsoft's administration portals. This dramatically increases visibility while reducing customer acquisition costs. Marketplace also enables participation in Microsoft's co-sell programs, where Microsoft sales teams actively recommend partner solutions during customer engagements. For many software companies, Marketplace has evolved from an optional distribution channel into a fundamental part of their overall go-to-market strategy. As Microsoft continues investing in partner incentives and Marketplace Rewards, the platform is becoming increasingly important for software vendors building on Azure and Microsoft 365.  AI IS CHANGING THE MARKETPLACE EXPERIENCE Like many Microsoft products, Marketplace is rapidly being transformed by artificial intelligence. Instead of requiring customers to search using exact product names, Marketplace increasingly supports natural language queries. Rather than typing "project management software," a customer might simply ask for "an AI agent that helps coordinate projects inside Microsoft Teams." Marketplace understands the request, recommends relevant solutions, highlights important differences, and even generates side-by-side comparisons that explain which product best matches the customer's requirements. Product pages are also becoming more interactive through AI-powered assistants capable of answering licensing, deployment, integration, and compatibility questions. At the same time, Marketplace has introduced dedicated sections for Microsoft 365 Copilot agents and AI-powered business applications, making it much easier for organizations to discover intelligent solutions that integrate directly into their existing Microsoft environment. Instead of simply becoming a larger software catalog, Marketplace is evolving into an intelligent advisor that actively helps customers make better purchasing decisions.  EVERYTHING CONNECTS THROUGH THE MICROSOFT ECOSYSTEM Perhaps the greatest strength of Microsoft Marketplace isn't the number of available products—it's how seamlessly everything integrates. When a customer purchases a solution through Marketplace, they're not simply buying software. They're extending their existing Microsoft environment. Authentication works through Microsoft Entra ID. Existing Conditional Access policies continue protecting users. Billing flows through established Microsoft agreements. Azure subscriptions provision resources automatically, while Microsoft Teams, Copilot, Dynamics 365, and Microsoft 365 can immediately surface newly purchased applications. This level of integration dramatically reduces deployment complexity while maintaining the governance, identity management, and security controls organizations have already invested in. Rather than introducing another isolated platform, Marketplace strengthens the Microsoft ecosystem by allowing customers to extend it safely with trusted third-party solutions. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support [https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support?utm_source=rss&utm_medium=rss&utm_campaign=rss].

22 jul 202616 min
aflevering Microsoft Secure Score - Simply Explained artwork

Microsoft Secure Score - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. In this episode, we're exploring Microsoft Secure Score—one of the simplest yet most misunderstood security features in Microsoft 365. Many administrators log into the Microsoft Defender portal, see a percentage like 35% or 50%, and immediately wonder whether their organization is at risk. Others spend months trying to reach a perfect score of 100%, believing that's the ultimate goal. The reality is very different. Secure Score isn't a cybersecurity grade or a guarantee against attacks. Instead, it's a practical roadmap that helps organizations understand how many of Microsoft's recommended security controls have been implemented and where improvements can have the biggest impact. WHAT IS MICROSOFT SECURE SCORE? Microsoft Secure Score measures how many recommended security controls are enabled within your Microsoft 365 tenant. It evaluates configuration rather than real-world security effectiveness. Think of it as a checklist rather than a vulnerability scanner. The score answers questions such as: * Is Multi-Factor Authentication enabled? * Are security policies configured? * Are recommended protections implemented? * Have important security settings been activated? Secure Score lives inside the Microsoft Defender portal under Exposure Management and provides organizations with a continuously updated view of their Microsoft security configuration. HOW SECURE SCORE IS CALCULATED Secure Score follows a simple formula: Points Earned ÷ Total Available Points = Secure Score Organizations earn points in two ways. Binary Controls Some recommendations are either enabled or disabled. For example: * Multi-Factor Authentication * Legacy Authentication blocking * Security Defaults If the control is enabled, full points are awarded. If not, no points are earned. Proportional Controls Other recommendations award partial credit. For example, if BitLocker encryption is enabled on 80% of managed devices, Secure Score awards approximately 80% of the available points. This allows organizations to receive recognition while gradually expanding security across their environment. WHAT IS A GOOD SECURE SCORE? One of the biggest misconceptions is that every organization should achieve 100%. In reality, Microsoft itself recognizes that this isn't always practical. Reasons include: * Different licensing levels * Features not relevant to every organization * Business requirements * Legacy systems * Accepted business risks Many Microsoft 365 environments begin between 30% and 45%, while organizations with mature security programs often maintain scores between 70% and 85%. Rather than chasing perfection, Secure Score should help organizations prioritize meaningful security improvements without negatively affecting productivity. THE FOUR PILLARS OF SECURE SCORE Secure Score organizes recommendations into four primary categories. Identity Identity focuses on: * Multi-Factor Authentication * Conditional Access * Password protection * Blocking legacy authentication Since compromised identities remain one of the most common attack vectors, this category carries significant weight. Devices Device recommendations include: * BitLocker * Microsoft Defender Antivirus * Attack Surface Reduction * Tamper Protection These settings strengthen endpoint security across managed devices. Data Data recommendations focus on: * Sensitivity Labels * Data Loss Prevention * Encryption * Microsoft Purview These controls help protect sensitive organizational information. Apps Application security evaluates: * App governance * Third-party application permissions * Cloud application security * OAuth management Together, these four pillars provide a broad overview of Microsoft's recommended security controls across the Microsoft ecosystem. COMMON MISCONCEPTIONS Secure Score is frequently misunderstood. A high score does not mean an organization cannot be compromised. It simply indicates that recommended security configurations have been implemented. Likewise, a lower score doesn't necessarily indicate an insecure organization. Another misconception is believing every recommendation should always be implemented. Some recommendations may: * Conflict with business requirements * Require licenses that aren't available * Break legacy applications * Introduce unnecessary operational complexity Organizations can document accepted risks or alternative mitigations when recommendations aren't appropriate for their environment. Secure Score supports these decisions instead of forcing every recommendation to be implemented. USING SECURE SCORE AS A ROADMAP The greatest value of Secure Score comes from its Recommended Actions. Instead of treating the score as a report card, administrators should use it as a prioritized work queue. Each recommendation includes: * Security impact * Required configuration * Implementation guidance * Direct links to configuration pages Administrators can mark recommendations as: * Planned * Risk Accepted * Resolved through Alternative Mitigation This creates both technical progress and valuable documentation for future administrators and auditors. Small monthly improvements often provide greater long-term value than trying to complete dozens of recommendations simultaneously. PART OF A LARGER SECURITY STRATEGY Secure Score represents only one component of Microsoft's overall security ecosystem. It complements solutions including: * Microsoft Defender XDR * Microsoft Sentinel * Microsoft Entra ID * Microsoft Defender for Endpoint * Microsoft Defender for Office 365 While Secure Score measures configuration coverage, these additional products provide: * Threat detection * Incident response * Identity protection * Security monitoring * Vulnerability management A strong Secure Score improves an organization's security posture, but effective cybersecurity also requires continuous monitoring, user awareness, patch management, and operational security practices. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support [https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support?utm_source=rss&utm_medium=rss&utm_campaign=rss].

22 jul 202614 min
aflevering Microsoft Defender for Cloud Apps - Simply Explained artwork

Microsoft Defender for Cloud Apps - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. In this episode, we're exploring Microsoft Defender for Cloud Apps—Microsoft's Cloud Access Security Broker (CASB) that helps organizations discover, monitor, and protect the cloud applications employees use every day. Modern organizations rely on hundreds of cloud services, but many of them are never approved by IT. Employees sign up for AI tools, file-sharing platforms, collaboration services, and productivity apps to solve business problems quickly. While these services improve productivity, they can also introduce significant security, compliance, and data protection risks. Microsoft Defender for Cloud Apps helps organizations regain visibility, understand risk, and protect business data without preventing innovation. THE PROBLEM: SHADOW IT One of the biggest challenges facing modern IT departments is Shadow IT. Shadow IT refers to cloud applications employees use without official approval from the IT department. Examples include: * File-sharing websites * AI writing assistants * Project management tools * Online collaboration platforms * Personal cloud storage Employees often adopt these services because they're convenient, but organizations lose visibility into where sensitive business information is being stored and shared. Without visibility, companies cannot adequately manage: * Data leakage * Compliance requirements * Insider threats * Third-party security risks Microsoft Defender for Cloud Apps was designed specifically to eliminate these blind spots. WHAT IS MICROSOFT DEFENDER FOR CLOUD APPS? Microsoft Defender for Cloud Apps acts as a security layer between users and cloud services. Rather than replacing cloud applications, it continuously monitors how they're being used. Its primary responsibilities include: * Discovering cloud applications * Assessing application risk * Detecting suspicious behavior * Protecting sensitive information * Enforcing security policies As part of the broader Microsoft Defender ecosystem, it integrates closely with Microsoft Entra ID, Microsoft Defender for Endpoint, Microsoft Sentinel, and Microsoft Defender XDR to provide enterprise-wide cloud security. CLOUD DISCOVERY The platform's first major capability is Cloud Discovery. Cloud Discovery identifies every cloud application employees access across the organization, including services that IT never approved. Organizations using Microsoft Defender for Endpoint receive continuous automated monitoring, while Microsoft 365 Business Premium customers can upload firewall or proxy logs for periodic analysis. The Cloud Discovery dashboard provides insights into: * Applications in use * Number of users * Network traffic * Data uploads * Geographic locations * Risk ratings Instead of guessing which cloud services employees use, administrators gain complete visibility into their cloud environment. THE APP CATALOG Finding cloud applications is only the beginning. Microsoft maintains an App Catalog containing more than 31,000 cloud applications, each evaluated against over 90 security and compliance factors. Applications receive risk scores based on criteria including: * Encryption * Multi-Factor Authentication * Compliance certifications * Privacy policies * Data ownership * Audit capabilities Organizations can classify applications as: * Sanctioned * Unsanctioned * Monitored This allows IT departments to quickly identify trusted services while blocking or closely monitoring applications that introduce unnecessary business risk. THREAT DETECTION Microsoft Defender for Cloud Apps continuously monitors user behavior for suspicious activity. Built-in policies automatically detect scenarios such as: * Impossible travel * Mass downloads * Mass deletions * Logins from risky IP addresses * Suspicious email forwarding * Unusual account behavior Using User and Entity Behavior Analytics (UEBA), the platform learns normal user activity over time and identifies anomalies that could indicate compromised accounts or insider threats. Organizations can respond automatically by: * Sending alerts * Blocking sessions * Suspending accounts * Triggering security workflows This allows security teams to react quickly before attackers cause significant damage. DATA PROTECTION Beyond detecting threats, Defender for Cloud Apps actively protects sensitive information. Integration with Microsoft Information Protection enables automatic application of sensitivity labels based on document content. The platform can also enforce: * Download restrictions * Copy and paste controls * Printing restrictions * Session monitoring * Conditional Access policies Support extends beyond Microsoft services to third-party platforms including: * Google Workspace * Salesforce * Box * AWS * Dropbox This consistent protection helps organizations secure data regardless of where employees choose to work. OAUTH APP GOVERNANCE Many cloud applications request access through OAuth permissions. While convenient, some applications request far more permissions than necessary. Defender for Cloud Apps monitors OAuth applications and identifies services requesting excessive access to: * Email * Files * Calendars * Contacts * OneDrive * Microsoft 365 data Administrators can review, approve, or revoke permissions before sensitive business information becomes exposed through third-party applications. This provides another critical layer of protection against data leakage and account compromise. Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support [https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support?utm_source=rss&utm_medium=rss&utm_campaign=rss].

22 jul 202615 min