Security Assessment using Office 365 Secure Score

Numerous partners today are reselling Office 365 through the Cloud Solution Provider (CSP) program. To ensure customer stickiness it is recommended that each partner include some intellectual property (IP) with their service offering. This additional IP should go beyond great support, it should be something that adds value to the solution such as additional analytics. An example of this could be customized security assessment performed using Office 365 Secure Score. Secure Score is a numerical summary of a given customer’s security posture within Office 365 based on system configurations, user behavior, and other security-related measurements. It represents the extent to which the customer has adopted security controls available in Office 365, which can help offset the risk of being breached. No online service is completely immune from security breaches; Secure Score should not be interpreted as a guarantee against security breach in any manner.

Secure Score information is available through Microsoft Graph. This means a partner can easily obtain this information for each customer. This functionality makes it possible to identify which customers have a security posture that is less than desirable. Using this information, a partner can rapidly perform a security assessment for all their customers that have Office 365 services. Also, it can be utilized to determine which customer could benefit from the following services

Microsoft Azure AD Multifactor Authentication

Microsoft Enterprise Mobility + Security

Microsoft Office 365 Advanced Threat Protection

If you would like to provide this purposed solution for your customers, then you can take advantage of the Partner Smart Office opensource project. This project leverages Azure Functions to capture Secure Score information for each customer and stores it in an instance of Azure Cosmos DB. Using this information, you can easily create Power BI reports like the following

image

image

If there is a new feature you would like for us to add to this project, then please log a request using the issue tracker. Microsoft is committed to our partners and is eager to help build new solutions. Please reach out to your account team if you would like help enhancing your Office 365 service offering.