Compliance Score and improvement actions

We all love scores. They give us a quick sense of where we stand, what’s improving, and where we might be falling behind. In the Microsoft ecosystem, scores are everywhere: Security Score, Identity Score, Exposure Score—and in Microsoft Purview, Compliance Score.

At their best, these scores turn complex security and compliance landscapes into something tangible and measurable. They help translate abstract requirements—from internal policies to industry standards and legal obligations—into something you can track, discuss, and act on. A higher score feels reassuring; a lower one is a clear signal that something needs attention.

But scores are more than just numbers on a dashboard. They’re meant to drive behavior. Each score reflects a set of actions, configurations, and decisions that collectively shape how secure and compliant an organization really is. In Purview, the Compliance Score is Microsoft’s way of answering a deceptively simple question: how well are we meeting our internal and external compliance requirements—right now?

Let’s dive into Compliance Score.

Compliance Score

Compliance Score is an essential part of Compliance Manager. Compliance Manager helps organizations work systematically with compliance across different types of requirements—internal policies, industry standards, and legislation such as GDPR and the NIS2 Directive. The first time you check the Compliance Score in Purview, it will typically be around 50%. How high should it be? The uncomfortable answer is that the higher the score, the higher the level of compliance. As a rule of thumb, I recommend aiming for a Compliance Score of at least 75%.

Compliance Manager is based on regulations, where each regulation consists of a set of improvement actions. The Compliance Score reflects how many of these improvement actions have been implemented. However, when we talk about regulations, there is often some confusion around terminology. A regulation in Purview is not the same as a statutory regulation under national law (for example the Digital Security Regulation). In Purview, a regulation can represent a standard (such as ISO 27001), a directive (such as NIS2), or a regulation in the EU sense (such as GDPR).

What Microsoft has done is to derive the essential requirements from these standards and legal frameworks and express them as a set of improvement actions. The idea is that by implementing these concrete improvement actions, an organization improves its compliance with the relevant standards and laws.

To help you get started, Microsoft has collected a set of baseline requirements from various laws and standards into a regulation called the Data Protection Baseline. If you do not add any additional regulations, this is the regulation you will see the first time you enter Compliance Manager. Microsoft describes the Data Protection Baseline as follows:

“The Microsoft 365 data protection baseline is a set of controls that includes common industry regulations and standards. This baseline draws elements primarily from NIST CSF (National Institute of Standards and Technology Cybersecurity Framework) and ISO (International Organization for Standardization), as well as from FedRAMP (Federal Risk and Authorization Management Program) and GDPR (General Data Protection Regulation of the European Union).”

There are several hundred regulations to choose from. With an E5 license (or an E5 Compliance Suite license), you can use three of these at no additional cost (also referred to as premium regulations). It is sufficient that users working with Compliance Manager have such licenses.

You can read more about premium regulations in a separate article.

Improvement Actions

Now that we understand that regulations consist of improvement actions, we can explore how these actions are managed and how they contribute to the Compliance Score. It is important to know that improvement actions fall into two categories: actions the organization must implement itself, and actions that Microsoft has already implemented. The Compliance Score is calculated by summing all implemented improvement actions. This is why the initial Compliance Score is around 50% – it reflects Microsoft-implemented actions.

We now see that the Compliance Score represents how many improvement actions have been implemented, and therefore how well the organization complies with the selected regulations. Each improvement action has a point value associated with it. Some actions are worth 21 points, while others are worth 9 points. Why is that?

To understand this, we need to look at the purpose of improvement actions.

Improvement actions can be divided into three categories:

  • Actions that prevent risks (preventive actions)
  • Actions that actively monitor systems to detect risks (detective actions)
  • Actions that aim to reduce the negative impact of a security incident (corrective actions)

In addition, improvement actions can be:

  • Mandatory, meaning absolute requirements that must be followed
  • Discretionary, meaning they depend on users understanding and complying with the rule

Taken together, the different types of improvement actions can be illustrated as follows:

Naturally, we should prioritize improvement actions that provide the highest impact—and often, the highest score. These are typically the actions that help prevent security incidents from occurring in the first place.

Implementing Improvement Actions

If you are familiar with Secure Score in the Defender portal, you know that Secure Score is updated automatically based on the actual security configuration of the tenant. This is not the case with Compliance Score. Most improvement actions need to be updated manually, meaning they must be explicitly marked as implemented. In addition, each implemented action must be tested. When there are 500 improvement actions to review – which is quite common – this becomes a time-consuming process.

Let’s look at an example of an improvement action:

As we can see, this is an example of a manual action (Type of test = Manual). To update it, we must edit the action and set Implementation status = Implemented and Test status = Passed. Only then will the Compliance Score increase (slightly).

Implementing Improvement Actions in Bulk

The most efficient approach is to update improvement actions in bulk. This is done by exporting the actions to a CSV file (Export actions). You can then edit the file, update the relevant cells in the spreadsheet (for example setting Implemented), and upload the file again (Update actions). Instructions for completing the file are included in a separate worksheet. This makes it easy to bulk-update 50–100 actions at a time.

If you receive an error when importing the CSV file, it is usually because you are attempting to update an action that is automatically updated by Microsoft. Make sure you only update manual actions, and remove any unnecessary rows from the spreadsheet before uploading.