All Episodes

February 26, 2026 22 mins
Topics Summary

Join CTOs Felicia King and Shimon Magal for a candid, off-the-cuff conversation that pulls back the curtain on Microsoft Secure Score. They explore its strengths and sharp limitations—where it guides security improvements, where it pushes licensing, and why it falls short for real compliance and legal attestation.

Through real-world MSP and enterprise scenarios, they reveal the importance of risk-prioritized, continuous configuration management, explain how compensating controls and human workflows matter, and outline why non-tamperable reporting and the right licensing are critical. Whether you’re an MSP or an in-house security leader, this episode challenges assumptions and offers a practical roadmap to turn Microsoft security metrics into defensible, actionable posture management.

Shimon is the CTO for Optimize365.io https://www.optimize365.io/

Microsoft Secure Score Limitations

Shimon and Felicia discussed the limitations of Microsoft's Secure Score tool, which Felicia described as being Microsoft-centric and not providing comprehensive compliance reports. They agreed that while Secure Score could be useful as a baseline assessment, organizations need more specific controls for compliance with frameworks like CIS, NIST, or HIPAA. Felicia emphasized that the tool's accuracy is crucial for meaningful risk assessment, though she acknowledged that technology assessments must evolve as the tools themselves change.

Challenges with Secure Score Assessment

Shimon and Felicia discussed the limitations and challenges of Secure Score, a Microsoft tool for assessing security posture. They highlighted that Secure Score's scoring system is not equally weighted across all aspects, making it difficult for organizations to improve in specific areas. Felicia emphasized that Secure Score is primarily used to sell more Microsoft licensing rather than providing meaningful insights for improving security. They also discussed the importance of generating legal attestation reports and tracking changes over time, which Secure Score does not support effectively. Felicia suggested the need for a more comprehensive assessment platform that can produce meaningful reports, facilitate workflows, and provide a customer-facing portal for better visibility and control.

Enhancing Risk Assessment Tools

Felicia and Shimon discussed the limitations of Secure Score, noting that it does not account for complementary tools or manual processes, which are crucial for compensating controls. They emphasized the importance of incorporating both technical and human components into risk-prioritized assessments and attestation workflows.

Secure Score Compliance Challenges

Felicia expressed deep concern about MSPs using Secure Score as a fee-based service without generating legally valid attestation reports, emphasizing the importance of non-tamperable documentation for legal proof and compliance. She highlighted the need for automated systems to generate and publish reports to a secure repository, ensuring retention policies align with legal requirements. Shimon agreed on the shortcomings of Secure Score for MSPs and the need for a robust workflow that includes documentation repositories to meet business and legal needs.

M365 Licensing and Security Management

Felicia discussed the importance of having the right licensing, such as Entra IDP2, to access proactive real-time controls and data from Microsoft 365. She emphasized that alerting and diagnostics tools like Petra Security and Optimize can be beneficial for MSPs, but they should not replace Entra IDP2 licensing. Felicia also stressed the need for consistent, regular proactive secure configuration management as a service, not a one-time project, and advised MSPs to ensure their M365 tenants have this service or have explicitly declined it.

Listen
Watch
Mark as Played

Advertise With Us

Popular Podcasts

Joy 101 with Hoda Kotb

Joy 101 with Hoda Kotb

Joy is essential. And it's also elusive. You can't order it, borrow it, or simply hope it into life. But now, there's a new and exciting way to start your journey toward a more joyful existence: The Joy 101 Podcast with Hoda! Best known for her Emmy-winning work and co-anchoring Today, Hoda Kotb infuses her authenticity, curiosity, and warmth into conversations with the world’s most fascinating people. Entertainment legends, sport icons, wellness experts, and everyday folks will share how they find, allow, and experience joy. Hoda will offer her own tips and takes on seeking a more balanced, harmonious life. If you're craving inspiration, support, and useful tools to maximize your joy, tune in to these candid, uplifting, and moving on-air chats. Joy after a breakup, joy as an empty-nester, joy after loss, joy as a caretaker — Hoda's new podcast will speak to you. Joy 101 with Hoda Kotb, an iHeartPodcast.

Stuff You Should Know

Stuff You Should Know

If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices