Skip to content
Notifications
Clear all

Hot take: Entra ID's 'Identity Secure Score' feels like a gamified checkbox exercise.

3 Posts
3 Users
0 Reactions
0 Views
(@laurad)
Trusted Member
Joined: 1 week ago
Posts: 27
Topic starter   [#8815]

Spent the last quarter trying to get our 'score' up. Feels like chasing a high score in a game where the rules keep changing and the 'rewards' are just things you should've already done.

It nudges you to enable MFA (fine) or block legacy auth (also fine), but it's just a compliance checklist dressed up with progress bars. Zero insight into *actual* risk context. Saw a 15-point jump just by turning on a single policy that had no material impact on our day-to-day security posture. Gamified compliance, not real security. Anyone else feel like they're just checking boxes for the auditor and the CISO's dashboard?


If it sounds too good, read the release notes


   
Quote
(@kevinb)
Estimable Member
Joined: 1 week ago
Posts: 55
 

Exactly. The 15-point jump for a meaningless policy change tells you everything. The score is just a sales tool to push you onto higher license tiers for features you didn't know you "needed."

Wait until next year's scoring update suddenly demotes your config because a new premium control is the recommended "improvement." The whole cycle is designed to create a perpetual compliance project that justifies the spend.

You're not securing the estate, you're feeding the meter.



   
ReplyQuote
(@infra_architect_42)
Reputable Member
Joined: 1 month ago
Posts: 127
 

You've identified the underlying commercial engine perfectly. It's not a measurement tool, it's a demand-generation algorithm.

I've seen the same pattern in GCP's Security Command Center and AWS Security Hub. The initial "free" score is compelling, but the "recommendations" inevitably point to proprietary, costly services. That 15-point policy change is likely a low-friction item designed to give a quick win and build psychological investment in the system, making the subsequent premium upsell harder to refuse.

The real failure is that these scores are inherently non-contextual. They can't weigh the operational impact or the actual threat relevance for *your* specific tenant. So you're left optimizing for a number, not your security posture. It turns security teams into point farmers.


Boring is beautiful


   
ReplyQuote