A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Dear @GC-7046
The behavior you're seeing can be expected, because Defender for Cloud Secure Score should not be interpreted simply as a count of remediated Critical or High recommendations.
Secure Score is calculated at the security control level. Each control has a maximum possible score, and the score you currently receive depends on how much of that control has been satisfied across the applicable resources.
Because of this, remediating a large number of individual recommendations does not necessarily produce a proportional increase in the overall score. A recommendation may also have a relatively small impact on the total score, even if it is classified as High or Critical.
I would therefore recommend using Security controls --› Current score / Potential score as the primary way of prioritizing remediation. Look for controls with a significant remaining score gap and then drill down into the recommendations contributing to that gap.
The situation where a category shows potential score impact but currently has no active findings can also be confusing. The potential score represents the improvement available from that control; it should not be interpreted as meaning that there must currently be unhealthy resources behind it.
One other important point is that Secure Score is not necessarily recalculated immediately after remediation. Defender for Cloud needs to reassess the affected resources, so I would allow some time and then verify both the recommendation status and the control score.
For troubleshooting, I would compare these three things rather than relying only on the overall percentage:
- Security control --› current score vs. maximum score
- Recommendations contributing to the control
- Number of affected resources before and after remediation
This usually gives a much clearer picture of why the overall score has (or has not) moved.
If the recommendations are showing as healthy, the affected resources have been successfully reassessed, and the corresponding security control score still does not change, then I would investigate that specific control/recommendation rather than the overall Secure Score.
If this answers your query, please click Accept Answer and Upvote if you found it helpful. If you have any further questions, feel free to let us know.