Home / Blog / Methodology
Methodology

Understanding the weighted compliance score (L1/L2)

EntraGUARD·2026-03-03·6 min

A compliance score is only useful if you know what it measures. A raw "X of Y checks passed" ratio treats a critical control and a cosmetic setting as equal. EntraGUARD weights every result by criticality so the number reflects real risk.

The problem with a simple ratio

Imagine two organisations that both pass 200 of 283 controls — the same 71%. In the first, the failures are minor level 2 hardening items. In the second, the failures include unblocked legacy authentication and privileged accounts without MFA. A flat ratio calls both 71%. That is misleading, and it makes the score hard to defend.

Weighting by criticality

EntraGUARD classifies each control by level and weights it accordingly:

A warning (an indeterminate result — something the audit could not fully confirm) counts as an intermediate value rather than a straight pass or fail. The result is a score that moves most when the things that matter most are wrong.

Why 3×? The multiplier encodes a simple truth: a single failed fundamental control usually exposes you more than several failed hardening controls. The score should drop accordingly.

Overall and per-referential scores

EntraGUARD reports a global score and a score per referential. This matters because an overall 70% can hide a service sitting at 40%. Looking at the breakdown tells you where to focus: a strong Entra ID posture does not compensate for a weak Exchange or Azure one.

A defensible number

Because the weighting is explicit and documented, the score is one you can put in front of an executive committee, a cyber insurer or an ISO assessor and explain. It is not "percentage of boxes ticked" — it is a risk-weighted measure of posture, with a methodology behind it.

Watching it improve

The same weighting makes progress meaningful. When you remediate fundamental issues first, the score climbs faster than if you had cleared minor items — which is exactly the behaviour you want to encourage. Comparing two audits over time turns remediation work into a measurable trend.

Audit your Microsoft environment

Put this into practice. EntraGUARD runs 283 automated controls across Entra ID, Active Directory and Azure — try the free demo.

Download the free demo