Understanding the weighted compliance score (L1/L2)
A compliance score is only useful if you know what it measures. A raw "X of Y checks passed" ratio treats a critical control and a cosmetic setting as equal. EntraGUARD weights every result by criticality so the number reflects real risk.
The problem with a simple ratio
Imagine two organisations that both pass 200 of 283 controls — the same 71%. In the first, the failures are minor level 2 hardening items. In the second, the failures include unblocked legacy authentication and privileged accounts without MFA. A flat ratio calls both 71%. That is misleading, and it makes the score hard to defend.
Weighting by criticality
EntraGUARD classifies each control by level and weights it accordingly:
- Level 1 (fundamental) — controls that address core, high-impact risk. Weighted 3×.
- Level 2 (hardening) — defence-in-depth measures. Weighted 1×.
A warning (an indeterminate result — something the audit could not fully confirm) counts as an intermediate value rather than a straight pass or fail. The result is a score that moves most when the things that matter most are wrong.
Why 3×? The multiplier encodes a simple truth: a single failed fundamental control usually exposes you more than several failed hardening controls. The score should drop accordingly.
Overall and per-referential scores
EntraGUARD reports a global score and a score per referential. This matters because an overall 70% can hide a service sitting at 40%. Looking at the breakdown tells you where to focus: a strong Entra ID posture does not compensate for a weak Exchange or Azure one.
A defensible number
Because the weighting is explicit and documented, the score is one you can put in front of an executive committee, a cyber insurer or an ISO assessor and explain. It is not "percentage of boxes ticked" — it is a risk-weighted measure of posture, with a methodology behind it.
Watching it improve
The same weighting makes progress meaningful. When you remediate fundamental issues first, the score climbs faster than if you had cleared minor items — which is exactly the behaviour you want to encourage. Comparing two audits over time turns remediation work into a measurable trend.
Audit your Microsoft environment
Put this into practice. EntraGUARD runs 283 automated controls across Entra ID, Active Directory and Azure — try the free demo.
Download the free demo