Which Defender Service Includes Microsoft Secure Score for Devices?

Answer Correct answer: B — Microsoft Secure Score for Devices is included with Microsoft Defender for Endpoint, surfacing in the Defender Vulnerability Management dashboard.

Which service includes Microsoft Secure Score for Devices?

  1. Microsoft Defender for IoT
  2. Microsoft Defender for Endpoint Correct Answer
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Office 365

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you can separate the tenant-wide Microsoft Secure Score from the device-scoped Secure Score for Devices, which belongs to Defender for Endpoint — the trap is assuming any Defender-branded workload shows it.

Microsoft Secure Score for Devices is a device-level security configuration metric that ships with Microsoft Defender for Endpoint and appears in the Defender Vulnerability Management dashboard. This page confirms option B and explains why the other Defender workloads do not expose it.

Choosing Microsoft Defender for Identity (C) or Defender for Office 365 (D) because they also surface recommendations in the Microsoft Defender portal; those workloads do not host Secure Score for Devices.

Community Discussion (4 comments)

KindFlame 👍 1 Selected: B
Microsoft Defender for Endpoint
TechyStacy 👍 1 Selected: B
Microsoft Defender for Endpoint
LegendaryZA 👍 2 Selected: B
Answer: Microsoft Defender for Endpoint
chiliman 👍 2 Selected: B
Microsoft Secure Score for Devices is included as part of Microsoft Defender Vulnerability Management. Specifically, it is visible in the Defender Vulnerability Management dashboard of the Microsoft Defender portal. This feature is designed to reflect the collective security configuration state of your devices and is applicable to services such as Microsoft Defender for Endpoint Plan 2, Microsoft Defender XDR, and **Microsoft Defender for Servers Plan 1 & 2

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Secure Score for Devices is a device-focused measure of how well your endpoints are hardened, and it is delivered as part of Microsoft Defender for Endpoint's vulnerability management capability (now Defender Vulnerability Management). The score is visible in the Defender Vulnerability Management dashboard inside the Microsoft Defender portal and rolls up the configuration state of onboarded devices. Because the metric depends on device onboarding, telemetry and vulnerability data that only Defender for Endpoint collects, no other Defender workload can produce it. The SC-900 objective of mapping security capabilities to the right Defender service therefore points squarely at option B.

Why the Other Options Are Wrong

Microsoft Defender for IoT (A) secures operational technology and unmanaged IoT/OT devices and reports through its own inventory and alert views, not Secure Score for Devices. Microsoft Defender for Identity (C) monitors on-premises Active Directory signals such as lateral movement and recon, and it contributes to the overall Microsoft Secure Score but never to the device-level score. Microsoft Defender for Office 365 (D) protects email, Teams and collaboration workloads with its own threat and configuration posture, again without a device vulnerability score. Only Defender for Endpoint combines endpoint onboarding, vulnerability management and the device hardening recommendations that feed Secure Score for Devices.

Community Comment Notes

Consensus on the page is unanimous at 100% for option B, and no commenter argues for the other three workloads. LegendaryZA, KindFlame and TechyStacy simply record "Microsoft Defender for Endpoint" as their pick, which matches the official mapping. chiliman adds useful nuance, stating that Microsoft Secure Score for Devices is "included as part of Microsoft Defender Vulnerability Management" and is viewed in the Defender Vulnerability Management dashboard of the Microsoft Defender portal, tied to Defender for Endpoint Plan 2 onboarding. That detail is worth remembering: on SC-900, the phrase "for Devices" is the signal that points to the endpoint workload.

Official Reference

Exam Strategy

Read the qualifier before the product name: "for Devices" narrows the answer to the endpoint workload, while "for Identity", "for Office 365" and "for IoT" describe identities, collaboration and OT devices respectively. If you can recall which workload owns device onboarding and vulnerability data, this becomes a near-instant pick.

Frequently Asked Questions

Why is Microsoft Secure Score for Devices not part of Defender for Identity?

Defender for Identity monitors Active Directory and identity signals, so it has no device onboarding or vulnerability data to compute a device hardening score.

Is Secure Score for Devices the same as the overall Microsoft Secure Score?

No. The overall Microsoft Secure Score aggregates tenant-wide recommendations across services, while Secure Score for Devices is scoped to device configuration and lives in Defender for Endpoint.

Related Analysis

Practice All SC-900 Questions

Access 141 questions with complete answers and detailed explanations.

View Full SC-900 Practice Test →

← Back to SC-900 Study Guide