CLASSIC SECURE SCORE STILL SHOWS A DEPRECATED RECOMMENDATION

Raja P 20 Reputation points
2026-09-09T10:59:13.81+00:00

CLASSIC SECURE SCORE STILL SHOWS A DEPRECATED RECOMMENDATION | Why does Classic Secure Score still show unhealthy resources after a grouped recommendation was deprecated?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

Answer accepted by question author
Givary-MSFT 35,916 Reputation points Microsoft Employee Moderator
2026-09-09T11:10:55.36+00:00

@Raja P

This behavior can occur as part of Microsoft Defender for Cloud's transition from legacy grouped recommendations to individual recommendations.

During this transition, some Classic Secure Score controls can continue to receive posture signals from assessments that are now represented through individual recommendations. This can result in the following behavior:

- Classic Secure Score shows unhealthy resources.

- The previous grouped recommendation is no longer visible.

- The visible recommendations appear completed.

- The control does not receive its expected full score.

Before the transition, a grouped recommendation combined multiple security findings and affected resources into one broad recommendation. Microsoft completed the retirement of these grouped recommendations on July 31, 2026. The findings are now represented as more granular individual recommendations.

During this transition, the Classic Secure Score can still receive scoring information associated with a retired grouped assessment, even though that grouped recommendation is no longer displayed in the Classic recommendations list. As a result, every recommendation currently visible under a Classic control might show as completed while the control still doesn’t award its full potential score.

In simple terms, Classic view might no longer display the complete explanation for every point being deducted. The unresolved findings have moved to the individual-recommendation model and should be reviewed in Risk view.

What should customers do?

  1. Open Microsoft Defender for Cloud > Recommendations.
  2. Switch from Classic view to Risk view.
  3. Locate the individual recommendations related to the affected Secure Score control.
  4. Review the affected resources and remediate or formally exempt the applicable findings.
  5. Allow time for the findings and score to be recalculated.
  6. When comparing scores, use the same subscription or management-group scope and the same portal experience.

An increase in recommendation count after switching to Risk view doesn’t necessarily mean that the environment became less secure. One legacy grouped recommendation might now be represented by multiple individual findings, each showing a specific affected resource, risk, and remediation action.

Classic Secure Score Vs Cloud Secure Score

Customers should also be aware that Microsoft currently provides two different cloud scoring experiences:

• Classic Secure Score is available in the Azure portal.

• Risk-based Cloud Secure Score is available in the Microsoft Defender portal.

These models use different calculations and can show different percentages. For audit purposes, confirm which model the auditor expects and consistently record:

• The portal and scoring model used

• The subscription or management-group scope

• The reporting date and time

• The included Azure, AWS, and GCP environments

• Any approved exemptions

Reference:

https://learn.microsoft.com/en-us/azure/defender-for-cloud/transition-grouped-individual-recommendations#classic-secure-score-behavior-after-the-transition

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Newest
  1. AI answer

    2026-09-09T10:59:26.0966667+00:00

    Yes. This is expected behavior in some cases.

    After the transition from grouped recommendations to individual recommendations, the classic Secure Score in the Azure portal can still show a resource as unhealthy under a control even when the old grouped recommendation is no longer visible. The underlying reason is that the resource now has associated security findings represented through the individual recommendations model.

    What to do:

    1. In Microsoft Defender for Cloud, open Recommendations.
    2. Switch to Risk view. This is the recommended view to investigate the underlying findings.
    3. Review the current individual recommendations that now represent that deprecated grouped recommendation.
    4. If needed, filter by the relevant recommendation category such as:
      • SoftwareUpdate
      • SystemUpdate
      • HostMisconfigurations
      • ExposedSecrets
      • CodeVulnerabilities
      • IacVulnerabilities
      • ApiVulnerabilities

    Key points:

    • The classic Secure Score was kept functionally stable during the transition.
    • Recommendation volume can increase because individual findings are more granular and actionable.
    • An unhealthy classic control does not necessarily mean the deprecated recommendation is still active; it can reflect the newer individual findings instead.
    • The classic view is still available in the Azure portal under Microsoft Defender for Cloud > Recommendations > Switch to classic view.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.