Microsoft certification badges banner
Headshot of Michael Korting

Blog

Microsoft 365 • Security • Compliance

Microsoft Purview Compliance Manager: Why Improving Your Compliance Score Is a Journey, Not a Checkbox

Practical lessons for assigning improvement actions, documenting evidence, validating controls, and building a sustainable compliance program.

The Reality of Compliance Manager

When many administrators first open Microsoft Purview Compliance Manager, they immediately focus on the Compliance Score. The dashboard displays a percentage, highlights areas needing attention, and provides recommended improvement actions.

The natural instinct is to ask:

After spending time working through Compliance Manager, however, most organizations discover the same thing:

Microsoft Purview Compliance Manager is not simply another dashboard. It is a governance and evidence-management platform designed to help organizations implement, document, validate, and continuously maintain compliance controls. Microsoft states that the Compliance Score measures progress toward completing improvement actions, but it should not be interpreted as a guarantee of regulatory compliance.

Understanding the Compliance Score

The Compliance Score is built from several types of improvement actions:

  • Microsoft-managed controls
  • Technical customer-managed controls
  • Non-technical customer-managed controls

Microsoft-managed actions can contribute points for controls operated within Microsoft cloud services. Organizations earn points for the controls they own by implementing and validating those controls.

This explains why an organization may initially see a score containing Microsoft-managed points while customer-managed improvement actions remain incomplete.

I have seen environments where much of the existing score came from Microsoft-managed responsibilities while hundreds of customer-owned improvement actions remained outstanding. That is the moment when the dashboard becomes a project plan.

The Compliance Manager Workflow

One aspect administrators often underestimate is the workflow required for each improvement action.

  1. Review the improvement action.
  2. Assign ownership.
  3. Investigate the requirements.
  4. Implement the control.
  5. Upload evidence or add supporting links and notes.
  6. Update the implementation status.
  7. Perform or review testing.
  8. Record the testing result.
  9. Monitor the control for ongoing compliance.

This means compliance improvements frequently involve multiple teams, including Security, Microsoft 365 Administration, Legal, Human Resources, Risk Management, Audit, and Executive Leadership.

The technical change may be only one part of the overall effort. Ownership, policies, evidence, approval, and testing can require considerably more coordination.

Why Compliance Projects Become Long-Term Initiatives

Organizations often expect compliance improvement to resemble Secure Score remediation:

  • Enable a setting.
  • Earn points.
  • Move to the next recommendation.

Compliance Manager is different. Many controls require work in three broad areas.

Policy Development

Examples may include acceptable use policies, data retention policies, incident response procedures, and privacy policies.

Evidence Collection

Supporting evidence may include screenshots, training records, policy documents, procedure documentation, audit reports, or links to authoritative internal records.

Ongoing Validation

Compliance is not a one-time achievement. Controls may need to be reviewed, tested, and maintained to demonstrate that they remain effective.

The Difference Between Secure Score and Compliance Score

Many Microsoft 365 professionals are familiar with Microsoft Secure Score and assume Compliance Manager functions the same way. While both use scoring systems, their goals are different.

Microsoft Secure Score

  • Security configurations
  • Identity protection
  • Endpoint security
  • Threat protection
  • Access controls

Compliance Score

  • Governance
  • Documentation
  • Risk management
  • Regulatory requirements
  • Operational controls
  • Evidence collection

A Secure Score recommendation may be addressed through a configuration change. A Compliance Manager improvement action may also require stakeholders, policy approval, formal documentation, evidence, and testing before the organization considers the control complete.

Start with High-Value Improvements

One mistake organizations make is trying to complete every improvement action immediately. A more sustainable approach is to prioritize deliberately.

Quick Wins

  • Actions that are already implemented but not documented
  • Actions that need evidence attached
  • Actions that require an ownership or status update
  • Actions supported by automatic testing

High-Impact Actions

Prioritize actions that materially reduce risk and support the organization’s compliance objectives, rather than chasing points without considering business relevance.

Regulatory Relevance

Not every framework applies to every organization. Concentrate on assessments, regulations, and internal obligations that reflect the organization’s industry, contracts, risk profile, and legal requirements.

Building a Compliance Program

The strongest Compliance Manager projects treat the platform as a compliance operating system rather than a scorecard.

  • ✅ Assign control owners.
  • ✅ Establish recurring review cycles.
  • ✅ Define evidence collection standards.
  • ✅ Create policy management processes.
  • ✅ Track exceptions and compensating controls.
  • ✅ Monitor assessment changes.
  • ✅ Periodically retest controls.

This transforms Compliance Manager from a dashboard into an active governance platform.

Final Thoughts

After working through improvement actions for the first time, many administrators reach the same conclusion:

They are usually right.

Microsoft Purview Compliance Manager requires ownership, evidence, testing, and ongoing validation because compliance is ultimately about demonstrating that controls exist and are operating effectively.

The Compliance Score provides a roadmap, but the true value of Compliance Manager is not simply achieving a higher percentage. The real value comes from creating repeatable governance processes that help an organization understand, document, validate, and continuously improve its compliance posture.

A higher score is the byproduct of a more mature compliance program.

References