Scoring¶
Results¶
| Result | Meaning | Counts toward the score? |
|---|---|---|
| Pass | The setting meets the requirement | Yes, full credit |
| Warn | Partly configured, or configured in a weaker way | Yes, half credit |
| Fail | The setting doesn't meet the requirement | Yes, no credit |
| Not evaluated (N/A) | Doesn't apply, or couldn't be checked (for example needs Entra ID P1) | No |
| Error | The check couldn't run, usually a permissions problem | No |
The score¶
Each check carries a severity weight:
| Severity | Weight |
|---|---|
| High | 3 |
| Medium | 2 |
| Low | 1 |
Score = points earned ÷ points possible, across the checks that count. A High-severity failure costs three times as much as a Low-severity one.
Only checks within the client's standards are scored. Changing a client's standards recalculates every score, including past scans, immediately.
Drift¶
A check drifts when it passed on the previous scan and fails or warns now. Drifted checks are flagged on the Fleet page and on the device page, and the score shows the change since the previous scan, for example 82% +4.
Overdue¶
A device is overdue when it hasn't reported in for 3 days. Its last results stay visible with a grey Overdue tag. See Troubleshooting.
Thresholds¶
Some checks use thresholds, such as minimum password length or maximum days since the last update. Defaults are listed on each check in the reference. They follow common benchmarks, and Trimtab can adjust them to match a client's policy.