Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: The Free Setting That Blocks Most Identity Attacks

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2019, written in 2026 with the benefit of hindsight.

The short version: In 2019, Microsoft released Security Defaults: a free, one-click setting that turns on multi-factor authentication and blocks older, risky sign-in methods. It stops the large majority of account takeover attempts — and many small and mid-sized companies still don't use it or anything stronger.

Why this is the cheapest security win available

Security Defaults costs nothing beyond the Microsoft 365 subscription you already pay for. It protects every account with a second sign-in step and closes the back doors attackers use to get around it.

Why companies turn it off

Usually to fix a problem: an old app that stopped working, an executive who disliked the prompts, a scanner that couldn't send email. Sometimes it was replaced with something better. Often it was replaced with nothing.

Questions to ask your team

  • Is Security Defaults enabled, or do we have Conditional Access policies that do the same job or better?
  • If neither, why not, and when was it turned off?
  • Are any users or service accounts excluded from multi-factor authentication?

What good looks like

Either Security Defaults enabled, or Conditional Access policies that require MFA for everyone and block legacy sign-in methods — with a short, documented list of exceptions.

The decision

Ask for a yes-or-no answer: "Does every account in our tenant require multi-factor authentication?" If it isn't an unqualified yes, fix it this month.

azure ad security defaults impactSecurity Defaults2019

More on this story