CIO Brief: The Free Setting That Blocks Most Identity Attacks
Retrospective: this article looks back at events from October 2019, written in 2026 with the benefit of hindsight.
The short version: In 2019, Microsoft released Security Defaults: a free, one-click setting that turns on multi-factor authentication and blocks older, risky sign-in methods. It stops the large majority of account takeover attempts — and many small and mid-sized companies still don't use it or anything stronger.
Why this is the cheapest security win available
Security Defaults costs nothing beyond the Microsoft 365 subscription you already pay for. It protects every account with a second sign-in step and closes the back doors attackers use to get around it.
Why companies turn it off
Usually to fix a problem: an old app that stopped working, an executive who disliked the prompts, a scanner that couldn't send email. Sometimes it was replaced with something better. Often it was replaced with nothing.
Questions to ask your team
- Is Security Defaults enabled, or do we have Conditional Access policies that do the same job or better?
- If neither, why not, and when was it turned off?
- Are any users or service accounts excluded from multi-factor authentication?
What good looks like
Either Security Defaults enabled, or Conditional Access policies that require MFA for everyone and block legacy sign-in methods — with a short, documented list of exceptions.
The decision
Ask for a yes-or-no answer: "Does every account in our tenant require multi-factor authentication?" If it isn't an unqualified yes, fix it this month.
- Azure AD Security Defaults Arrive (Oct 2019): Free Baseline Protection for Every Tenant Platform Changes
- How to Choose Between Security Defaults and Conditional Access How-To & Hardening
- Security Defaults Rollout Checklist and User Communication Template How-To & Hardening