How to Choose Between Security Defaults and Conditional Access
Retrospective: this article looks back at events from October 2019, written in 2026 with the benefit of hindsight.
Entra ID offers two ways to enforce baseline identity security: Security Defaults (free, simple) and Conditional Access (requires Entra ID P1, flexible). Here is how to choose and how to switch safely.
Choose Security Defaults if
- You don't have Entra ID P1 licenses (for example, Microsoft 365 Business Basic or Standard only).
- You have a small, simple environment without service accounts signing in interactively.
- You don't need exceptions for specific users or locations.
Choose Conditional Access if
- You have Entra ID P1 or P2 (Microsoft 365 Business Premium, E3, E5).
- You need different rules for admins, users, guests or devices.
- You need exclusions (break-glass accounts, specific service accounts).
- You want to require compliant devices, phishing-resistant MFA or risk-based policies.
Switching from Security Defaults to Conditional Access
You cannot use both at once. Switch carefully to avoid a gap:
- Create Conditional Access policies that replicate Security Defaults, at minimum:
- Require MFA for administrators (phishing-resistant strength recommended).
- Require MFA for all users.
- Block legacy authentication.
- Require MFA for Azure management.
- Set them to Report-only and review results.
- Disable Security Defaults and immediately switch the policies to On.
- Monitor sign-in logs for failures.
Microsoft's Conditional Access policy templates make step 1 quick.
Common mistakes
- Turning off Security Defaults to fix one issue and creating no replacement policies.
- Assuming per-user MFA settings are equivalent — they are a legacy approach Microsoft recommends migrating away from.