Entra ID & IdentityHow-To & HardeningRetrospectives

How to Choose Between Security Defaults and Conditional Access

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2019, written in 2026 with the benefit of hindsight.

Entra ID offers two ways to enforce baseline identity security: Security Defaults (free, simple) and Conditional Access (requires Entra ID P1, flexible). Here is how to choose and how to switch safely.

Choose Security Defaults if

  • You don't have Entra ID P1 licenses (for example, Microsoft 365 Business Basic or Standard only).
  • You have a small, simple environment without service accounts signing in interactively.
  • You don't need exceptions for specific users or locations.

Choose Conditional Access if

  • You have Entra ID P1 or P2 (Microsoft 365 Business Premium, E3, E5).
  • You need different rules for admins, users, guests or devices.
  • You need exclusions (break-glass accounts, specific service accounts).
  • You want to require compliant devices, phishing-resistant MFA or risk-based policies.

Switching from Security Defaults to Conditional Access

You cannot use both at once. Switch carefully to avoid a gap:

  1. Create Conditional Access policies that replicate Security Defaults, at minimum:
  • Require MFA for administrators (phishing-resistant strength recommended).
  • Require MFA for all users.
  • Block legacy authentication.
  • Require MFA for Azure management.
  1. Set them to Report-only and review results.
  2. Disable Security Defaults and immediately switch the policies to On.
  3. Monitor sign-in logs for failures.

Microsoft's Conditional Access policy templates make step 1 quick.

Common mistakes

  • Turning off Security Defaults to fix one issue and creating no replacement policies.
  • Assuming per-user MFA settings are equivalent — they are a legacy approach Microsoft recommends migrating away from.
security defaults vs conditional accessSecurity Defaults2019

More on this story