Entra ID & IdentityPlatform ChangesRetrospectives

Secure Future Initiative and Microsoft-Managed Conditional Access Policies (Nov 2023)

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.

On November 2, 2023, Microsoft announced the Secure Future Initiative (SFI), a company-wide security commitment following a series of high-profile incidents, including Storm-0558. The same month, Microsoft began rolling out Microsoft-managed Conditional Access policies to customer tenants.

The Secure Future Initiative

SFI committed Microsoft to changes in how it builds and operates products, including:

  • Secure by default product settings.
  • Faster vulnerability response.
  • Stronger protection of identity infrastructure and signing keys (including moving key storage to hardware security modules and automated rotation).
  • Expanded security logging for customers by default.

In 2024, after the Midnight Blizzard breach and the CSRB report, Microsoft expanded SFI and said security would take priority over new features, tying executive compensation in part to security progress.

Microsoft-managed Conditional Access policies

Microsoft began automatically creating Conditional Access policies in eligible tenants, initially in report-only mode, with automatic enablement after a notice period unless administrators opted out. Early policies included:

  • MFA for admins accessing Microsoft admin portals.
  • MFA for per-user MFA users (to migrate from legacy per-user MFA).
  • MFA and reauthentication for risky sign-ins (for P2 tenants).

Later policies addressed areas such as blocking device code flow and legacy authentication in some tenants.

Why it mattered

Microsoft shifted from recommending protections to applying them by default. For tenants with weak configurations, it was an automatic security upgrade. For tenants with mature Conditional Access, it required review to avoid conflicts.

In hindsight

Managed policies, mandatory MFA for Azure portals and other default changes became Microsoft's main tools for raising the baseline. Administrators who ignored the notifications sometimes discovered new policies only when users were prompted.

microsoft managed conditional access policiesSFI & managed CA policies2023

More on this story