Security Defaults Rollout Checklist and User Communication Template
Retrospective: this article looks back at events from October 2019, written in 2026 with the benefit of hindsight.
Use this checklist to enable Security Defaults with minimal disruption, especially for smaller organizations.
Before enabling
- Confirm no Conditional Access policies are in use (Security Defaults and Conditional Access are mutually exclusive).
- Identify service accounts and shared mailboxes that sign in interactively; plan alternatives.
- Identify apps or devices using legacy authentication; plan migration.
- Confirm administrators know they will be prompted for MFA every sign-in.
User communication template
Subject: Extra sign-in protection starts [date]
To protect your account and our company data, we are turning on multi-factor authentication. Starting [date], you will be asked to set up the Microsoft Authenticator app the next time you sign in. It takes about five minutes. You'll occasionally approve sign-ins on your phone. If you need help, contact [help desk details]. Thank you for helping keep our company safe.
Enable
- In the Entra admin center: Overview → Properties → Manage security defaults → Enabled.
- Users have 14 days to register for MFA after their first prompted sign-in.
After enabling
- Monitor help desk calls and sign-in failures for two weeks.
- Confirm legacy authentication sign-ins are failing as expected.
- Check MFA registration progress in the authentication methods registration report.
Plan the next step
- When you acquire Entra ID P1 (for example through Microsoft 365 Business Premium), plan migration to Conditional Access for more control.