Back to Blog
Microsoft 365 Cybersecurity

Microsoft 365 Security Defaults: What SMBs Need to Know

✍️ Eugene Moore · 📅 October 9, 2026 · ⏱ 6 min read

If you run Microsoft 365, your tenant has a set of baseline controls called Security Defaults — and there's a good chance nobody at your company has ever deliberately reviewed them.

Microsoft introduced Security Defaults in 2019 to give organizations a baseline without configuring everything from scratch. Newer tenants get them switched on automatically. Older tenants often don't — and plenty of businesses have quietly switched them off. They're free, they're built in, and for a business that has done nothing else, they're better than nothing.

But they're not the same as a real security configuration. Here's what you need to know.

What Security Defaults Actually Do

When Security Defaults are on, Microsoft enforces the following across your tenant:

🔒

MFA registration for all users

Every user must register for multi-factor authentication and is prompted for it when sign-ins look risky or come from a new device.

🛡️

MFA for admins, every time

Admin accounts must use MFA on every sign-in. They're the highest-value target in your tenant.

🚫

Legacy authentication blocked

Older protocols (basic auth, IMAP, POP3) that can't do MFA are blocked — closing one of the most common attack paths.

⚠️

Privileged actions protected

High-risk actions, like accessing Azure management portals, require MFA even mid-session.

That's a meaningful baseline. Blocking legacy authentication alone shuts down a large category of password-spraying and credential-stuffing attacks.

The Catch: What Security Defaults Don't Cover

Security Defaults are a floor, not a ceiling. Here's what they leave open:

1

No Conditional Access controls

Security Defaults are all-or-nothing. They can't say "require MFA off-network but not in the office" or "block sign-ins from countries we don't operate in." That's Conditional Access, which requires Microsoft Entra ID P1 or higher.

2

No device compliance requirements

They don't care whether the device signing in is managed or personal, patched or years out of date. Intune enrollment and compliance policies are a separate layer.

3

No risky sign-in detection

A sign-in from an unusual location or a flagged IP isn't automatically blocked. Identity Protection requires Entra ID P2.

4

No alerting

Nothing notifies you when something suspicious happens. You need Defender for Office 365, an MDR service, or a SIEM for that visibility.

5

No protection once an account is compromised

An attacker who gets past authentication — through token theft, for example — has everything that account can reach. Data loss prevention and session controls are separate.

Why Some Businesses Have Turned Them Off

⚠️ Common mistake

Security Defaults and Conditional Access can't run at the same time. Moving to Conditional Access means disabling Security Defaults first — and some businesses disable them without ever finishing the Conditional Access setup. That leaves them with nothing.

We've also seen Security Defaults turned off because an older CRM, a scanner, or a legacy email client stopped working once legacy authentication was blocked. The right fix is to modernize those applications. The wrong fix is to switch off the control and forget about it.

Security Defaults vs. Conditional Access

If your licensing includes Entra ID P1 — Microsoft 365 Business Premium, E3, or higher — you should be using Conditional Access policies instead of Security Defaults. Conditional Access gives you:

  • Per-user, per-group, and per-app control over when MFA is required
  • Location-based rules for trusted networks vs. unknown locations
  • Device compliance requirements — managed and patched devices only
  • Sign-in risk policies that respond to unusual behavior
  • Narrow, documented exceptions instead of all-or-nothing

If you're on Business Basic or Business Standard, which don't include Entra ID P1, Security Defaults are the right choice — and you should confirm they're still on.

Quick check

In the Microsoft Entra admin center, go to Identity → Overview → Properties → Manage security defaults. If they're off, confirm that Conditional Access policies are actually enabled — not sitting in report-only mode.

What a Properly Configured Tenant Looks Like

Beyond Security Defaults or Conditional Access, a hardened Microsoft 365 environment for a small business typically includes:

  • MFA through an authenticator app, not SMS
  • Separate admin accounts with no mailbox and no day-to-day use
  • Anti-phishing, Safe Links, and Safe Attachments configured in Defender
  • External email warning banners
  • Unified audit logging enabled and retained
  • Automatic external forwarding blocked at the tenant level
  • SPF, DKIM, and DMARC configured on your domain

None of these come configured out of the box. In our experience reviewing small business tenants across Connecticut and New York, most are missing at least half of them.

Free Microsoft 365 Tenant Review

We'll go through your tenant setting by setting and tell you what's protected, what's exposed, and what to fix first — without selling you anything you don't need.

DM us "M365" on LinkedIn or schedule a free consultation · (646) 791-2137

← Managed IT vs. In-House IT Vendor Risk Management →
Free M365 Tenant Review

Is your Microsoft 365 tenant actually configured?

We'll review your tenant configuration and show you exactly what's protected and what's exposed — before an attacker finds it first.