FREE STUDY NOTES · SC-300

Security defaults vs per-user MFA vs Conditional Access

The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.

From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)

There are three ways to turn on MFA across a tenant. Choosing between them depends on licensing and how much control you need.

Security defaults Per-user MFA Conditional Access
Licence None (any tenant) Included with Office 365 / Microsoft 365 plans Microsoft Entra ID P1 (P2 for risk conditions)
Customisation On or off only Per-user state, few exceptions Fully customisable
Exclude users No Yes Yes
FIDO2, Windows Hello for Business, hardware tokens No Yes Yes
Location and device conditions, report-only No No Yes
New users protected automatically Yes No Yes
Where Entra ID > Overview > Properties > Manage security defaults Users > Per-user MFA Conditional Access

Security defaults

Security defaults are aimed at Free tenants. They’re turned on for new tenants, with a 24-hour grace period before enforcement, and the least-privileged role to change them is Conditional Access Administrator. When enabled they:

Users register Microsoft Authenticator with notifications (or any OATH TOTP app). The Directory Synchronization Accounts role is excluded. To move to Conditional Access, disable security defaults first, then turn on equivalent policies (Microsoft-managed policies exist for this). After enabling security defaults, revoke existing tokens with Revoke-MgUserSignInSession so signed-in users have to register.

Common trap: Creating Conditional Access policies while security defaults are still on - an organisation that replaces security defaults with Conditional Access must disable security defaults. The two aren’t designed to run side by side.

Per-user MFA

Per-user MFA has three states: Disabled (the default), Enabled (enrolled; legacy authentication still works until registration) and Enforced (MFA required; legacy apps need app passwords). Enabled users move to Enforced automatically when they register. Manage states at Users > All users > Per-user MFA (Authentication Policy Administrator), or through the Graph perUserMfaState property. Microsoft’s guidance is clear: don’t enable or enforce per-user MFA if you use Conditional Access. Users protected by Conditional Access or security defaults correctly show as Disabled.

Legacy MFA service settings

The service settings page (Multifactor authentication > Additional cloud-based MFA settings) is a legacy portal that still holds:

Report suspicious activity

Report suspicious activity replaced Fraud alert, Block/unblock users and notifications. The legacy features were removed on 1 March 2025. Enable it at Authentication methods > Settings (Authentication Policy Administrator). Its Microsoft managed state is currently disabled, so it must be set to Enabled. A user who reports a prompt is set to high user risk (detection type User Reported Suspicious Activity). With P2, risk-based Conditional Access can then block the user or require remediation. With P1, admins work from the risk detections report and the sign-in and audit logs, or automate through Microsoft Graph.

SMS and voice: passkeys by default

Microsoft is moving users from telephony to passkeys:

Date Change
1 September 2026 Users enabled for SMS or voice were auto-enabled for passkeys and nudged to register (the registration campaign moved to Microsoft managed). A temporary opt-out (passkeyDynamicMigration) runs until 1 February 2027
30 October 2026 Configuration of your own telephony provider (Microsoft Security Store) becomes available
1 February 2027 Microsoft-provided SMS and voice retired for all users except Global Administrators and external users (internal guests are included). Users whose only MFA method is SMS or voice must register a passkey to continue
1 July 2027 Retired for Global Administrators and external users

The retirement covers SSPR too. A telephony provider can keep SMS and voice going for MFA, but not SMS as a primary sign-in method. Custom voice messages for voice calls were retired on 28 February 2026.

Get the whole book

This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-300 terms in the glossary · All SC-300 study notes

More SC-300 study notes