---
title: Microsoft Security Defaults for Office 365 Explained
description: Learn how Microsoft Security Defaults impact Office 365 admins and users through MFA prompts, login restrictions, and security updates.
image: https://blog.securesky.com/hubfs/Defult%20Security%20Blog%20Image.png
---

[![SecureSky](https://blog.securesky.com/hs-fs/hubfs/raw_assets/public/Securesky_March2022/images/SecureSkyLogo-01.png?width=500&height=500&name=SecureSkyLogo-01.png "SecureSky")](https://securesky.com/)

- [What We Do](https://securesky.com/security-services/) 
    - Assessment and Deployment Services 
          - [Cloud Security Assessment](https://securesky.com/security-services/cloud-security-assessment/)
          - [Application Security Assessment](https://securesky.com/security-services/application-security-architecture/)
          - [Penetration Testing](https://securesky.com/security-services/penetration-testing/)
          - [Application Architecture Services](https://securesky.com/security-services/application-architecture-services/)
          - [Microsoft Security (XDR) Deployment](https://securesky.com/security-services/microsoft-security-deployment/)
          - [Microsoft Sentinel (SIEM) Deployment](https://securesky.com/security-services/microsoft-sentinel/)
    - Security Posture Management (CSPM/SSPM) 
          - [Active Protection Platform Overview](https://securesky.com/cloud-security-posture-management/)
          - [Active Protection Platform Technology](https://securesky.com/security-services/active-protection-platform-technology/)
    - Managed XDR Services 
          - [Managed XDR Services Overview](https://securesky.com/security-services/microsoft-sentinel/#XDR)
          - [BEC/ATO Incident Response](https://securesky.com/security-services/business-email-compromise-response/)
- [About Us](https://securesky.com/about-us/) 
    - [Why SecureSky](https://securesky.com/about-us/)
    - [Leadership](https://securesky.com/leadership/)
    - [Careers](https://securesky.com/careers/)
    - [Partners](https://securesky.com/about-us/partners/)
- [Resources](https://securesky.com/resources/) 
    - [Recent News](https://securesky.com/securesky-news/)
    - [Datasheets](https://securesky.com/resources/datasheets/)
    - [eBooks](https://securesky.com/resources/ebooks/)
- [Blog](https://blog.securesky.com)
- [Contact Us](https://securesky.com/contact-us/)
- [Log In](https://portal.securesky.com/login)

- [What We Do](https://securesky.com/security-services/) 
    - Assessment and Deployment Services 
          - [Cloud Security Assessment](https://securesky.com/security-services/cloud-security-assessment/)
          - [Application Security Assessment](https://securesky.com/security-services/application-security-architecture/)
          - [Penetration Testing](https://securesky.com/security-services/penetration-testing/)
          - [Application Architecture Services](https://securesky.com/security-services/application-architecture-services/)
          - [Microsoft Security (XDR) Deployment](https://securesky.com/security-services/microsoft-security-deployment/)
          - [Microsoft Sentinel (SIEM) Deployment](https://securesky.com/security-services/microsoft-sentinel/)
    - Security Posture Management (CSPM/SSPM) 
          - [Active Protection Platform Overview](https://securesky.com/cloud-security-posture-management/)
          - [Active Protection Platform Technology](https://securesky.com/security-services/active-protection-platform-technology/)
    - Managed XDR Services 
          - [Managed XDR Services Overview](https://securesky.com/security-services/microsoft-sentinel/#XDR)
          - [BEC/ATO Incident Response](https://securesky.com/security-services/business-email-compromise-response/)
- [About Us](https://securesky.com/about-us/) 
    - [Why SecureSky](https://securesky.com/about-us/)
    - [Leadership](https://securesky.com/leadership/)
    - [Careers](https://securesky.com/careers/)
    - [Partners](https://securesky.com/about-us/partners/)
- [Resources](https://securesky.com/resources/) 
    - [Recent News](https://securesky.com/securesky-news/)
    - [Datasheets](https://securesky.com/resources/datasheets/)
    - [eBooks](https://securesky.com/resources/ebooks/)
- [Blog](https://blog.securesky.com)
- [Contact Us](https://securesky.com/contact-us/)
- [Log In](https://portal.securesky.com/login)

## SecureSky Insights

# Microsoft Security Defaults for Office 365 Explained

Apr 21, 2020

In the digital age, [Office 365 security](https://securesky.com/) and safeguarding your environment is paramount. This guide delves into the essential security controls necessary to protect against prevalent threats such as [Business Email Compromise (BEC), Account Takeover (ATO) attacks](https://securesky.com/security-services/business-email-compromise-response/), and unauthorized data access. With Microsoft's platform continually evolving, the strategies outlined here adhere to the most up-to-date best practices.

If you have created a new Office 365 tenant recently, or if you administer an Office 365 environment, you may have noticed a few changes. 

First – as you can see in the following screenshots, new tenants are created with ‘Security Defaults’ enabled: 

![O386 ‘Security Defaults’ Enabled Screen office 365 security](https://blog.securesky.com/hs-fs/hubfs/blob-2.png?width=600&name=blob-2.png)

Second, users of Azure Active Directory will see that some baseline conditional access policies have been deprecated and can no longer be used, as presented in the following screenshot: 

![Azure Active Directory](https://word-edit.officeapps.live.com/we/ResReader.ashx?v=00000000-0000-0000-0000-000000000014&n=E2o203656770.img&rndm=29431f21-ecbd-4528-810b-1e23d2bde9b6&WOPIsrc=https%3A%2F%2Fsecureskycom%2Esharepoint%2Ecom%2Fsites%2FPrivate%2F%5Fvti%5Fbin%2Fwopi%2Eashx%2Ffiles%2Fe70909ef6ffb4fc187283855cab8de1e&access_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6InhYbFQwSUp4MlZCVEJFeVFMdGtFOFY2ZkhwZyJ9.eyJhdWQiOiJ3b3BpL3NlY3VyZXNreWNvbS5zaGFyZXBvaW50LmNvbUAzYTQwM2VjNi0yNzQ0LTRjYjYtYWNiNi0yYWYxOTcyNWFhMGQiLCJpc3MiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAOTAxNDAxMjItODUxNi0xMWUxLThlZmYtNDkzMDQ5MjQwMTliIiwibmJmIjoiMTU4NzQ4OTM5MCIsImV4cCI6IjE1ODc1MjUzOTAiLCJuYW1laWQiOiIwIy5mfG1lbWJlcnNoaXB8Z25hcG90bmlrQHNlY3VyZXNreS5jb20iLCJuaWkiOiJtaWNyb3NvZnQuc2hhcmVwb2ludCIsImlzdXNlciI6InRydWUiLCJjYWNoZWtleSI6IjBoLmZ8bWVtYmVyc2hpcHwxMDAzMjAwMDNjYjE4YzE5QGxpdmUuY29tIiwic2lnbmluX3N0YXRlIjoiW1wia21zaVwiXSIsImlzbG9vcGJhY2siOiJUcnVlIiwiYXBwY3R4IjoiZTcwOTA5ZWY2ZmZiNGZjMTg3MjgzODU1Y2FiOGRlMWU7dlhqbUZlRWpsc2p4TTFaeTMxT2ZFVmlKQUUwPTtEZWZhdWx0OzsxQjAzQzQzMUFFRjtUcnVlOzs7MDthOWZlNGE5Zi04MDViLTAwMDAtNDc1NS00OGQ1MmYwNmEzYmUifQ.fE8MyosSiitHbYzyN-pl5n4jJxrPRJhVFZ9UcpkEU5NvqaDYHwHm7eyPicn_YHf2Bz4fnp7QqpXxhbSUJkk5iu5ySoCY9UaUhvkzFOHQJlhwWX5Ql6k9Vi9PdexBBlEP948De-pixRhS3x-VkmHnTKfiy_FzeuX0JuZuAKa6UQbhR6rpHgwUr43jTU21fGrqRQ7W_u1fXnz1QtjsHTD1SXWuGJ-GZAOpSqrNhcdByP29leKpPfVdH0favanOcoYqOptUlj6EQaTcH_Dn5KKxtbohI3n6kRuOiGoS1Z8UZWjrtJza83RcjBxghOv-ORnClBg9WTxJKG6J04_uiXCt3w&access_token_ttl=1587525391839&usid=58882a3a-ffad-4a80-9b2b-03cd9ea4bc05&build=16.0.12815.33700&waccluster=US7)

So – what are ‘Security Defaults’, and why are some legacy features being deprecated now? 

## ** Azure AD Security Evolution: Advancing with Security Defaults **

On January 9th, Microsoft took a significant step in bolstering Azure Active Directory (AAD) security by introducing Security Defaults. This initiative builds on the foundation laid in 2012 when Microsoft's Identity Protection team began setting stringent security standards for consumer accounts, including personal emails, Xbox, and Skype. These standards encompassed multi-factor authentication (MFA), access challenges upon detecting abnormal activity, and mandatory password resets following breach exposures.

The impact of these measures has been profound, leading to a sixfold reduction in account compromise rates. Remarkably, despite the growing user base, Microsoft accounts have never been more secure.

In 2014, Microsoft extended these advanced security technologies to Azure Active Directory organizational customers, demonstrating their effectiveness in the corporate realm. Microsoft's data reveals that implementing MFA and disabling legacy authentication could prevent over 99.9% of organizational account compromises. Furthermore, Google's research supports these findings, showing that account recovery measures, including MFA, can thwart up to 100% of automated bots, 99% of bulk phishing attacks, and 66% of targeted attacks (Source: [Google Security Blog](https://security.googleblog.com/2019/05/new-research-how-effective-is-basic.html)).

However, the challenge remains in the widespread adoption of these critical security controls. Despite Microsoft's concerted efforts to promote MFA, only about 9% of organizational users have encountered an MFA prompt, indicating a significant gap in the adoption of essential security measures.

At SecureSky, our observations mirror Microsoft's findings. Across various client sectors, we've noted a consistent lack of improvement in security postures, including challenges related to [manufacturing cybersecurity](https://securesky.com/manufacturing/), as evidenced by stagnant Secure Scores. This underscores the urgent need for organizations to embrace and implement the available security technologies to safeguard their digital environments effectively.

#### **CSP/MSP Secure Score Average**

**![CSP/MSP Secure Score Average](https://blog.securesky.com/hs-fs/hubfs/image-2.png?width=600&name=image-2.png)**

**Manufacturing Secure Score Average**

**![Manufacturing Secure Score Average](https://blog.securesky.com/hs-fs/hubfs/image-3.png?width=600&name=image-3.png)**

**Healthcare Secure Score Average**

**![Healthcare Secure Score Average office 365 security](https://blog.securesky.com/hubfs/image-4.png)**

 

**Security Defaults** 

Microsoft needed to take a different tack – to protect organizational accounts just like they do with consumer accounts. Security Defaults provide secure default settings that Microsoft manages on behalf of organizations to keep customers safe until they are ready to manage their own identity security. 

What are Security Defaults? To begin, Microsoft is doing the following:  

- Requiring all users and admins to register for MFA. 
- Challenging users with MFA - mostly when they show up on a new device or app, but more often for critical roles and tasks. 
- Disabling authentication from legacy authentication clients, which can’t do MFA. 

These controls are intended for organizations that are not configuring their own security. If you have configured security settings in your own environment, Microsoft isn’t going to jump in and change your settings – clients that are already using Conditional Access will not see Security Defaults implemented in their tenant. 

## **A Great Step Forward in Office 365 Security** 

SecureSky is happy to see Microsoft enforcing Multi-factor Authentication as part of Security Defaults. It is a critical control for securing Office 365 environments. 

The big question is will companies respond to Microsoft’s nudge to securely configure your O365 and Azure environment, hopefully, history isn’t an indicator. 

However, Multifactor Authentication is not a silver bullet. With the wider adoption of MFA, we anticipate seeing more attack techniques designed to circumvent it. Multi-factor Auth protects against password guessing or brute-force attacks and credential disclosure via data breaches. However, it is critical to remember that any authentication that relies on something the user knows and types in can be phished. Attacks against MFA include: 

**Man-in-the-middle frameworks** – There are several open source projects that exist to help attackers build infrastructure to sit between a victim and MFA websites, so that the attacker can steal all tokens and take over sessions. A screenshot of the Github repository for a popular framework is presented in the following screenshot: 

![Man in the middle frameworks  office 365 security](https://blog.securesky.com/hs-fs/hubfs/blob-3.png?width=600&name=blob-3.png)

MFA attack approaches include: 

**SMS Phishing attacks** – Social engineering of users  

**SIM Swap Attacks **– Social engineering of provider to change SIM/phone linkage 

**Compromised Endpoint Attacks** – Attack can steal session credentials and start second sessions. 

**Login Recovery Attacks **– Can bypass MFA to recover account, potentially change user settings. 

Attacks that use these techniques are often highly targeted. For example, a SIM swap attack was recently used to compromise the account of Twitter CEO Jack Dorsey and SMS. 

### **Going beyond MFA**![CIS Microsoft 365 Foundations Benchmark office 365 security](https://blog.securesky.com/hs-fs/hubfs/image-5.png?width=353&height=400&name=image-5.png)

While Default Security is a great first step by Microsoft, organizations must take it upon themselves to extend the security controls implemented in their cloud environments.

- Organizations must properly configure and harden their entire O365 environment. Recommendations of key settings to implement in Office 365 environment are presented in the following [SecureSky blog posts](https://blog.securesky.com/the-unassuming-threat-business-e-mail-compromise-office-365-vulnerabilities-part-1-of-6). Additionally, we recommend that organizations evaluate the comprehensive controls provided in the Center for Internet [Security Microsoft 365 Foundations Benchmark](https://www.cisecurity.org/benchmark/microsoft_office), to which SecureSky contributes.

- Enablement of effective [detection capabilities in O365](https://securesky.com/security-services/microsoft-security-deployment/), as well as timely monitoring and analysis of detected threat events.

As always if you have more questions about Microsoft Security Defaults please feel free to reach out to us any time. [info@securesky.com](mailto:info@securesky.com)

### Frequently Asked Questions 

 What are Microsoft Security Defaults in Office 365?

 Microsoft Security Defaults are built-in security settings that help protect Office 365 and Azure Active Directory accounts by enabling MFA, blocking legacy authentication, and improving login security.

 Why is Microsoft enforcing Multi-Factor Authentication (MFA)?

 Microsoft enforces MFA to reduce risks from password attacks, phishing, and account takeovers. MFA adds an extra verification step that makes unauthorized access much harder.

 How do Security Defaults affect Office 365 administrators and users?

 Security Defaults can require users to register for MFA, trigger additional login verification prompts, and block older apps or devices that use legacy authentication.

 Can Security Defaults prevent all cyberattacks on Office 365 accounts?

 No. While Security Defaults and MFA greatly improve security, advanced attacks like phishing, SIM swap attacks, and session hijacking can still bypass some protections.

 What should organizations do beyond enabling Security Defaults?

 Organizations should strengthen their Office 365 environment with Conditional Access policies, monitoring tools, threat detection, endpoint security, and regular security reviews.

 

 

 

- [What We Do](https://securesky.com/security-services/) 
    - Assessment and Deployment Services 
          - [Cloud Security Assessment](https://securesky.com/security-services/cloud-security-assessment/)
          - [Application Security Assessment](https://securesky.com/security-services/application-security-architecture/)
          - [Penetration Testing](https://securesky.com/security-services/penetration-testing/)
          - [Application Architecture Services](https://securesky.com/security-services/application-architecture-services/)
          - [Microsoft Security Deployment](https://securesky.com/security-services/microsoft-security-deployment/)
          - [Microsoft Sentinel Deployment](https://securesky.com/security-services/microsoft-sentinel/)
    - Security Posture Management (CSPM/SSPM) 
          - [Active Protection Platform Overview](https://securesky.com/cloud-security-posture-management/)
          - [Active Protection Platform Technology](https://securesky.com/security-services/active-protection-platform-technology/)
    - eXtended Detection and Response (XDR) Services 
          - [eXtended Detection and Response Overview](https://securesky.com/security-services/microsoft-sentinel/)
          - [BEC/ATO Incident Response](https://securesky.com/security-services/business-email-compromise-response/)
- [About Us](https://securesky.com/about-us/) 
    - [Why SecureSky](https://securesky.com/about-us/)
    - [Leadership](https://securesky.com/leadership/)
    - [Careers](https://securesky.com/careers/)
    - [Partners](https://securesky.com/about-us/partners/)
- [Resources](https://securesky.com/resources/) 
    - [Recent News](https://securesky.com/securesky-news/)
    - [Datasheets](https://securesky.com/resources/datasheets/)
    - [eBooks](https://securesky.com/resources/ebooks/)
- [Blog](https://blog.securesky.com)
- [Contact Us](https://securesky.com/contact-us/)
- [Log In](https://portal.securesky.com/login)

©2018-2026 SecureSky, Inc. All rights reserved. SafetyNET, SecureSky, AdaptiveDefender and the SecureSky logo are marks of SecureSky, Inc. SecureSky U.S. Patent Nos. 8,347,391; 8,856,324; 9,021,574; 9,350,707; 9,787,713; 9,888,018; 10,015,239. Additional patents pending. Azure and Office 365 are registered trademarks of Microsoft.

[Privacy Policy](https://securesky.com/privacy-policy/)   [Website Terms of Use](https://securesky.com/website-terms-of-use/)

- <https://x.com/securesky>
- <https://www.linkedin.com/company/securesky>

![](https://px.ads.linkedin.com/collect/?pid=4331593&fmt=gif)

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Microsoft Security Defaults are built-in security settings that help protect Office 365 and Azure Active Directory accounts by enabling MFA, blocking legacy authentication, and improving login security."
    },
    "name" : "What are Microsoft Security Defaults in Office 365?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Microsoft enforces MFA to reduce risks from password attacks, phishing, and account takeovers. MFA adds an extra verification step that makes unauthorized access much harder."
    },
    "name" : "Why is Microsoft enforcing Multi-Factor Authentication (MFA)?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Security Defaults can require users to register for MFA, trigger additional login verification prompts, and block older apps or devices that use legacy authentication."
    },
    "name" : "How do Security Defaults affect Office 365 administrators and users?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. While Security Defaults and MFA greatly improve security, advanced attacks like phishing, SIM swap attacks, and session hijacking can still bypass some protections."
    },
    "name" : "Can Security Defaults prevent all cyberattacks on Office 365 accounts?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Organizations should strengthen their Office 365 environment with Conditional Access policies, monitoring tools, threat detection, endpoint security, and regular security reviews."
    },
    "name" : "What should organizations do beyond enabling Security Defaults?"
  } ]
}
```