RUBELLSERVICES LLC
All articles

Security

MFA for small businesses: security defaults or Conditional Access?

Both turn on multifactor authentication in Microsoft 365. Here’s how they differ, what each one costs, and how to choose the right one for your business.

Stolen and guessed passwords are still one of the most common ways attackers get into a business. Multifactor authentication (MFA) is the single most effective fix: even when someone has the password, they also need the second factor on the user’s phone or security key. Microsoft’s own research has found that MFA stops the vast majority of account-compromise attacks.

If your business runs on Microsoft 365, there are two ways to require MFA: security defaults and Conditional Access. They both work, but they suit different businesses.

Option 1: Security defaults

Security defaults are a free, preconfigured set of protections included with every Microsoft 365 tenant. They’re turned on automatically for tenants created since late 2019, but older tenants, and tenants where someone switched them off, may not have them.

With security defaults on, Microsoft Entra ID:

  • Requires every user to register for MFA, usually with the Microsoft Authenticator app.
  • Requires administrators to complete MFA when they sign in.
  • Prompts other users for MFA when a sign-in looks unusual or risky.
  • Blocks legacy authentication, the older email protocols that can’t do MFA and that attackers love to use for password guessing.

The trade-off is that it’s all or nothing. You can’t exclude an account, create exceptions for a particular location, or require a managed device. For many small businesses, that’s perfectly fine.

To check whether security defaults are on, sign in to the Microsoft Entra admin center, open Overview, select Properties, and then Manage security defaults.

Option 2: Conditional Access

Conditional Access lets you write your own if-then rules: if this person signs in to this app, from this place, on this device, then require MFA, require a company-managed device, or block the sign-in. It requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium and the Enterprise E3 and E5 plans.

Common policies for a small business include:

  • Require MFA for all users on all cloud apps.
  • Block legacy authentication.
  • Require stronger, phishing-resistant MFA (passkeys or security keys) for administrators.
  • Allow access to company data only from devices managed and checked by Intune.
  • Block sign-ins from countries where you don’t do business.

One thing to know: the two options don’t mix. You have to turn security defaults off before your Conditional Access policies can take over, so build and test your policies first.

Which one is right for you?

A simple rule of thumb:

  • On Business Basic or Business Standard, with no special requirements? Make sure security defaults are on, and make sure everyone has actually registered.
  • On Business Premium, or need exceptions, device rules, or location rules? Use Conditional Access. You’re already paying for it, and it gives you far more control.

The worst option is neither. If you’ve turned security defaults off and haven’t replaced them with Conditional Access, your accounts may have no MFA requirement at all.

Rolling out Conditional Access safely

Conditional Access is powerful enough to lock everyone out, including you. A careful rollout looks like this:

  1. Create two emergency access accounts that are excluded from your policies, with long, unique passwords stored somewhere safe. These are your way back in if a policy goes wrong.
  2. Start every policy in report-only mode. Review the sign-in logs for a week to see who would have been affected before you enforce anything.
  3. Tell your team what’s coming. Give people a date, a short guide to setting up the Authenticator app, and someone to ask for help.
  4. Turn policies on one at a time, starting with blocking legacy authentication and requiring MFA for administrators.
  5. Review regularly. New staff, new apps, and new devices all change what your policies need to cover.

The bottom line

Whichever option you choose, the goal is the same: no one should be able to sign in to your business with just a password. If you’re not sure what your tenant is doing today, that’s worth finding out this week.

Want a second pair of eyes on your setup? Email me and I’ll help you work out what’s in place and what to do next.

LET’S TALK

Have a question about
your own setup?

Every business is a little different.
Tell me what you’re working with, and let’s figure out the next step together.

brubell@rubellservicesllc.com