Get in touch
Microsoft 365

MFA in Microsoft 365: what you can turn on without extra licences

Published:

Short answer: if your Microsoft 365 plan does not include Microsoft Entra ID P1 or P2, Microsoft recommends enabling security defaults. They are a ready-made set of baseline settings that includes multi-factor authentication (MFA) for users and administrators, at no extra cost.

What security defaults enforce

  • All users must register for MFA and are prompted for extra verification when necessary. When it is requested, Microsoft Authenticator shows a number to enter, which helps against MFA fatigue approvals.
  • Administrators perform MFA on every sign-in.
  • Legacy authentication protocols, such as IMAP, SMTP and POP3 with basic authentication, are blocked.

Why blocking legacy protocols matters

Microsoft's documentation notes that legacy protocols do not support MFA. So even with MFA enabled, an attacker who knows the password can sign in through an older protocol and bypass it. Before enabling security defaults, check whether printers, scanners or old applications send email this way, because they will stop working.

When they are enough and when they are not

Microsoft recommendation by plan
PlanWhat Microsoft recommends
Microsoft 365 without Entra ID P1/P2Security defaults
Microsoft 365 E3 (Entra ID P1)Conditional Access: MFA for administrators, MFA for all users, block legacy authentication
Microsoft 365 E5 (Entra ID P2)Additional risk-based policies: MFA on medium or high sign-in risk, password change for high-risk users

Security defaults do not let you define your own rules, for example exceptions or per-application requirements. If you need that level of control, you need Conditional Access, which is included in Entra ID P1.

What to do (our own practical advice)

  1. List which devices and applications send email or sign in using legacy protocols.
  2. Prepare administrator accounts separate from daily ones. Microsoft recommends this so administrators are not prompted for MFA constantly during everyday work.
  3. Brief staff before enabling: what they will see, which app they need and who to ask if they get stuck.
  4. Enable, and check the next day that email and applications work. If you have Entra ID P1, prefer Conditional Access, tested first in report-only mode.

Frequently asked questions

Do security defaults cost anything?

No. They are available in all Microsoft Entra tenants and, according to Microsoft, new tenants have them enabled from creation.

Is MFA enough to be safe?

Not on its own. It is among the most effective measures, but you also need updates, device protection, backup and training.

What about printers that send email?

If they use SMTP basic authentication they will be affected. Microsoft has guidance on alternative ways for devices and applications to send mail, and we can set these up before you enable.