Mandatory "security defaults"

Anonymous
2023-09-08T17:48:33+00:00

Hi, I am the admin for my company and just received an email from Microsoft that "security defaults" will be enabled in a month and that users must register for 2 factor using "microsoft authenticator" app. My questions are:

  1. Most of my users already have 2 factor enabled but they are using the "SMS code to cell" option. Will they still be forced to use the "microsoft authenticator" app?
  2. How about "common" mailboxes (e.g. for mail archiving)? Can I disable this "security default"?

Thanks.

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

3 answers

Sort by: Most helpful
  1. Anonymous
    2023-10-19T19:19:11+00:00

    Can Microsoft stop forcing this? It seems they have now changed it so when you turn it off, they make you turn it on again.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-09-15T16:18:00+00:00

    Hello Eddie Chew1,

    Good day!

    We are following up this thread to see if you have further concerns on this topic, or if you have any other questions.

    If our information was helpful, we also invite you to vote the reply so that others may find it easier.

    Thank you for your time and wish you a nice day.

    Regards,

    De Paul | Microsoft Community Moderator

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-09-08T19:44:20+00:00

    Dear Eddie Chew1,

    Good day! Thank you for posting to Microsoft Community. We are happy to help you.

    Based on your description, I understand that you have a query "Mandatory "security defaults"". Email from Microsoft stating that "security defaults" will be enabled in a month, is because the app provides an additional layer of security and helps prevent unauthorized access to your account and Microsoft recommend that you switch to the app for added security benefits.

    1. If your users already have 2-factor authentication enabled using the "SMS code to cell" option, they will not be forced to switch to the "Microsoft Authenticator" app. Microsoft requires the use of the Authenticator app for certain MFA settings, such as when using the "Notify me through app" option in the https://account.activedirectory.windowsazure.com/UserManagement/MfaSettings.aspx?BrandContextID=O365. So, try unchecking this option so it will not keep still forcing to use the "Microsoft authenticator" app.
    2. Unfortunately, the "security defaults" cannot be disabled for specific mailboxes. It is a global setting that applies to all users in your organization. However, you can create an exception for certain users by creating a Conditional Access policy. This will allow you to exempt specific users or groups from the "security defaults" policy.

    To disable security defaults, Sign in to the Microsoft Entra admin center > Browse to Microsoft Entra ID (Azure AD) > Properties > Select Manage security defaults > Set Security defaults to disabled > Select Save. Refer to Providing a default level of security in Azure Active Directory - Microsoft Entra | Microsoft Learn.

    Image

    Please note that disabling MFA for the whole tenant is not recommended for security reasons. It is better to disable it on a user basis if it is not practical for your organization at the moment.

    We look forward to hearing from you; Please note that our initial response does not always resolve the issue right away. However, with your help and more detailed information, we can work together to find a solution. Thank you for your help.

    Sincerely

    De Paul | Microsoft Community Moderator

    Was this answer helpful?

    0 comments No comments