Effects of turning off Security Defaults

Jim Goyette 26 Reputation points
2022-08-02T21:12:14.35+00:00

We turned on Azure AD Security Defaults about a week ago but now need to turn it off and configure conditional access policies for MFA. About half of our accounts have registered for MFA authentication. Will our already registered accounts need to re-register after turning off Security Defaults and enabling conditional access policies? Will MFA authentication be enforced immediately after enabling conditional access policies or will there be a delay as with Security Defaults implementation?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} vote

Accepted answer
  1. Vasil Michev 119.7K Reputation points MVP Volunteer Moderator
    2022-08-03T07:36:09.37+00:00

    No, the already registered accounts will be able to just use MFA, as needed. Whether/when they will be prompted for MFA depends on what you configure within Conditional access.

    2 people found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2022-08-08T20:47:12.747+00:00

    @Jim Goyette
    Thank you for your post and I apologize for the delayed response!

    Will our already registered accounts need to re-register after turning off Security Defaults and enabling conditional access policies?

    Additional Links:
    Security defaults in Azure AD
    Conditional Access
    Create a Conditional Access policy

    ---------------------------------

    Will MFA authentication be enforced immediately after enabling conditional access policies or will there be a delay as with Security Defaults implementation?

    • Once you create your Conditional Access policy and activate that policy; as mentioned by michev, depending on what you've configured (apps, users, location, etc.) this will depend on when users are prompted for MFA.

    Additional Links:
    Test Azure AD Multi-Factor Authentication
    Plan a Conditional Access deployment
    Conditional Access: Require MFA for all users
    Manage emergency access accounts in Azure AD

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.