Hi Stan,
When you enable security defaults you enable MFA to be registered for all of your users in your tenant.
Security defaults were designed to help protect your company's user accounts from the start. When turned on, security defaults provide secure default settings that help keep your company safe by:
- Requiring all users and admins to register for MFA using the Microsoft Authenticator app or any third-party application using OATH TOTP.
- Challenging users with MFA, mostly when they show up on a new device or app, but more often for critical roles and tasks.
- Disabling authentication from legacy authentication clients that can't do MFA.
- Protecting admins by requiring extra authentication every time they sign in.
MFA is an important first step in securing your company, and security defaults make enabling MFA easy to implement. If your subscription was created on or after October 22, 2019, security defaults might have been automatically enabled for you—you should check your settings to confirm.
If you are looking to control who has MFA enabled, then you may want to look at the other option, which is Conditional Access Policies.
If this is helpful please accept answer.