Security Defaults is Microsoft’s built‑in baseline security mode.
It automatically enforces MFA, blocks legacy authentication, and applies basic identity protections — mainly for small tenants.
But here’s the catch:
When Security Defaults is enabled, you cannot create Conditional Access policies.
So if your MSP uses Conditional Access for MFA, device compliance, or location restrictions, you’ll need to turn Security Defaults off.
Before you disable Security Defaults, make sure you already have a Conditional Access baseline ready to go.
Turning off Security Defaults without replacing it with Conditional Access will remove MFA enforcement and weaken the tenant’s security.
The correct workflow is:
Prepare Conditional Access policies
Disable Security Defaults
Immediately enable your Conditional Access baseline
Now let’s disable it.