Understanding Conditional Access policies and security defaults
Nowadays, modern security extends beyond the boundaries of an organization's network to include user and device identity. These identity signals can be used by organizations as part of their access control decisions. However, these require configuration and ongoing management, plus you must upgrade to the Azure AD Premium P1 tier to use it.
For some organizations, this may either involve too much effort (perhaps you are a small team) or possibly cost too much. Because security is so important, Microsoft offers security defaults as part of the free tier.
Security defaults
Security defaults are a set of built-in policies that protect your organization against common threats. Essentially, enabling this feature preconfigures your Active Directory tenant with the following:
- It requires all users to register for MFA.
- It requires users to use MFA when necessary (for example, in response to security events...