Mastering Microsoft 365 Security: Standard MFA vs. Conditional Access
Summary:
Standard MFA applies automatically per user at onboarding and blocks outdated authentication protocols, but requires manual review to manage at scale. Conditional Access, configured in Entra ID and included with Azure AD Premium P1 (or Business Premium), applies centralized policies based on user location, device compliance, and sign-in risk — even when MFA shows as "disabled" in the M365 portal. Security defaults offer a simpler baseline for Microsoft 365 Business and Basic customers who don't need that granularity.
|
What you'll Learn |
|
|
Benefits for MSPs |
|
|
Required Next Steps |
|
Ask an MSP whether a customer's Microsoft 365 tenant has MFA enabled, and you'll usually get a confident yes. Ask them to prove it from the admin center, and things get murkier — because Standard MFA and Conditional Access aren't the same control, and the portal doesn't always make that obvious.
Getting this distinction right matters more than it sounds. It's the difference between MFA that's actually protecting every sign-in and MFA that only covers the accounts someone remembered to configure manually.
- Azure AD is now branded Microsoft Entra ID — this article uses the current name throughout
- Conditional Access requires: Azure AD Premium P1 (included in Microsoft Business Premium)
- Security defaults available on: Microsoft 365 Business, Microsoft 365 Basic
- Configuration location: Microsoft Entra admin center
Scope and Limitation Statement
This content covers sign-in and MFA enforcement based on user, device, and risk conditions inside Entra ID. It does not cover data-loss-prevention, endpoint compliance policies in Intune, or app-level permissions — those are separate policy layers. Security defaults are a Microsoft 365 Business/Basic baseline only and are not a substitute for Conditional Access at scale.
Understanding Standard MFA and Conditional Access
Standard MFA: Strengthening User Authentication
When you onboard a client with Microsoft 365, certain security measures, known as Standard MFA, are automatically applied. These measures require users to go through an additional authentication step, typically through a code sent to their mobile device, providing an extra layer of security. Standard MFA also blocks access from outdated protocols.
While Standard MFA provides a baseline level of protection, it requires manual control and can become challenging to manage as your client base grows. As an MSP, it's crucial to ensure that all users in your clients' organisations are properly configured with Standard MFA. Regular audits and monitoring are necessary to identify any potential gaps in security and promptly address them.
Conditional Access: Centralised Control and Customisation
To streamline the security management process, MSPs can turn to Conditional Access, a powerful tool housed within the Azure AD portal. Conditional Access allows you to define a single policy that applies to all users, ensuring consistent security measures across the board.
Unlike Standard MFA, which focuses on individual user authentication, Conditional Access provides centralised control and customisation options. It enables you to set specific conditions and requirements for accessing Microsoft 365 services based on factors such as user location, device compliance, or risk level. This granular control helps you tailor the security policies to your clients' unique needs.
With Conditional Access, you can implement more advanced security measures, such as requiring multi-factor authentication only for high-risk activities or specific user groups. This approach ensures that your clients' most sensitive data and applications are protected while allowing for a seamless user experience in less critical scenarios.
It's important to note that Conditional Access may not reflect the MFA status visibly within the Office 365 portal. Even if MFA appears "disabled," the Conditional Access policy is working behind the scenes to enforce the security measures you have set.
To confirm the MFA status under Conditional Access, you can check the user sign-in logs. Regularly monitoring these logs helps you identify any suspicious activities or potential security breaches, allowing you to take immediate action and mitigate any risks.
The Role of Security Defaults
In addition to Standard MFA and Conditional Access, Microsoft 365 also offers security defaults. These defaults provide a simplified approach to security by enabling certain baseline settings for Microsoft 365 Business and Microsoft 365 Basic users.
When security defaults are enabled, users are automatically prompted to set up MFA during their initial sign-in. This ensures that every user in your clients' organisations has an added layer of protection from the start. Security defaults also block legacy authentication protocols and enforce modern security practices.
While security defaults offer ease of use, they lack the granular control and customisation options available with Conditional Access. It's important to assess your clients' security needs and consider whether security defaults provide sufficient protection or if upgrading to a licence that includes Azure AD P1 or implementing Conditional Access would better align with their requirements.
Additionally, it's crucial to educate your clients about the importance of strong passwords, periodic password changes, and the risks associated with sharing credentials. Regular security awareness training sessions can help reinforce good security practices among users and reduce the likelihood of successful cyberattacks.
Conclusion
For MSPs, both Standard MFA and Conditional Access play vital roles in enhancing clients' security within the Microsoft 365 ecosystem. While Standard MFA strengthens user authentication and blocks outdated protocols, Conditional Access offers centralised control and customisation, allowing you to tailor security policies to the unique needs of each client.
As an MSP, it is essential to adopt a proactive approach to security. Regularly reviewing and adjusting your clients' security configurations is crucial to ensure their environments are protected against evolving threats. By leveraging Standard MFA and Conditional Access, you can significantly strengthen your clients' security posture and provide them with peace of mind.
Consider leveraging Conditional Access for larger organisations or those requiring more specialised security measures. Conditional Access allows you to implement context-based access controls, ensuring that the right users have access to the right resources under the appropriate conditions. By defining specific policies based on factors like user location, device compliance, or risk level, you can enhance the security of your clients' sensitive data and applications.
Security defaults offer a simplified approach for clients using Microsoft 365 Business or Microsoft 365 Basic. While they provide baseline protection, it's important to evaluate whether these defaults meet your clients' unique security requirements. Upgrading to a licence that includes Azure AD P1 or implementing Conditional Access may be necessary for clients seeking advanced security controls and customisation options.
In conclusion, MSPs have powerful security tools at their disposal with Standard MFA and Conditional Access in Microsoft 365. The package now offered with Microsoft Business Premium includes all the essential tools, including conditional access, to protect your clients. By effectively utilising these features, you can provide your clients with robust protection against cyber threats and help them navigate the ever-changing landscape of security. Regular monitoring, auditing, and educating your clients on best practices are essential to maintain a strong security posture.
FAQs
What's the difference between Standard MFA and Conditional Access in Microsoft 365?
Standard MFA applies automatically per user, prompting for a second authentication factor and blocking outdated protocols, but it's managed per-account and gets harder to audit at scale. Conditional Access, configured centrally in Entra ID, applies one policy across all users with granular conditions based on location, device compliance, or sign-in risk.
Do I need Azure AD Premium P1 for Conditional Access?
Conditional Access requires Azure AD Premium P1 licensing, which is included in Microsoft Business Premium — so customers already on Business Premium have access to it without an additional purchase.
Why does MFA show as "disabled" even though Conditional Access is enforcing it?
Conditional Access policies can enforce MFA behind the scenes without flipping the per-user MFA toggle in the Microsoft 365 admin portal to "enabled," so that toggle isn't a reliable indicator. Confirming actual enforcement means checking user sign-in logs rather than the portal status field.
Is Microsoft 365 security defaults enough, or do I need Conditional Access?
Security defaults — a baseline available to Microsoft 365 Business and Basic customers — automatically require MFA at sign-in and block legacy authentication, but offer no granular control. They're a reasonable floor for smaller customers; larger organizations or those needing condition-based policies should move to Conditional Access.
When should an MSP recommend Conditional Access over Standard MFA?
When a customer needs policies tailored to risk level, device compliance, or location — for example, requiring MFA only for high-risk sign-ins rather than every sign-in — Conditional Access gives that granularity where Standard MFA and security defaults can't.
Does Business Premium include Conditional Access?
Yes — Business Premium includes the Azure AD Premium P1 licensing Conditional Access requires, making comprehensive, condition-based client protection available as part of that tier.
Share this
You may also like
These related stories

The MSP’s Guide to Selling Microsoft 365 Security to Skeptical Customers

Microsoft Intune Plans Summary and Comparison
