New Microsoft CSP security requirements: what Partners need to know before October 2025
Summary:
Starting October 1, 2025, Microsoft enforced new CSP program security requirements on direct bill partners, distributors, and indirect resellers: 100% MFA coverage for admin accounts, a Partner Center Secure Score of 80+ for indirect resellers, and under-24-hour response to security alerts. Partners who fall short risk losing CSP authorization and revenue eligibility. MSPs need visibility across every tenant to stay compliant, which tools like inforcer’s 365 Manager provide.
|
What you'll Learn |
|
|
Benefits for MSPs |
|
|
Required Next Steps |
|
If you're an indirect reseller, direct bill partner, or distributor in Microsoft's Cloud Solution Provider (CSP) program, the clock is already running. From October 1, 2025, Microsoft is enforcing a new set of security and revenue requirements across the CSP program — and partners who don't meet them risk losing their authorization to sell Microsoft licenses.
This isn't a soft recommendation. Microsoft has published specific, measurable thresholds for admin account MFA, incident response time, and Partner Center Secure Score, and partners are expected to demonstrate compliance, not just intent.
For MSPs managing dozens of customer tenants, the challenge isn't understanding what Microsoft wants — it's proving it, tenant by tenant, before the deadline.
- Enforcement date: October 1, 2025
- Applies to: direct bill partners, distributors (formerly indirect providers), indirect resellers
- Minimum Secure Score for indirect resellers: 80
- MFA requirement: 100% of admin users
- Alert response time threshold: under 24 hours (for direct partners/distributors)
Scope and Limitation Statement
Inforcer's 365 Manager helps MSPs monitor and improve Secure Score and MFA compliance across connected Microsoft 365 tenants. It does not automatically submit compliance data to Microsoft Partner Center on the MSP's behalf, guarantee CSP authorization status (that decision remains Microsoft's), or track revenue.
Big changes are coming for Microsoft partners
If you are an indirect reseller, the time to act is now.
From 1 October 2025, Microsoft will begin enforcing new security and revenue requirements across the Cloud Solution Provider (CSP) program!
A critical security deadline is approaching, and these requirements apply to direct bill partners, distributors (formerly indirect providers), and indirect resellers, and are designed to strengthen the security posture of the entire partner ecosystem.
|
Enforcement Deadline 1 October 2025 Date when new partner security requirements take effect |
MFA Coverage 100% Admins All partner tenant admin users must use multi-factor authentication |
|
Alert Response Time < 24 Hours Security alerts must be answered within one day (for direct partners/distributors) |
|
[Source: Microsoft]
These updates are part of Microsoft’s broader effort to improve the baseline security posture of its entire partner ecosystem. However, as is often the case, the official guidance can be confusing, especially when trying to translate policy into practical next steps. We are here to deliver you the essential information.
What is changing?
Microsoft’s updated FY26 eligibility criteria apply to all CSP partners, including direct billers, distributors, and indirect resellers. For indirect resellers specifically, the key requirements are:
- Minimum of $1,000 in trailing twelve months (TTM) revenue
- Microsoft Partner Center Security Score of 80 or higher
Failing to meet these criteria could jeopardize your partner authorization status moving forward.
Please note that indirect partners do not have a Microsoft Partner Center Security Score. Indirect partners only need to complete all other criteria outlined in this blog.
Secure Score achievement criteria
At first glance, it seems straightforward. Achieve an 80 percent Secure Score and you are compliant. But once you dive into the Microsoft Learn documentation, it becomes clear that it is not quite that simple.
The Secure Score requirement is not just about hitting a number. Microsoft provides detailed guidance on specific security actions that partners should take to demonstrate compliance. These actions contribute to achieving and maintaining a high score, but the real focus is on building a secure environment.
Microsoft’s updated CSP authorization eligibility requirements introduce a set of mandatory security measures that every partner must implement by the enforcement date. In summary, all partners must ensure the following by October 2025 (selected measures):
- Enable Multi-Factor Authentication (MFA) for all administrative users in your partner tenant. Every account with admin privileges must be protected with MFA, no exceptions.
- Designate a security contact in Partner Center. You need to specify a contact person (with up-to-date email and phone details) to receive security notifications and coordinate on security issues.
- Respond to security alerts within 24 hours. Partners are expected to monitor and act on security alerts (for example, notifications of suspicious activity or vulnerabilities) within a day or less. Rapid response is critical to limit damage from incidents.
All the above must be in place by the time enforcement begins (October 1, 2025). If your CSP program anniversary falls soon after that date, it effectively becomes your personal deadline for compliance, as Microsoft will check your status in that month each year.
Partners who do not comply risk losing their CSP credentials or other partner privileges, which could disrupt your ability to transact in the Microsoft ecosystem.
Check more details here: Security requirements dashboard for Partner Center.
How inforcer can help you and your customers?
Raise the security levels of all customer tenants by defining and deploying a consistent baseline. inforcer is a platform built specifically for MSPs to simplify and automate security configuration across multiple Microsoft 365 tenants.
inforcer can help you to:
- Monitor and improve Secure Scores across all your customer tenants
- Automate the implementation of policies
- Provide clear, audit-ready reporting
- Stay aligned with Microsoft’s evolving security and compliance expectations
Key takeaways
The October 2025 deadline for Microsoft’s mandatory partner security requirements is a pivotal moment for CSPs. Compliance is about strengthening your foundations and delivering greater value to customers by showcasing a secure operation. inforcer simplifies this process by automating security configurations across Microsoft 365 tenants, monitoring Secure Scores, and ensuring audit-ready reporting. We help MSPs of all sizes align with Microsoft’s evolving security standards without significant overhead, enabling scalable security best practices for every client.
By investing in solutions like inforcer, MSPs can differentiate themselves as security-forward partners, earning trust and reducing vulnerabilities to breaches. Meeting the October deadline ensures not only compliance but also positions you as a leader in the Cloud-first era, prepared to guide customers through future challenges.
Taking proactive steps now will pay dividends far beyond compliance and help foster resilience in an ever-changing cybersecurity landscape.
Contact us to learn more today.
FAQs
What are Microsoft's new CSP security requirements for October 2025?
Starting October 1, 2025, Microsoft requires CSP partners to enable MFA for 100% of admin users, respond to security alerts within 24 hours (direct partners and distributors), and — for indirect resellers — maintain a Partner Center Secure Score of 80 or higher alongside a minimum $1,000 trailing-twelve-month revenue. These sit on top of existing CSP terms and are tied to FY26 eligibility.
Which partners are affected by the October 2025 CSP security requirements?
The requirements apply across the CSP hierarchy: direct bill partners, distributors (formerly "indirect providers"), and indirect resellers. Obligations differ slightly by tier — distributors and direct partners must hit the 24-hour alert response time, while indirect resellers also carry the Secure Score and revenue thresholds.
What Secure Score do I need to keep my CSP status?
Indirect resellers need a Microsoft Partner Center Secure Score of 80 or higher. Microsoft has been clear this isn't just about the number itself — it expects specific actions behind that score, including MFA for all admins and a designated security contact on file in Partner Center.
What happens if my MSP doesn't meet the new requirements by the deadline?
Non-compliant partners risk losing their CSP program authorization, which can affect their ability to transact Microsoft licenses on behalf of customers — a significant risk given how central CSP revenue is to most MSPs.
How do I get all customer tenants to 100% MFA before October 2025?
Rather than logging into each tenant's admin center individually, most MSPs use centralized tooling like inforcer's 365 Manager to monitor MFA and Secure Score status across every connected customer tenant from one place.
Does Inforcer help with Microsoft's new CSP compliance requirements?
Yes — inforcer's 365 Manager monitors and helps improve Secure Scores and automates policy implementation (including MFA) across connected tenants, giving partners one consolidated view against the October 2025 requirements.
Share this
You may also like
These related stories

What Microsoft's Copilot Specialization Means for MSPs

Windows Autopatch Now Supports Microsoft Business Premium
