Multi-factor authentication is the single highest-impact security control most organizations can add โ it blocks the vast majority of account-takeover attempts even when a password is compromised.
Before You Begin
Plan a rollout in phases rather than switching it on for everyone at once โ start with IT/admin accounts, then a pilot group, then the full organization, to catch any workflow issues early.
Step 1 โ Access Security Defaults or Conditional Access
Choose your approach
Small organizations can enable Security Defaults (a simple on/off MFA baseline) from the Entra admin center. Organizations needing more granular control should use Conditional Access policies instead, which requires Microsoft 365 Business Premium or an Entra ID P1/P2 license.
Step 2 โ Enable Security Defaults (simplest path)
Turn Security Defaults on
Set the toggle to Yes and save. This requires MFA registration for all users at next sign-in.
Step 3 โ Or configure a targeted Conditional Access policy
Step 4 โ Communicate the change to users
Notify users in advance
Send clear instructions on how to register the Microsoft Authenticator app before the policy takes effect, to avoid a flood of lockout support tickets on rollout day.
Frequently Asked Questions
Do I need a paid license to enable MFA?
Security Defaults are available on all Microsoft 365 plans at no extra cost. Conditional Access policies (for more granular control) require Entra ID P1 or higher, typically bundled into Business Premium or E3 licensing.
What happens to a user who hasn’t registered MFA when the policy activates?
They’ll be prompted to register the next time they sign in โ this is why advance communication (Step 4) matters, so it doesn’t look like an unexpected lockout.
Conclusion
For most small-to-medium organizations, Security Defaults is the fastest way to get baseline MFA protection in place; Conditional Access is worth the extra licensing once you need more granular exceptions and rules.