The impact to customers of Microsoft enforcing Security Defaults

Microsoft will be making multi-factor authentication (MFA) mandatory for all organisations in 2023.

What’s happening?

In 2022, Microsoft publicly announced it planned to raise the baseline security for all their customers, globally (see here). Microsoft’s focus is disabling legacy authentication (username and password) capability and mandating the use of Multi-Factor Authentication (MFA) for sign-in. Microsoft state Multi-Factor Authentication would have prevented more than 99.9% of user account compromises, from identity-related attacks including password spray, replay, and phishing.

They are planning to achieve this by enabling Security Defaults within customer tenancies for organisations that do not currently use Security Defaults or Conditional Access. It must be noted that using Security Defaults – which is the Microsoft’s minimum requirement, can result in interrupted use of systems, so we strongly recommend you plan ahead and speak to a trusted advisor at TSG.

When is this happening?

As of May 2023, TSG can confirm some clients are now receiving emails from Microsoft, advising Security Defaults will be enabled within 14-days of the date of the email. These emails are sent to global administrators for customer tenancies.

What are the challenges of this?

Enabling Security Defaults can cause issues for companies that do not supply mobile devices for all employees within their organisation. This is due to only being able to use MFA through the mobile app. If you need more MFA methods, which we strongly recommend to mitigate interruption to services, you will need ‘Conditional Access’.

‘Service accounts’ used by software programmes to send email can stop working, as well as scan to email services from devices such as Multi-Function Printers (MFP’s).

What do I need to do?

We strongly recommend you get in touch with us about this change so you can plan ahead. Failure to prepare for this change would result in interrupted use of systems with no access.

What are my options?

There are three different methods for enabling MFA:

A) Per User MFA (now Legacy MFA) not recommended

This option is not recommended as it does not provide for any centralised management or compliance.

B) Security Defaults minimum Microsoft recommendation

This is the minimum Microsoft recommendation but can directly cause problems for customers. It also requires all employees to have mobiles phone for the Authenticator app.

Common issues include service accounts used by application software to send email to stop working, or scan to email services from devices (MFP’s) to stop working.

C) Conditional Accessrecommended

This must be paid for but provides the best experience out of the three options. It gives a more granular control and is recommended by Microsoft (and TSG) for ‘more complex’ environments. As well as Microsoft Authenticator app, Conditional Access also works through user receiving a text message, phone call, or using a hardware token.

We can help you to determine the most appropriate Microsoft 365 licensing for your organisation, as the various plans, including Azure Active Directory Premium P1/P2, Microsoft 365 Business Premium, Microsoft 365 E3/E5/F3/F5, Microsoft EM+S have different use cases/features.

 

MFA Chart

 

TSG clients:

It is important that you enable Azure MFA as soon as possible to continue to operate your business as normal. Please do not wait until you are contacted by Microsoft as new licensing may need to be in place before the change, so preparation is key.

We understand this may be confusing and you may not know where to start. Please contact us if so, and we will be in touch to help.

Non-TSG clients:

You must prepare for this transition whether you are a TSG client or not to avoid having your accounts affected.

We pride ourselves on having a team of seasoned security professionals with years of experience in managing risks and ensuring security for businesses of all sizes.  Contact us today to learn more about how we can help you safeguard your systems and networks for your peace of mind.

Q&A

Microsoft started the enforcement of security defaults in May last year.  As of May 2023, TSG can confirm that some customers are now receiving emails from Microsoft, advising Security Defaults will be enabled within 14-days of the date of the email. It is important that you prepare yourself for this change beforehand, to ensure no interruption to your services.

As mentioned above, Microsoft are planning to raise their baseline security by enabling security defaults as standard. However, this usually only works well for those companies where all have have a company mobile with the Authenticator app. If you need more MFA methods and more control over how it is enforced, we strongly recommend you get ‘Conditional Access’.

Please see the diagram above for more information on these licenses.

This applies to M365 and any services you log into through the Azure Active Directory account that is behind your M365 tenant. Applications such as Dynamics, SharePoint and Teams will be affected.

Unfortunately, sticking with Microsoft’s ‘Security Defaults’ can affect service accounts used by software programmes to send email and cause them to stop working, as well as scan to email services from devices such as Multi-Function Printers (MFP’s). It also requires all users to have the Authenticator App installed on a work or personal mobile, which some staff or companies may not be comfortable with. We recommend ‘Conditional Access’ to get the best experience for MFA.

The best option in this instance would be method ‘C’ above, which is Conditional Access. This must be paid for but provides the best experience out of the options. It gives a more granular control and is recommended by Microsoft (and TSG) for ‘more complex’ environments. As well as Microsoft Authenticator app, Conditional Access also works through user receiving a text message, phone call, or using a hardware token.

We can help you to determine the most appropriate Microsoft 365 licensing for your organisation, as the various plans, including Azure Active Directory Premium P1/P2, Microsoft 365 Business Premium, Microsoft 365 E3/E5/F3/F5, Microsoft EM+S have different use cases/features.

Depending on the situation and the particular licence in use, there are ways to modify the scope of the MFA requirement, or to set up Conditional Access so MFA is not required for normal use. Contact us to speak to a trusted advisor around MFA.

After the 14 day notification period is up, users will need to have MFA enabled in order to sign in to M365. They will be given the ability to do this themselves upon login, however, if the Microsoft Authenticator app is not installed on all employees mobiles, you will need Conditional Access to guarantee no interruption of systems.

We strongly advise you plan ahead and not wait for Microsoft’s email to get ready for this change. Fill in our form below so we can guide you through this.

This will apply to all user accounts including those used to send emails from printers/scanners. Service accounts’ used by software programmes to send email can stop working, as well as scan to email services from devices such as Multi-Function Printers (MFP’s). Please contact TSG and we can help resolve this.

Need support setting up MFA?

Contact our Training team today using the form below.