Microsoft 365 identity
Microsoft has three ways to require multi-factor authentication, and the names do not make it obvious that they are alternatives. Here is how to choose in about sixty seconds.
The short answer
No premium license, use Security Defaults. Microsoft Entra ID P1 or P2, use Conditional Access. Either way, switch off legacy per-user MFA. It still works, but Microsoft no longer recommends it, and running it alongside the modern methods only creates duplicate enforcement.
The three methods at a glance
| Feature | 🗄Per-user MFA | 🛡Security Defaults | 🎛Conditional Access |
|---|---|---|---|
| What it is | The original method: flip MFA on per account | One free tenant-wide on or off switch | Policies that require MFA based on conditions |
| Cost | Free | Free | Entra ID P1 or P2 (in Business Premium, E3, E5) |
| Granularity | Per user, prompts on nearly every sign-in | All or nothing, everyone the same | By user, app, location, device, and risk |
| Best for | Almost no one in 2026 | Small orgs with no premium license | Anyone who needs exceptions or owns a license |
| Microsoft's stance | No longer recommended | Good baseline | Recommended where licensed |
Start here
Do you have Entra ID P1 or P2?
It is included with Microsoft 365 Business Premium, E3, and E5. If yes, use Conditional Access.
No premium license?
Turn on Security Defaults. One free switch, a safe baseline, nothing to configure.
Running per-user MFA?
Once the above handles MFA, set per-user MFA back to Disabled for everyone.
Not sure what your tenant is actually enforcing?
Most environments we review run two MFA methods at once, leave admins half-covered, or pay for Conditional Access they never turned on. The Identity and Insurance Evidence Pack proves what your Entra ID enforces, in the format a cyber-insurance renewal asks for.