Microsoft says it will improve security for all Entra tenants where security defaults are enabled by making multi-factor authentication (MFA) enrollment mandatory.
See also: CISA: New security requirements for the protection of personal and government data

This move is part of the Secure Future , launched in November 2023, to strengthen cybersecurity protections in products .
The change will affect all newly established tenants starting December 2, 2024 , and will begin rolling out to existing tenants starting January 2025.
Microsoft Entra Security Defaults is a setting that automatically enables various security features to protect organizations from common attacks, such as password sprays, replays, and phishing.
As of October 22, 2019, new tenants have automatically enabled security defaults, and older tenants have automatically enabled it over time if they are not using Access , do not have high-quality licenses, or are using legacy authentication clients.
To enable security defaults, you need to log in to the Microsoft Entra admin center (at least as a Security Administrator), go to Identity > Overview > Properties and select Manage security defaults. From there, set “Security defaults” to Enabled and click Save.
See also: FBI arrests man suspected of hacking SEC's X account
Administrators who don't use Conditional Access are recommended to enable security defaults for their organization because they provide a simple and effective way to protect users and resources from common threats .

However, although security defaults offer a good security foundation, they do not allow for the customization provided by conditional access policies that complex organizations require.
In August, Microsoft also warned global Entra administrators to enable MFA for their tenants by October 15thto ensure users don’t lose access to management portals. By enforcing mandatory MFA for all Azure sign-in attempts, Microsoft aims to protect Azure accounts from hijacking and phishing attempts.
The company also announced in November that it would deploy conditional access policies that require MFA for all administrators logging into Microsoft admin portals (e.g., Entra, Microsoft 365, Exchange, and Azure), for users across all cloud , and high-risk sign- ins.
In January, Microsoft-owned GitHub also began enforcing two-factor authentication (2FA) for all active developers as part of the company's ongoing effort to boost MFA adoption
See also: Mamba 2FA: New phishing service targets Microsoft 365 accounts
Multi-factor authentication (MFA) is a security process that requires users to provide multiple forms of verification before gaining access to an account or system. It enhances security by combining two or more independent credentials: something the user knows (a password), something the user has (a security token or smartphone), and something the user does (biometric verification, such as a fingerprint). This multi-layered approach reduces the likelihood of unauthorized access because even if one factor is compromised, an attacker would still have to breach additional layers to gain access. As cyber threats evolve, MFA serves as a critical tool for protecting sensitive information in both personal and organizational contexts.
Source: bleepingcomputer
