Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Easy
A small business is setting up its Microsoft 365 tenant and wants to ensure that all user accounts have a baseline level of security, such as requiring multi-factor authentication for administrative roles and blocking legacy authentication protocols. They have limited IT staff and need a simple, automated solution. Which Microsoft 365 feature should they enable?
- AAzure AD Security Defaults
- BConditional Access policies
- CAzure AD Identity Protection
- DMicrosoft Defender for Cloud Apps
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Security Defaults
Azure AD Security Defaults provide a basic level of security for all users without requiring extensive configuration, making them ideal for organizations with limited IT resources. They enforce common security best practices such as MFA for privileged roles and blocking legacy authentication.
Why the other options are wrong
- B. Conditional Access policies offer granular control but require more complex configuration and an Azure AD Premium license, which is not suitable for a simple, automated solution for a small business.
- C. Azure AD Identity Protection is a more advanced feature focused on detecting and remediating identity-based risks, requiring Azure AD Premium P2.
- D. Microsoft Defender for Cloud Apps focuses on cloud app security, shadow IT discovery, and data governance, not baseline user security configuration.
Azure AD Security Defaults
A set of basic security policies enforced by Azure Active Directory to protect organizations from common identity-related attacks, especially useful for small businesses.
- Automatically enabled for new tenants unless explicitly disabled.
- Enforces multi-factor authentication for administrative roles.
- Blocks legacy authentication protocols.
- Provides a baseline security posture without complex configuration.
Memory trick: Default settings give a safe, secure start.