CIO Brief: Microsoft Is Changing Your Defaults — Here's What to Know
Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.
The short version: In November 2023, Microsoft announced a major security push — the Secure Future Initiative — and began automatically adding security rules to customers' Microsoft 365 tenants. Microsoft is increasingly changing your security settings for you. That's mostly good, but you need to know what's changing.
What's happening
After high-profile breaches, Microsoft committed to making its products "secure by default." In practice, that means:
- Automatic policies requiring multi-factor authentication in certain situations.
- Mandatory MFA for administrators using Azure and Microsoft 365 admin portals.
- Retirement of older, less secure features.
- Expanded security logging.
The business impact
- Better baseline security for organizations that hadn't configured it.
- Surprise changes for users if IT doesn't track announcements.
- Potential conflicts with existing policies.
Questions to ask your team
- Who monitors Microsoft's security change announcements for our tenant?
- What automatic policies has Microsoft added to our tenant, and have we reviewed them?
- Are any upcoming changes likely to affect our users or applications?
What good looks like
A named owner reviewing Microsoft's announcements monthly, a documented decision for each automatic policy, and user communications planned before changes take effect.
The decision
Assign responsibility for tracking Microsoft's security changes. It costs a few hours a month and avoids disruption.
- Secure Future Initiative and Microsoft-Managed Conditional Access Policies (Nov 2023) Platform Changes
- How to Review and Customize Microsoft-Managed Conditional Access Policies How-To & Hardening
- Conditional Access Policy Review Checklist How-To & Hardening