Secure Future Initiative and Microsoft-Managed Conditional Access Policies (Nov 2023)
Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.
On November 2, 2023, Microsoft announced the Secure Future Initiative (SFI), a company-wide security commitment following a series of high-profile incidents, including Storm-0558. The same month, Microsoft began rolling out Microsoft-managed Conditional Access policies to customer tenants.
The Secure Future Initiative
SFI committed Microsoft to changes in how it builds and operates products, including:
- Secure by default product settings.
- Faster vulnerability response.
- Stronger protection of identity infrastructure and signing keys (including moving key storage to hardware security modules and automated rotation).
- Expanded security logging for customers by default.
In 2024, after the Midnight Blizzard breach and the CSRB report, Microsoft expanded SFI and said security would take priority over new features, tying executive compensation in part to security progress.
Microsoft-managed Conditional Access policies
Microsoft began automatically creating Conditional Access policies in eligible tenants, initially in report-only mode, with automatic enablement after a notice period unless administrators opted out. Early policies included:
- MFA for admins accessing Microsoft admin portals.
- MFA for per-user MFA users (to migrate from legacy per-user MFA).
- MFA and reauthentication for risky sign-ins (for P2 tenants).
Later policies addressed areas such as blocking device code flow and legacy authentication in some tenants.
Why it mattered
Microsoft shifted from recommending protections to applying them by default. For tenants with weak configurations, it was an automatic security upgrade. For tenants with mature Conditional Access, it required review to avoid conflicts.
In hindsight
Managed policies, mandatory MFA for Azure portals and other default changes became Microsoft's main tools for raising the baseline. Administrators who ignored the notifications sometimes discovered new policies only when users were prompted.
- How to Review and Customize Microsoft-Managed Conditional Access Policies How-To & Hardening
- Conditional Access Policy Review Checklist How-To & Hardening
- CIO Brief: Microsoft Is Changing Your Defaults — Here's What to Know CIO Briefings