Microsoft is now creating security policies inside your Microsoft 365 tenant for you — and it will turn them on whether you act or not.
They're called Microsoft-managed Conditional Access policies. Microsoft creates them in eligible tenants in "report-only" mode first: evaluated on every sign-in, but not enforced, so you can see exactly who would have been affected. Leave them alone and Microsoft switches them on, typically at least 30 days later. You get an email and a message center post about two weeks before that happens.
Conditional Access is just an if-then rule for sign-ins. If an advisor signs in from somewhere unusual, then make them prove it's really them. Microsoft's defaults are sensible ones: require MFA for everyone, require it again on a risky sign-in, and block the old mail protocols attackers still love. Microsoft's own data puts more than 99% of password spray attacks on those legacy protocols.
Here's where firms get hurt. Nobody reads the message center notice, the policy flips on during a busy week, and the one advisor still running an old desktop mail client can't reach email Monday morning. That isn't a security failure. It's a planning failure, and it costs you a day of client calls.
Go read your report-only results before Microsoft reads them for you. Thirty days is plenty of warning if somebody is actually watching.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email