Forum Discussion
Why is Microsoft being a bully in regard to security defaults?
Hi,
I received this email today:
The security defaults setting for your domain.com tenant will be turned on by May 11, 2023
You’re receiving this email because you’re a global administrator for domain.com.
To help protect your organization, we’re always working to improve the security of Microsoft cloud services. As part of this, we’re enabling the security defaults setting in your tenant that includes multifactor authentication, which can block more than 99.9 percent of identity attacks that attempt to compromise your accounts.
When you log in to your account between April 27, 2023, and May 11, 2023, you’ll see a message prompting you to proactively enable security defaults. If you haven’t logged in or enabled this setting when that timeframe ends, we’ll enable it for you automatically.
This is my subscription, I pay for it and Microsoft has no right to tell me what to do!!!! Angry
I already disabled my security defaults in Azure admin centre a long time ago and do not want security defaults on because there may be situations where my mobile is unavailable, there is no signal or the battery is flat.
Microsoft can suggest this, but cannot force their clients to enable this if they don't want to. There are many of my clients that don't want to authenticate a second time because it would cause a nightmare with their employees.
Forcing someone is dictatorship. In a democratic society people get to choose what they want to do.
I read that I can use conditional access policies but Microsoft is going to hit you with an additional Azure AD Premium subscription on top of what you are already paying. Many of my clients are small businesses who try to keep their costs down.
Currently inflation is rampant and many small businesses are going bust.
Thanks Microsoft for increasing our cost of living and running a business.
This is my 2 cents worth on this subject.
4 Replies
- Horizon_ITBrass Contributor
It's worse than you think, the latest "scrap SMS and calls, and then force auth app or passkeys" is a REAL nightmare!
Issues I can see from space, where to begin....
1. You use the Microsoft authenticator for MFA, and backup onto you cloud account.
So when you swap phone, it will all be restored... WRONG
The backup will NOT restore Microsoft accounts, you have to re-add them in the user security settings, which is a NIGHTMARE is you are the tenant admin and your MFA is your lost phone!2. Passkeys cannot be backed up or transferred to a new device!
They exist only on the device, lose the device, lose access.3. Only "solutions" recommended are to register multiple devices with Auth App and passkeys, they literally said "get two phones"...
This is just madness, the levels of user support for this will be wild, it is for normal MFA when the users mess up the backups.
- mickliTin Contributor
What's worse is Microsoft's "one size fits all" security opinions are LESS SECURE for some environments and situations! By forcing us into their mold, they are in fact REDUCING security for some people. No opt-out. You got two options -- use Microsoft and accept their dictatorship of "we know what is best for you" even if it compromises your security. Or don't use Microsoft.
I finally chose the latter, and am actively moving away from the Microsoft ecosystem.
Microsoft claims to be "security first". But it is a LIE! Just look at the terrible default settings on their products. Look at the lack of support in new products for good security configurations (our Microsoft rep says they initially release products without "those security features in place", then add them later!). What Microsoft does do is decide what WE should be doing for security (sans information about our environments), and cram it down our throats with no option to say "no thank you, that doesn't help us".
- Horizon_ITBrass Contributor
I hate security default, forcing sodding auth apps, great until the user changes phone and loses them all, or the back up isn't 100%.
I'm all for 2FA, but simple text message is WAY better. Yes, we can consider to opt-out to fit our organization requirement