MFA for Microsoft 365: the Cyber Essentials v3.3 configuration
Configure Microsoft 365 MFA for Cyber Essentials v3.3: Security Defaults and Conditional Access, current number matching, administrator recovery and evidence of enforcement.

Section 01
MFA for Microsoft 365: the Cyber Essentials v3.3 configuration
Microsoft 365 cloud-service authentication must use MFA. This guide shows how to choose and verify Microsoft enforcement controls, with recovery planned before rollout. Read the MFA pillar for the scheme requirements.
Section 02
Security Defaults vs Conditional Access
Security Defaults
Microsoft's baseline is available without a separate premium MFA policy licence. It requires MFA registration, protects administrators and prompts ordinary users according to Microsoft's documented behaviour. It blocks legacy authentication. There is no Cyber Essentials fifty-user cutoff or ninety-percent coverage allowance.
Conditional Access
Requires an appropriate licence, such as Entra ID P1. Use it when you need granular targeting, authentication strengths or session controls. The need follows the implementation and licence, rather than an arbitrary staff count.
Microsoft's current documentation explains both options. Security Defaults does not demand a fresh MFA prompt on every ordinary-user sign-in. Assess the effective authentication and session controls for your scope instead of inferring a pass from the policy name.
Section 03
Security Defaults configuration
1. Sign in to the Entra admin centre with an appropriate role. Follow Entra ID → Overview → Properties → Manage security defaults.
2. Prepare supported authentication methods and recovery, then enable the setting.
3. Verify registration in Authentication methods → User registration details, and separately verify sign-in enforcement.
4. Investigate accounts and applications still using basic authentication before retiring their access route.
Microsoft removed the fourteen-day registration grace on 29 July 2024. Do not wait fourteen days on the assumption that registration or enforcement will become compliant automatically.
Section 04
Conditional Access configuration
For a broad baseline, target all relevant users and cloud resources and require multifactor authentication in the Grant controls. Review technical identities and emergency access before applying the policy. Use report-only mode to understand impact, test representative users, then enable enforcement once recovery is ready. Report-only mode does not enforce MFA.
Create an additional policy blocking legacy authentication clients where needed. Inspect Microsoft sign-in logs and current client-app conditions, and check that direct service access and guest access are covered.
Do not simply exclude emergency administrators and leave password-only cloud access. Follow Microsoft's emergency-access design, including strong independent authentication and safely tested recovery.
Section 05
Number matching for Microsoft Authenticator
Number matching is enabled for Microsoft Authenticator push notifications. The former opt-out toggle is unavailable. Register Authenticator for the intended users and test the actual flow; same-device sign-in behaviour can differ from a separate-device prompt.
Section 06
Admin account hardening
Cyber Essentials requires separate administrative accounts and MFA where available, always for cloud services. It does not mandate FIDO2-only access or ban administrator SMS.
We recommend phishing-resistant passkeys or security keys for privileged roles. If you adopt an authentication-strength policy, first enrol supported credentials, provide recovery credentials independent of the normal device, and test the policy safely. A product name or enrolment screenshot does not prove that sign-in uses the intended strength.
Section 07
Legacy authentication
Basic authentication can bypass an MFA policy. POP, IMAP and SMTP AUTH can also use modern OAuth authentication, so do not treat those protocol names as proof of a bypass.
Review sign-in logs for legacy client use, identify the application and its authentication mode, migrate to a supported modern flow, and enforce the corresponding block policy. Confirm representative applications still work after the change.
Section 08
SMS as a fallback
The NCSC baseline recognises SMS but recommends suitable alternatives. Choose allowed methods according to accessibility, product support and risk. A stricter administrator-method policy is hardening, not a scheme-wide SMS prohibition.
Section 09
What to show the assessor
Is MFA enforced?
Show the effective Security Defaults or Conditional Access configuration and representative sign-in evidence. Registration reports are useful supporting evidence but do not demonstrate enforcement alone.
How are admins protected?
Show unique admin identities, separate ordinary-use accounts and the actual MFA flow. Include recovery design where relevant; FIDO2-only policies are optional hardening.
Can legacy clients bypass protection?
Show the applicable block or modern-authentication configuration and testing. An empty log filter alone does not establish that every possible bypass has been blocked.
Prepare evidence of the controls you actually operate. Discuss technical limitations with the certification body before relying on an exclusion.
Start Cyber Essentials | Buy CE Micro £299.99 | Read the MFA pillar
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Multi-factor authentication for Cyber Essentials v3.3: the complete pillar guide
MFA is the single most common reason Cyber Essentials v3.3 submissions fail. This pillar explains which accounts need MFA, which methods are acceptable, and how to implement it across Microsoft 365, Google Workspace, and line-of-business SaaS.
Read articleTechnical Guides
MFA for Google Workspace: the Cyber Essentials v3.3 setup
Google Workspace 2-Step Verification for Cyber Essentials v3.3: enrolment, effective enforcement, administrator recovery and current OAuth client guidance.
Read articleTechnical Guides
MFA conditional access under Cyber Essentials v3.3: what works, what fails
Review Conditional Access for Cyber Essentials v3.3: effective MFA, location exclusions, authenticated sessions, device trust and safe administrator recovery.
Read article

