Skip to content
Technical Guides

MFA for Microsoft 365: the Cyber Essentials v3.3 configuration

Configure Microsoft 365 MFA for Cyber Essentials v3.3: Security Defaults and Conditional Access, current number matching, administrator recovery and evidence of enforcement.

A glossy glass cube with the Microsoft logo o

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

10 min read

Share

Section 01

MFA for Microsoft 365: the Cyber Essentials v3.3 configuration

Microsoft 365 cloud-service authentication must use MFA. This guide shows how to choose and verify Microsoft enforcement controls, with recovery planned before rollout. Read the MFA pillar for the scheme requirements.

Section 02

Security Defaults vs Conditional Access

Security Defaults

Microsoft's baseline is available without a separate premium MFA policy licence. It requires MFA registration, protects administrators and prompts ordinary users according to Microsoft's documented behaviour. It blocks legacy authentication. There is no Cyber Essentials fifty-user cutoff or ninety-percent coverage allowance.

Conditional Access

Requires an appropriate licence, such as Entra ID P1. Use it when you need granular targeting, authentication strengths or session controls. The need follows the implementation and licence, rather than an arbitrary staff count.

Microsoft's current documentation explains both options. Security Defaults does not demand a fresh MFA prompt on every ordinary-user sign-in. Assess the effective authentication and session controls for your scope instead of inferring a pass from the policy name.

Section 03

Security Defaults configuration

1. Sign in to the Entra admin centre with an appropriate role. Follow Entra ID → Overview → Properties → Manage security defaults.

2. Prepare supported authentication methods and recovery, then enable the setting.

3. Verify registration in Authentication methods → User registration details, and separately verify sign-in enforcement.

4. Investigate accounts and applications still using basic authentication before retiring their access route.

Microsoft removed the fourteen-day registration grace on 29 July 2024. Do not wait fourteen days on the assumption that registration or enforcement will become compliant automatically.

Section 04

Conditional Access configuration

For a broad baseline, target all relevant users and cloud resources and require multifactor authentication in the Grant controls. Review technical identities and emergency access before applying the policy. Use report-only mode to understand impact, test representative users, then enable enforcement once recovery is ready. Report-only mode does not enforce MFA.

Create an additional policy blocking legacy authentication clients where needed. Inspect Microsoft sign-in logs and current client-app conditions, and check that direct service access and guest access are covered.

Do not simply exclude emergency administrators and leave password-only cloud access. Follow Microsoft's emergency-access design, including strong independent authentication and safely tested recovery.

Section 05

Number matching for Microsoft Authenticator

Number matching is enabled for Microsoft Authenticator push notifications. The former opt-out toggle is unavailable. Register Authenticator for the intended users and test the actual flow; same-device sign-in behaviour can differ from a separate-device prompt.

Section 06

Admin account hardening

Cyber Essentials requires separate administrative accounts and MFA where available, always for cloud services. It does not mandate FIDO2-only access or ban administrator SMS.

We recommend phishing-resistant passkeys or security keys for privileged roles. If you adopt an authentication-strength policy, first enrol supported credentials, provide recovery credentials independent of the normal device, and test the policy safely. A product name or enrolment screenshot does not prove that sign-in uses the intended strength.

Section 07

Legacy authentication

Basic authentication can bypass an MFA policy. POP, IMAP and SMTP AUTH can also use modern OAuth authentication, so do not treat those protocol names as proof of a bypass.

Review sign-in logs for legacy client use, identify the application and its authentication mode, migrate to a supported modern flow, and enforce the corresponding block policy. Confirm representative applications still work after the change.

Section 08

SMS as a fallback

The NCSC baseline recognises SMS but recommends suitable alternatives. Choose allowed methods according to accessibility, product support and risk. A stricter administrator-method policy is hardening, not a scheme-wide SMS prohibition.

Section 09

What to show the assessor

Is MFA enforced?

Show the effective Security Defaults or Conditional Access configuration and representative sign-in evidence. Registration reports are useful supporting evidence but do not demonstrate enforcement alone.

How are admins protected?

Show unique admin identities, separate ordinary-use accounts and the actual MFA flow. Include recovery design where relevant; FIDO2-only policies are optional hardening.

Can legacy clients bypass protection?

Show the applicable block or modern-authentication configuration and testing. An empty log filter alone does not establish that every possible bypass has been blocked.

Prepare evidence of the controls you actually operate. Discuss technical limitations with the certification body before relying on an exclusion.

Start Cyber Essentials | Buy CE Micro £299.99 | Read the MFA pillar

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group