IMPORTANT: Disabling security defaults lowers your tenant's security posture. Before proceeding, plan a replacement approach using Conditional Access policies or per-user MFA to avoid leaving the tenant unprotected. Document the business reason and obtain approval as this is a high-risk change.
Overview
Security defaults in Microsoft Entra ID automatically enforce multi-factor authentication (MFA) for users and administrators. This guide explains how to disable security defaults in the Entra admin center if MFA enforcement needs to be removed from the tenant.
Prerequisites
- A Global Administrator or Conditional Access Administrator account
- Access to the Microsoft Entra admin center at entra.microsoft.com
- A replacement security approach planned (Conditional Access or per-user MFA) before disabling security defaults
Step 1 - Sign In to the Entra Admin Center
- Go to entra.microsoft.com
- Sign in with a Global Administrator or Conditional Access Administrator account
Step 2 - Navigate to Security Defaults
- In the left navigation, expand Identity
- Click Overview
- Click Properties
- Scroll to the bottom of the Properties page and click Manage security defaults
Step 3 - Disable Security Defaults
- Click the Security defaults dropdown and select Disabled
- Select a reason for disabling security defaults when prompted
- Click Save
- When the confirmation prompt appears, click Disable to confirm
Step 4 - Verify Security Defaults Are Disabled
- Return to Identity > Overview > Properties
- Scroll down to the Security defaults section - you should see the warning message "Your organization is not protected by security defaults"
- Test sign-in with a non-admin user account to confirm MFA prompts have stopped
If Users Are Still Being Prompted for MFA
MFA prompts can be caused by more than just security defaults. If prompts continue after disabling, check the following:
- Conditional Access policies: go to Entra admin center > Protection > Conditional Access > Policies and look for any policies requiring MFA
- Per-user MFA (legacy): go to Entra admin center > Users > All users > Multi-factor authentication