Enforce MFA with Conditional Access — coverage is the threshold, not existence
Every renewal questionnaire asks some version of "is MFA enforced for all users?" and most tenants that answer yes are running a policy that covers some users. The framework bar is stricter: CIS M365 v6 (5.2.2.2) and CISA SCuBA (MS.AAD.3.2) require an enabled Conditional Access policy targeting All users and All cloud resources with the grant set to require MFA. A policy scoped to a pilot group, one admin role, or a handful of apps does not establish tenant-wide coverage, however long it has been enabled.
The part checklists get wrong
Three enforcement mechanisms can coexist in one tenant — Security Defaults, legacy per-user MFA, and Conditional Access — and each one can mask gaps in the others. A checklist that verifies "MFA is on" without saying which mechanism, at what scope, produces a yes that falls apart under review.
Security Defaults vs Conditional Access, honestly
Security Defaults costs nothing, requires no licensing, and blocks legacy authentication as a side effect. What you give up: no assignment scope, no exclusions, no report-only mode, and no named policy to export as evidence — Microsoft decides when to prompt. Conditional Access requires Entra ID P1 and gives you all four. If your licensing includes P1, use it. If it doesn't, Security Defaults is a supported configuration, not a lesser one for its tier — and it's how tenants without the Conditional Access capability should answer the questionnaire.
The migration window is where tenants get hurt. Enabling CA policies means turning Security Defaults off, and the tenant that disables Security Defaults before its CA policy is built and tested in report-only has an enforcement gap it created itself. Order of operations: build the policy, run report-only for a few days, enable, then disable Security Defaults.
Per-user MFA is debt — retire it
The per-user Enabled/Enforced states predate Conditional Access and coexist with it silently. They generate no policy evidence, interact unpredictably with CA prompts, and give your MFA story a second enforcement path a reviewer will eventually ask about. After the CA policy is enforced, set every user to Disabled: Entra admin center → Users → Per-user MFA. Note that a healthy CA policy proves nothing here — CA and stale per-user states coexist by design, which is why this is a separate control with its own evidence.
The policy, and break-glass done right
Entra admin center → Protection → Conditional Access → New policy: All
users, All cloud resources (previously "All cloud apps"), Grant → Require
multifactor authentication. Name it so an auditor can read it —
CA-Require-MFA-AllUsers.
Unlike the legacy-auth block, this policy conventionally carries an exclusion: your emergency-access accounts. Done right, that means the exclusion list contains exactly those accounts and nothing else. Two cloud-only accounts, excluded by name, credentials stored offline (or FIDO2 keys in a safe), an alert rule on every sign-in, and a dated test twice a year. A break-glass exclusion is defensible; a break-glass exclusion plus a service account added "temporarily" is the start of exclusion creep.
What a renewal reviewer actually accepts
A dated export, not a screenshot: the enabled policy with its full assignment scope showing All users and All cloud resources, the exclusion list with the named break-glass accounts and a one-line justification each, and the per-user MFA report showing every user Disabled. The exclusion list and the per-user report are the two artifacts reviewers have learned to ask for; volunteering both up front shortens the exchange.
How Calibrant checks this
The Conditional Access check requires tenant-wide coverage — a policy protecting only a group, role, or selected application does not pass. Scoring is capability-based: a tenant without the Entra ID P1 service plan is measured on the Security Defaults path instead of failing a control its licensing can't satisfy. Per-user MFA retirement is a separate check, and one that allows manual review by design, because the presence of CA or Security Defaults cannot prove the legacy states were retired. The output is a dated assessment report built for the renewal exchange above.
Early access is by invite — code SEO-MFA-CA at calibrant.ai.