July 4, 2024, 2:50 p.m. | /u/tech_london

cybersecurity www.reddit.com

Has anyone observed any inconsistencies with the MFA enforcement under Microsoft 365's security defaults? In some cases, users can log in without being prompted for MFA, especially when using test accounts on VMs or Sandboxes. Despite having security defaults turned on, these logins sometimes bypass MFA.

I know that conditional access policies offer a more reliable solution, but not everyone opts for them. I'm curious if others have faced similar issues and if there are specific factors, like …

access accounts bypass can cases conditional conditional access cybersecurity default enforcement log logins mfa microsoft microsoft 365 microsoft 365 security offer policies sandboxes security test under using vms

Technology Risk & Controls Manager

@ LegalAndGeneral | London, United Kingdom

Solutions Architect - Prisma Cloud

@ Palo Alto Networks | Munich, Germany

Security Operations Engineer

@ Cognite | Oslo

Ingénieur Cybersécurité PKI

@ Alter Solutions | PARIS, France

Cyber Security Project Engineer

@ Dezign Concepts LLC | Chantilly, VA

Cloud Cybersecurity Incident Response Lead

@ Maveris | Martinsburg, West Virginia, United States