Microsoft 365 Security Defaults Rollout (October 2019)
Microsoft automatically enabled baseline security settings for new Azure AD and Microsoft 365 tenants, including mandatory MFA for administrators, blocked legacy authentication, and required MFA for privileged activities. Existing tenants could opt in manually but weren't automatically migrated. The initiative aimed to protect small and medium businesses lacking dedicated security teams.
Adoption reached 30% of eligible tenants within first year; most enterprises opted out in favor of custom conditional access policies.
Established precedent for Microsoft forcing security features on by default, reducing account takeover attacks across the ecosystem.
The 2026 Teams activation follows the same playbook but applies to existing tenants, not just new ones—a far more aggressive intervention.
