StudyToCert

All certifications / SC-300 / Lessons

Microsoft Certified: Identity and Access Administrator Associate SC-300 (skills outline of April 27, 2026) · Domain 2: Implement authentication and access management

Security defaults vs Conditional Access, and emergency access (break-glass) accounts

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Security defaults are a free, one-switch set of identity protections that Microsoft enables for new tenants. They require all users to register for multifactor authentication (with a grace period after which registration is enforced), require administrators to perform MFA every time they sign in, prompt users for MFA when Microsoft judges it necessary, block legacy authentication protocols that can't do MFA, and protect privileged activities such as access to the Azure portal. Security defaults steer users to register Microsoft Authenticator as their MFA method. There is nothing to tune: no exclusions, no locations, no per-app rules.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-300 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-300 study plan