A small ferry cooperative still on Microsoft Entra security defaults wants per-group MFA exceptions for a vendor. What must the security engineer understand before creating Conditional Access policies?
Select an answer to reveal the explanation.
Short Explanation
Security defaults are the one-switch floodlight—everyone gets MFA, no vendor carve-outs. Need exceptions? Flip defaults off and rebuild the protection with Conditional Access (that path needs the right Entra license).
Full Explanation
Microsoft Entra security defaults provide baseline MFA protection without fine-grained exclusions and are mutually exclusive with Conditional Access as the primary enforcement model. Organizations that need per-group exceptions disable security defaults and implement Conditional Access policies, which generally require Microsoft Entra ID P1 or higher.