Security Defaults vs Conditional Access Policies for Businesses

Do any of these security features align with your current needs?

Security Defaults vs Conditional Access Policies for Businesses

Conditional Access Policies provide the granular control and customization that larger organizations or managed service providers need, whereas Security Defaults offer only a basic baseline and lack bypass options for specific users or services.

Implementing Conditional Access requires Azure AD Premium P1 licenses for every account involved, making it a potential cost hurdle compared to the baseline alternative.

Overly strict security measures often backfire by hindering productivity and pushing users to find risky workarounds, so it is best to keep security proportionate and user-friendly.

Security Defaults vs Conditional Access Policies for Businesses — infographic

Users suggest that Security Defaults may not align with the needs of larger organizations or those requiring fine-grained control, as Conditional Access Policies offer more flexibility. However, for smaller businesses or those with limited IT resources, Security Defaults can be a sufficient baseline.

Conditional Access Policies vs. Security Defaults

Conditional Access Policies offer more control and customization. Users emphasize that Conditional Access Policies (CAP) provide extensive control over security settings, which is essential for complex environments. "Conditional Access Policies are what an MSP should use as it gives you control and tools to manage this process."
Security Defaults are a good baseline but lack granular control. While Security Defaults are better than no security, they are often seen as insufficient for organizations that need to bypass MFA for specific users or services. "You get no control over security defaults."
Licensing is a consideration for Conditional Access Policies. Implementing CAP typically requires Azure AD Premium P1 licenses for all users covered by the policies, which can be a cost factor for some businesses. "Being very specific, you need an AAD P1 license for every account that's using Conditional Access."

Balancing Security and Usability

Overly strict security measures can hinder productivity. Users report that security features that are too intrusive, such as blocking USB devices or certain websites, can prevent employees from performing their jobs effectively. "I mean, I can't access a USB device, I can't email attachments."
Excessive security can lead to workarounds and increased risk. When security is too cumbersome, users may seek ways to bypass it, potentially creating greater security vulnerabilities. "The problem here is that eventually that can lead to users doing even worse things to circumvent that security."
Security should be proportionate and user-friendly. Effective security balances protection with usability, ensuring that measures are reasonable and don't unduly impede workflows. "Security measures should be reasonable and proportionate."

Specific Security Feature Experiences

Secure Boot and BitLocker can be complex to configure. Users have encountered issues when trying to combine Secure Boot and BitLocker, particularly when Secure Boot modes are incorrectly set. "If Secure Boot is in Setup/Custom Mode during imaging and you change it to User/Standard Mode afterward, the PCR 7 value changes and BitLocker can no longer unseal its keys."
Microsoft security updates can sometimes cause unexpected issues. Some Users have experienced problems with features like File Explorer previews or Quick Assist after Microsoft security updates, requiring workarounds or uninstallation of updates. "File Explorer Preview stopped with the most recent security update (KB5066835)"
Security awareness training platforms vary in effectiveness. While many platforms exist, Users note that the quality and relevance of content can differ, with some finding older content "meh or out of date."

Do these distinctions between Security Defaults and Conditional Access Policies help clarify which might be a better fit for your organization?

Pros & cons
Pros
Conditional Access offers extensive control and customization.
Security Defaults provide a quick baseline for small businesses.
Proportionate security keeps workflows functional.
Cons
Conditional Access requires premium licensing.
Security Defaults lack granular control and bypass options.
Overly strict settings push users toward risky workarounds.

Best for: Organizations needing fine-grained security control should consider Conditional Access, while small businesses with limited IT resources might find Security Defaults sufficient.

FAQ
Do I need a special license for Conditional Access Policies?
Yes, you need an Azure AD Premium P1 license for every account covered by the policies.
What happens if security settings are too restrictive?
Strict settings can stop employees from working effectively, which often leads them to bypass the rules and create larger vulnerabilities.
Can I bypass MFA for specific users with Security Defaults?
No, Security Defaults give you no control over the settings, so you cannot make exceptions for specific users or services.
What issues occur when combining Secure Boot and BitLocker?
If Secure Boot is changed from Setup or Custom Mode to User or Standard Mode after imaging, the PCR 7 value changes and BitLocker will fail to unseal its keys.
Comments (0)

No comments yet. Start the conversation.