Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To reduce the risk of Microsoft 365 account takeover, require multifactor authentication (MFA) for every user, block legacy authentication, and use phishing-resistant MFA for administrators wherever possible. Keep emergency administrator accounts available, and choose either Security Defaults for a simple baseline or Conditional Access for licensed tenants that need more control. Roll out changes carefully: an incorrectly scoped policy or an unsupported sign-in method can lock people out.

Check which sign-in protections your tenant uses

Before changing settings, check whether Microsoft Entra Security Defaults is enabled and whether the tenant already uses Conditional Access. The two approaches cannot be enabled together. If you plan to replace Security Defaults with Conditional Access, prepare equivalent protections first rather than turning the baseline off and leaving a gap.

Decision Security Defaults Conditional Access
License Available with Microsoft Entra ID Free. Requires Microsoft Entra ID P1 or P2.
Configuration A simple on/off baseline with no policy customization. Customizable policies, scope, and conditions.
Protections to account for Includes MFA requirements and blocks legacy authentication. When migrating, recreate equivalent baseline controls, including MFA for users and administrators and legacy authentication blocking.
Best fit Organizations that need a straightforward baseline. Organizations with the required license that need granular controls or exceptions.

Microsoft’s Security Defaults documentation and Microsoft 365 MFA setup guide describe these options and their licensing. Check current licensing before making a purchase or policy decision, since plan packaging can change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure administrator accounts first

Administrative identities can change tenant settings and user access, so protect them before broad rollout. Identify accounts assigned built-in privileged roles and require MFA. Prioritize phishing-resistant MFA for roles such as Global Administrator, Application Administrator, Authentication Administrator, Conditional Access Administrator, Exchange Administrator, Privileged Authentication Administrator, Privileged Role Administrator, Security Administrator, SharePoint Administrator, and User Administrator, as well as other built-in administrator roles.

#1 Best Overall
Microsoft 365 Personal | 12-Month Subscription | 1 Person | Premium Office Apps: Word, Excel, PowerPoint and more | 1TB Cloud Storage | Windows Laptop or MacBook Instant Download | Activation Required
  • Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
  • Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
  • 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
  • Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
  • Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.

Microsoft’s guidance for Conditional Access policies targeting built-in directory roles does not automatically cover custom roles or roles scoped to administrative units. Check those assignments separately so privileged accounts are not missed. See Microsoft’s guidance on requiring phishing-resistant MFA for administrator roles.

  • Use separate standard and admin accounts. Use the standard account for daily work such as email and Microsoft 365 apps, and reserve the admin account for administrative tasks.
  • Keep the number of administrator accounts low and assign each administrator only the role needed for their work.
  • Register and test the authentication methods administrators will need before enforcing a new requirement.

Microsoft’s Microsoft 365 business admin-account guidance recommends separate daily-use and administrative accounts, least privilege, and emergency access accounts.

Choose phishing-resistant MFA for privileged users

Standard MFA is an important baseline, but some methods are more resistant to phishing than others. Microsoft identifies passkeys, FIDO2 security keys, Windows Hello for Business, and certificate-based authentication as phishing-resistant methods. FIDO2 security keys use hardware-backed cryptographic proof. A security key is an optional authenticator, not a complete solution by itself: the tenant must support and configure the method, users must register it, and the organization needs a recovery plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Methods such as SMS or voice can be vulnerable to adversary-in-the-middle interception and social engineering. Microsoft’s identity guidance describes passkeys and FIDO2 security keys as providing the strongest protection against credential theft and sophisticated phishing; this is Microsoft’s guidance, not an independent comparative test. Read Microsoft’s guidance on protecting identities and secrets.

Rank #3
Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
  • FIDO2 CERTIFIED: FIDO Alliance Certified FIDO2 v2.1 and CTAP Level 1 for 2FA and MFA on Google Microsoft Apple GitHub login.gov AGOV SwissID and any WebAuthn service
  • PASSKEY READY: Works as a hardware passkey for passwordless sign-in where the service enables it and as a U2F and WebAuthn security key everywhere else
  • CERTIFIED SECURITY: NXP JCOP 4.5 secure element rated Common Criteria EAL6+ (augmented)
  • TAP OR INSERT: Dual NFC ISO 14443 and contact ISO 7816 interface in an ID-1 format smart card that is passive and battery-free
  • BUILT TO LAST: Passive smart card made in Switzerland designed by Swiss company Cryptnox and backed by a 2 year manufacturer warranty

Roll out phishing-resistant requirements without locking out admins

  1. Confirm that the target users—especially administrators—have registered a supported phishing-resistant method.
  2. In Conditional Access, scope the policy to the relevant built-in directory roles and resources, and exclude designated emergency access accounts.
  3. Start the policy in report-only mode where available. Review its impact and verify the scope and exclusions before enforcement.
  4. Turn the policy on only after validation. If you use external authentication methods, Microsoft documents a compatibility limitation with authentication strengths; use the “Require multifactor authentication” grant control in that situation.

Microsoft warns that enforcing phishing-resistant MFA before administrators register suitable methods can lock them out. Its administrator policy guidance covers policy scope, report-only evaluation, and the external-authentication-method limitation.

Require MFA for everyone and block legacy sign-ins

Security Defaults provides a simple tenant-wide baseline. It requires users to register for MFA, prompts users for MFA when Microsoft determines it is needed, requires MFA for listed administrators at every sign-in after registration, and blocks legacy authentication, including Exchange ActiveSync basic authentication. It also blocks device code flow, so apps or devices that depend on that sign-in method cannot authenticate under Security Defaults.

Rank #4
Microsoft System Builder | Windоws 11 Home | Intended use for new systems | Install on a new PC | Branded by Microsoft
  • STREAMLINED & INTUITIVE UI, DVD FORMAT | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
  • OEM IS TO BE INSTALLED ON A NEW PC with no prior version of Windows installed and cannot be transferred to another machine.
  • OEM DOES NOT PROVIDE SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
  • PRODUCT SHIPS IN PLAIN ENVELOPE | Activation key is located under scratch-off area on label.
  • GENUINE WINDOWS SOFTWARE IS BRANDED BY MIRCOSOFT ONLY.

Inventory older clients, devices, and device-code-flow dependencies before enabling the baseline. Microsoft’s documentation recommends revoking existing sign-in tokens when enabling Security Defaults so users must authenticate and register for MFA. Follow the current Security Defaults setup guidance for the tenant.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft says MFA can block over 99.2% of identity-based attacks. That is Microsoft’s cited effectiveness claim, not a guarantee for a particular organization or a promise that MFA prevents the same percentage of account takeovers. Microsoft’s documentation also states that the MFA-registration grace period was removed starting July 29, 2024; verify current tenant behavior in Microsoft’s live guidance.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep emergency access for administrator lockouts

Microsoft recommends maintaining two cloud-only emergency access accounts, permanently assigned the Global Administrator role, for break-glass use. Exclude these designated accounts from Conditional Access policies that could otherwise lock out every administrator. Protect them as sensitive credentials, monitor their use, and follow Microsoft’s current emergency-access recommendations for credential protection and alerts. They are recovery paths, not accounts for routine administration.

Add device and sign-in risk controls where appropriate

Where the organization’s licensing and deployment support it, Conditional Access can require a managed or compliant device. This can help ensure that sign-ins meet organizational device controls and endpoint-protection requirements. Microsoft also describes risk-based Conditional Access as a way to block risky sign-ins or require stronger authentication; relevant Identity Protection capabilities are associated with Entra ID P2. These controls add context to the sign-in decision but should not replace strong authentication.

Microsoft discusses device and risk controls in its identity infrastructure security guidance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.