Most generic cyber security advice says “just turn on multi-factor authentication.” For a school, that sentence hides a decision a board should actually be making on purpose, not by accident.
Multi-factor authentication is consistently the single biggest reduction in breach risk for the effort involved, and it’s one of the eight ASD mitigation strategies for exactly that reason. The generic advice to “enable Security Defaults” isn’t wrong for a typical business. It’s incomplete for a school, because a school has a population problem most businesses don’t: a few dozen staff, and potentially thousands of student accounts belonging to children as young as five, many of whom share a device with a sibling and don’t own a personal phone.
What Security Defaults actually does, and why that’s a governance question
Security Defaults is Microsoft’s free, tenant-wide MFA switch. Flip it on, and it applies to every account in the tenant, with almost no ability to exclude specific groups. For a business, that’s a reasonable one-step fix. For a school, it means mandating MFA registration for every student account at the same time as every staff account, with no built-in way to say “not yet” for the population that can’t practically comply.
That’s not a technical detail. It’s a decision with real consequences: children who can’t complete registration get locked out of learning platforms mid-lesson, IT support tickets spike from parents and students who don’t understand what’s happening, and a control meant to reduce risk ends up disrupting the school’s core function instead. Whoever flips that switch on a Friday afternoon without a plan has made a decision that should have gone through the same sign-off as any other change touching every student in the school. Most of the time, nobody intended to make that decision, it just happened as a side effect of “doing the right thing” on MFA.
The licence fork that determines whether you even have a choice
Whether a school can avoid this all-or-nothing trap depends entirely on licence tier, and this is worth stating in board-ready terms rather than leaving it to IT to explain informally.
Schools on a paid education tier, Microsoft 365 A3, A5, or anything that already includes Entra ID P1, already have Conditional Access at no extra cost. That means a single, targeted policy: include all users, exclude a “students” or “no-MFA-required” group. MFA lands on staff and admin accounts without touching student logins at all. This is the governance-safe path, and it costs nothing beyond configuration time if your licence already includes it.
Schools on the free Entra ID tier only, the standard Microsoft 365 A1 with no P1, don’t have Conditional Access available. Security Defaults is genuinely the only lever, and it remains all-or-nothing. In that situation, the honest advice isn’t “don’t bother”, it’s “sequence it deliberately”: get every admin and staff account onto MFA first, and treat the student rollout as a separate decision that goes to the board or executive team explicitly, alongside the question of whether upgrading even a subset of licences to unlock P1 is affordable. That’s a genuine resourcing trade-off worth naming, not something to quietly work around.
The deadline that isn’t optional, regardless of licence tier
Separate from the population question: Microsoft’s staged mandatory MFA enforcement for administrative sign-ins reached its final phase, with the last extension window closing 1 July 2026. This is specific to admin and management-plane sign-ins, Global Admin, Azure, Entra, and Intune admin centre access, not a blanket requirement on every account. If your school’s admin accounts don’t have MFA enforced already, that’s not a future risk to plan around, it’s a compliance gap that may already be affecting portal access today, and it applies regardless of which licence tier you’re on.
Where this leaves you
The question worth putting to your board isn’t whether MFA is a good idea, everyone already agrees it is. It’s whether the school has made a deliberate, documented decision about how MFA applies to a student population that a generic “just turn it on” answer was never built for.
Best Practice - This is the way
Sources
- Microsoft Learn: Microsoft Entra ID Plan 1 for Microsoft 365 Education.
- Microsoft Learn: Configure security defaults.
- This edition assumes a documented asset register is already in place; see the crown jewels register edition if it isn’t yet.