Most generic cyber security advice says “just turn on multi-factor authentication.” For a school, that sentence hides a decision a board should actually be making on purpose, not by accident.

Multi-factor authentication is consistently the single biggest reduction in breach risk for the effort involved, and it’s one of the eight ASD mitigation strategies for exactly that reason. The generic advice to “enable Security Defaults” isn’t wrong for a typical business. It’s incomplete for a school, because a school has a population problem most businesses don’t: a few dozen staff, and potentially thousands of student accounts belonging to children as young as five, many of whom share a device with a sibling and don’t own a personal phone.

What Security Defaults actually does, and why that’s a governance question

Security Defaults is Microsoft’s free, tenant-wide MFA switch. Flip it on, and it applies to every account in the tenant, with almost no ability to exclude specific groups. For a business, that’s a reasonable one-step fix. For a school, it means mandating MFA registration for every student account at the same time as every staff account, with no built-in way to say “not yet” for the population that can’t practically comply.

That’s not a technical detail. It’s a decision with real consequences: children who can’t complete registration get locked out of learning platforms mid-lesson, IT support tickets spike from parents and students who don’t understand what’s happening, and a control meant to reduce risk ends up disrupting the school’s core function instead. Whoever flips that switch on a Friday afternoon without a plan has made a decision that should have gone through the same sign-off as any other change touching every student in the school. Most of the time, nobody intended to make that decision, it just happened as a side effect of “doing the right thing” on MFA.

The licence fork that determines whether you even have a choice

Whether a school can avoid this all-or-nothing trap depends entirely on licence tier, and this is worth stating in board-ready terms rather than leaving it to IT to explain informally.

Schools on a paid education tier, Microsoft 365 A3, A5, or anything that already includes Entra ID P1, already have Conditional Access at no extra cost. That means a single, targeted policy: include all users, exclude a “students” or “no-MFA-required” group. MFA lands on staff and admin accounts without touching student logins at all. This is the governance-safe path, and it costs nothing beyond configuration time if your licence already includes it.

Schools on the free Entra ID tier only, the standard Microsoft 365 A1 with no P1, don’t have Conditional Access available. Security Defaults is genuinely the only lever, and it remains all-or-nothing. In that situation, the honest advice isn’t “don’t bother”, it’s “sequence it deliberately”: get every admin and staff account onto MFA first, and treat the student rollout as a separate decision that goes to the board or executive team explicitly, alongside the question of whether upgrading even a subset of licences to unlock P1 is affordable. That’s a genuine resourcing trade-off worth naming, not something to quietly work around.

The deadline that isn’t optional, regardless of licence tier

Separate from the population question: Microsoft’s staged mandatory MFA enforcement for administrative sign-ins reached its final phase, with the last extension window closing 1 July 2026. This is specific to admin and management-plane sign-ins, Global Admin, Azure, Entra, and Intune admin centre access, not a blanket requirement on every account. If your school’s admin accounts don’t have MFA enforced already, that’s not a future risk to plan around, it’s a compliance gap that may already be affecting portal access today, and it applies regardless of which licence tier you’re on.

Where this leaves you

The question worth putting to your board isn’t whether MFA is a good idea, everyone already agrees it is. It’s whether the school has made a deliberate, documented decision about how MFA applies to a student population that a generic “just turn it on” answer was never built for.

Best Practice - This is the way

Check your Entra admin centre for your actual licence tier before planning anything. Confirm whether Conditional Access is already sitting there unused, rather than assuming your tier’s coverage.
If you have P1, build one Conditional Access policy scoped to staff and admin, and explicitly exclude students for now. That’s the governance-safe default for anyone with the option available.
If you’re on the free tier, cover every admin account this week regardless. The enforcement deadline has already passed; this isn’t a scheduling choice.
Take the student MFA decision to the board or executive team explicitly if you’re on the free tier. Whether to hold off, or to fund a partial licence upgrade, should be a documented decision, not a default.
Push whoever does get MFA towards an authenticator app with number matching, not SMS. It’s free, and SMS carries SIM-swap risk plus a per-message cost at scale.
Treat student digital identity as its own governance topic, not a footnote here. Age, device ownership, and privacy obligations for student accounts deserve a dedicated conversation, not a rushed decision made under the same deadline pressure as the staff rollout.

Daniel Johns is a CRISC-certified virtual CISO and GRC advisor, Founder of Coastal Cyber, and a former member of the ISACA Global Advisory Council and CompTIA Executive Council ANZ. He works with independent and faith-based schools, healthcare providers, financial services, technology businesses, and MSPs across Southeast Queensland on privacy, cyber security, and governance.

If your school’s privacy and cyber posture needs a clear-eyed assessment, book a 20-minute conversation.

Sources

  1. Microsoft Learn: Microsoft Entra ID Plan 1 for Microsoft 365 Education.
  2. Microsoft Learn: Configure security defaults.
  3. This edition assumes a documented asset register is already in place; see the crown jewels register edition if it isn’t yet.