How to Configure Microsoft Entra Security Defaults and MFA for Office Apps
Question details
Administrators need to enable Microsoft Entra Security Defaults and guide users through registering for multifactor authentication (MFA) across their devices.

- Product
- Microsoft Entra, Microsoft Office
- Device & OS
- Windows, macOS, iOS, Android
- Scenario
- An organization is rolling out mandatory multifactor authentication by scheduling Microsoft Entra Security Defaults to be enabled for all users.
- Observed behavior
- When signing in to Office desktop applications or mobile Microsoft services, users are prompted to register an approved authentication method to proceed.
Ensure you have global administrator access to the Microsoft Entra admin center, and advise your users to download the Microsoft Authenticator app on their mobile devices beforehand.
Enable Security Defaults in Microsoft Entra Admin Center
Use this solution if you are an administrator tasked with enforcing MFA and basic identity protections across your entire Microsoft 365 or Office organization.
Enabling security defaults is a quick and effective way to protect your organization from identity-related attacks. It requires all users to register for MFA and automatically challenges them when signing in from new devices or locations.
Open a web browser and sign in to the Microsoft Entra admin center using an account with Global Administrator permissions.
On the left-hand navigation menu, expand the 'Identity' section and click on 'Overview'.
Click on 'Properties' from the Overview menu to view your tenant's core configurations.
Scroll to the bottom of the Properties page and click the 'Manage security defaults' link. A side pane will appear.
In the 'Security defaults' pane, toggle the setting from Disabled to Enabled, then click 'Save' at the bottom. Your organization will now begin enforcing MFA.

Register for MFA as an Office User
Follow these steps for end-users who are prompted to register an authentication method when opening an Office app like Word or Excel.
Experience Hassle-Free Document Management with WPS Office
Enterprise-level administration and mandatory multifactor authentication setups in Microsoft Entra can be complex and time-consuming. If you are looking for a powerful, lightweight office suite that requires zero administrative overhead while delivering top-tier performance, WPS Office is the perfect alternative.
- 1. Download the Installer: Visit the official WPS Office website and click the 'Free Download' button for your specific operating system.
- 2. Install the Application: Run the downloaded executable file and follow the straightforward on-screen installation wizard.
- 3. Start Creating Instantly: Launch WPS Office and immediately begin working on your documents, spreadsheets, and presentations without jumping through security hoops.

Frequently Asked Questions
How long do users have to register for MFA after Security Defaults are enabled?
Users have a 14-day grace period to register their multifactor authentication method using the Microsoft Authenticator app. The 14-day period begins the first time a user successfully signs in after Security Defaults have been enabled. After 14 days, they will be blocked from accessing Office apps until they complete the MFA registration.
Can users use a third-party authenticator app instead of Microsoft Authenticator?
Yes. Although Microsoft highly recommends using the Microsoft Authenticator app for push notifications, users can click 'I want to use a different authenticator app' during setup. This allows them to configure any OATH TOTP authenticator (like Google Authenticator or Authy) by scanning a QR code.
Will users be prompted for MFA every time they open Word or Excel?
No. Microsoft Entra utilizes token-based authentication. Users typically only receive an MFA prompt when they sign in on a new device, connect from an unfamiliar network location, or when their current authentication token expires.
Why is the 'Manage security defaults' option greyed out in Microsoft Entra?
The option to enable security defaults is often greyed out or unavailable if your organization currently has Conditional Access policies actively enabled. You must disable existing Conditional Access policies or use a Global Administrator account to make changes to Security Defaults.




