How to disable MFA / Security Defaults on Office 365


Security Defaults are a series of settings enabled by default on your Microsoft Office 365 account, to provide greater security. Every user is required to log in using Multi-Factor Authentication (MFA). Security Defaults also blocks connections from legacy email clients and disallows the use of email protocols like IMAP, POP3 and SMTP. For more information on what these Security Defaults do, see Microsoft's documentation.

If you need to connect without Multi-Factor Authentication or disable Security Defaults for another reason, you can do so as follows:


Step 1 - Log into your Office 365 management area as shown in this guide.

14292ceb6c0b501bad5d64025eb73a5cd50dbb10?t=d0dfc53cc7007d7e960c0db41360a7f2



Step 2 - Click on Admin. 

7c854845f7a14fbe772037a8397eba6d165e4ac3?t=13503dc9b46255bb4f024a516f1dee2a



Step 3 - Click on Azure Active Directory in the left hand column. If it's not present for you, select Show All to expand the menu.

fa0e4f8cd9e93c3736fa85a0f99b8f1834a21393?t=d61266254b04d21af768db59fe4ebf68



Step 4 -
(1) Select Azure Active Directory again.
(2) Select Properties.
(3) Select Manage Security Defaults.

6907959948902f3ef7e4345d46ad9db75375cae5?t=c15f01ce1c3f73fbaf05328973445a0e



Step 5 - Select No under Enable Security Defaults, then select Save.

6b2606f368c0ffee2e03b2cc11a3dc11f81dd7f2?t=e130e5fb965be76402cadff5c1c2b463



Step 6 - You will get a Success message indicating that Security Defaults has been disabled.

c0ceec4815eae8afeb77c47e7ec95f66b4c23949?t=292da405ceb11c731095b77f70ea15de



At this point, you will no longer be prompted to set up Multi-Factor Authentication when logging in. To authenticate with Legacy email clients, you will also need to follow Microsoft's guide here to manually re-enable IMAP and SMTP. If you have already set up Multi-Factor Authentication and you wish to remove it, follow these additional steps:



Step 7 - Return to the Office 365 Admin area and select Users then Active Users in the left menu. Select Multi-Factor Authentication on the Users page.

31ccea3da95770caa0639917557b8f2d0f5f6529?t=71a5dafd655478cccaf15cb1bb45ff27



Step 8 - Click on the Select All box, then click on Enable.

Usually if MFA is enabled, it will display an 'Enabled' status next to the user. MFA that was created when Security Defaults was active does not update this section properly. In order to disable MFA, we will need to enable it and then disable it in this section.

ea96c0c034d2f90c5129b029c351db7abdb06cd9?t=62c225a4394900738579be9577195df4


Step 9 - Select Enable multi-factor authentication, then close.

d277d7dc471baa119741a9f59cd80479d4d16769?t=46fce24a06c909e2dbe481240117b8af



Step 10 - Select the O365 account(s) you want to disable MFA for, then select Disable.

049d599785cf7ac454ee1044a4449700ac5d6c04?t=71da679ddba86725e21e01e954ce6d09



Step 11 - Select Yes then Close.

33c08850fd1f30a2925983ffee9cc8eb21b64d2a?t=2f1bce13a5e6b0ab3cdca028dabe0684


For more information and tutorials on Office 365, see our Getting Started guide.


Did you find this article useful?