Turn on an MFA baseline.
Not a per-user rollout, not a pilot: an org-wide floor that a new hire lands inside on day one. Both vendors are moving toward making this mandatory anyway, so the only question is whether it happens on your schedule or theirs.
Microsoft 365
Turn on security defaults, which is free on every tier: Entra admin center > Entra ID > Overview > Properties > Manage security defaults
It enforces six things, including MFA registration for all users, MFA for administrators across 16 roles, blocking legacy authentication and blocking device code flow. Tenants created on or after 22 October 2019 have it on already, with a 24-hour grace period, and the 14-day MFA-registration grace period was removed on 29 July 2024. From 1 July 2026, new tenants also block device code flow.
On Business Premium you can go further with Conditional Access, but read the sequencing: Microsoft’s documentation states that organizations choosing Conditional Access policies to replace security defaults “must disable security defaults.” Start any Conditional Access policy in Report-only.
Also worth knowing, and new enough that most material misses it: Baseline Security Mode is configurable on all Microsoft 365 subscriptions and plans, at Settings > Org Settings > Security and Privacy tab > Baseline Security Mode It carries org-wide switches to block basic authentication, block legacy auth flows, restrict end-user consent, and disable organization-wide access to Exchange Web Services. Unlike Microsoft-managed policies, the Conditional Access policies it creates are “created by the administrator, not Microsoft.”
Google Workspace
Google ships no security-defaults equivalent. Its model is opt-in configuration, and 2-Step Verification enforcement defaults to Off. You turn it on at Menu > Security > Authentication > 2-step verification
Set Enforcement to On, and set Methods to “Any except verification codes via text, phone call.” That second choice is the one that matters: Google’s own documentation says “Text messages are discouraged—They rely on external carrier networks and might be intercepted,” and that “Security keys are the most secure form of 2SV and protect against phishing threats.”
Give yourself a landing strip with New user enrollment period, which runs from one day to six months, before enforcement bites.
