Just saw the announcement about security defaults requiring an Entra ID P1 license starting July 2024. Honestly, this feels like a big shift for a lot of teams I've talked to who rely on it as their baseline "set it and forget it" protection.
I'm still getting up to speed on all the Entra tiers, but my understanding was that security defaults were the free, no-frills way to get MFA and block legacy auth. Now that it's moving behind a paywall, what are folks actually planning to do?
Are you:
* Biting the bullet and upgrading to P1 for the whole org just to keep this baseline?
* Switching to Conditional Access policies manually (if you already have P1)?
* Looking at third-party solutions for MFA and basic risk protection instead?
From a product analytics angle, I'm really curious how Microsoft's telemetry might have shown low adoption of the *free* tier leading to this change. Or maybe it's the opposite – it was too popular and they're trying to drive upsell? Either way, this seems like a major cost/ops impact for small and medium-sized shops. What's the play here?
Yeah, that licensing change is a real gut punch for smaller teams. You nailed the "set and forget" appeal - that was its whole value for many of us.
From the product analytics angle, I'd bet it's a classic upsell move. The free tier worked *too* well as a complete solution for basic needs, so they're pushing the paid features. My team's already on P1, so we'll just build out equivalent Conditional Access policies. It's more config work, but at least we get more granular control.
For shops without P1, the math gets ugly fast. Upgrading everyone is a huge cost leap. I'm already hearing chatter about folks evaluating third-party MFA, especially from identity platforms that bundle it more affordably. Might be a chance for them to grab market share.
✌️
You're right, the "set and forget" appeal is exactly what's being removed here. For teams that don't have P1, the cost jump is the main blocker - upgrading everyone for just baseline MFA feels like overkill when P1's other features might not be needed.
My team is in the third-party MFA camp for our non-critical apps. We're testing a few identity providers that offer just MFA at a fraction of the P1 per-user cost. The trade-off is managing another service, but the savings for a 50-person team are substantial.
From the product angle, I think it's both. The defaults were probably popular *and* showed low upgrade intent, so they're removing the free path to create a licensing floor. It forces a re-evaluation, and for many, that means looking outside the Microsoft stack.
Cloud cost nerd. No, I don't use Reserved Instances.