What it is
When Overe runs a Deep Scan, tells you not just whether MFA is in place for a tenant, but how it is being enforced. Scan results identify whether MFA protection comes from Security Defaults, from a Conditional Access policy or from Per-user MFA enforcement. giving you a clearer picture of each tenant's security posture.
What each enforcement method means
Security Defaults
Microsoft's baseline protection. When Security Defaults are enabled, all users are required to use MFA, but the settings cannot be customised. Security Defaults and Conditional Access cannot both be active at the same time.
Conditional Access policy
A configurable, policy-based approach that lets you define who must authenticate, under what conditions, and with what methods. This is the recommended approach for tenants on Microsoft 365 Business Premium, M365 E3/E5, or with an Entra ID P1 licence.
Per user MFA enforcement
This is a legacy method that doesn't allow authentication method visibility or the ability to define which methods are sufficient. Read more
How to use it
When reviewing scan results in Overe, check the MFA context shown for each tenant. If a tenant shows Security Defaults rather than Conditional Access, this is a signal to review whether that tenant has the licensing and readiness to move to policy-based enforcement. Conditional Access gives you more control, allows exclusions, and is a prerequisite for several Overe policy controls.
