M365Clarity · Change Management
Security changes in Microsoft 365 are the category most likely to generate complaints. Enforcing multi-factor authentication, enabling Conditional Access policies, restricting external sharing, blocking legacy authentication — each of these makes your organisation meaningfully more secure, and each of them creates friction for users who previously had none.
The friction is unavoidable. The complaints, mostly, are not.
Users who understand why a security change is happening, what it means for their daily workflow, and what they need to do differently are significantly less likely to complain and significantly more likely to comply. The communication is not a courtesy — it is part of the control itself.
Most security change communications from IT make the same mistake: they are written from the perspective of the technology, not the user. "We are implementing MFA as part of our security hardening programme" tells the user what IT is doing. It does not tell the user why it matters to them or what they need to do.
The framing that works is the one that answers the question the user is actually asking: "what does this mean for me on Monday morning?" A good security communication answers that in the first sentence and then explains the reason, rather than the other way around.
Compare these two opening sentences:
Option A: "As part of our ongoing commitment to information security, we will be implementing multi-factor authentication for all Microsoft 365 accounts with effect from 15 July."
Option B: "From 15 July, when you sign in to your work email or Microsoft 365, you will be asked to approve the sign-in on your phone. This takes about five seconds and protects your account if your password is ever stolen."
Option B tells the user exactly what will happen and why it protects them personally. Option A tells the user that something bureaucratic is happening. Most security comms sounds like Option A.
What generates resistance: users who have not used MFA before find it disruptive, especially if they access their accounts from multiple devices or locations. The first few days of MFA enforcement typically generate significant support calls. Frame it as: "your account is now protected even if your password is stolen — here is how the five-second approval process works." Include a screenshot of the Microsoft Authenticator approval screen so users know what to expect before they see it. Offer a drop-in session the day before enforcement for anyone who wants help setting it up.
What generates resistance: users who sign in from personal devices, home networks, or unusual locations suddenly find they cannot access their email or get a different sign-in experience. Frame it as: "we have set up rules that automatically protect your account when you sign in from an unrecognised device or location — here is what that looks like and when it might affect you." Be specific about what triggers the policy (personal device, non-corporate network) and what the user needs to do (complete MFA, use the company VPN, or contact IT). Vague Conditional Access policies that block access without explanation generate the most complaints.
What generates resistance: users who regularly share files with external partners or clients find that their existing share links stop working, or that they can no longer create "Anyone with the link" shares. Frame it as: "we have tightened how files can be shared externally — here is how to share with specific people, which is now the only method available." Provide a step-by-step guide for sharing with a named external user. If your organisation has specific use cases that require broader sharing (e.g. sharing with clients who do not have Microsoft accounts), address these explicitly with approved alternatives rather than leaving users to discover the restriction themselves.
What generates resistance: users with older email clients (Outlook 2013, Apple Mail on older iOS, third-party apps that use basic authentication) find that their email stops working. Frame it as: "we are switching off an older, less secure way of connecting to your email — most users will not notice, but if your email stops working on a particular device, here is how to fix it." List the specific clients and devices that may be affected and provide a step-by-step reconnection guide for each. The support burden from this change comes almost entirely from users who do not know their email client is using legacy authentication until it stops working.
What generates resistance: a small number of users feel surveilled. Frame it as: "we have switched on audit logging for Microsoft 365 — this records account activity so that if an account is ever compromised, we can identify what happened and when. It does not monitor the content of your work." The word "monitoring" tends to generate more concern than "audit logging." Use the latter. Audit logging is largely invisible to users but communicating it proactively avoids the situation where a user discovers it indirectly and feels that IT was hiding something.
Security changes that affect everyone in the organisation — particularly MFA enforcement and Conditional Access — benefit from being communicated by or explicitly endorsed by the CEO or IT Director, not just the IT team. "The company is doing this" lands differently from "IT is doing this." The former is a business decision. The latter is an IT imposition.
A single sentence from a senior leader — "we are strengthening our security and this is one of the things we are doing" — in a company-wide update significantly reduces the volume of complaints directed at IT. It also signals that non-compliance is not a viable option, which matters for the users who would otherwise simply ignore the change.
Never implement a security control without communicating it first. A Conditional Access policy that blocks a user from accessing their email from home, without any prior warning, generates more IT escalations in a day than a month of normal support requests. The technical control takes five minutes to configure. The resulting support calls take hours. Communicating first is cheaper.
The clearest signal that a security communication worked is the volume of support calls in the first week after the change. If calls are low — under 5% of your user base — the comms landed. If calls are high, either the communication did not reach everyone, the explanation was unclear, or the change affected a workflow you did not anticipate.
A secondary measure is the number of users who completed the required action voluntarily before it was enforced. For MFA, this is the proportion of users who set up the Authenticator app before the enforcement deadline. A high voluntary completion rate means users understood the urgency and trusted the process. A low rate means the deadline was not clear or the instructions were not simple enough.
The single most common reason security change communications fail is that they are sent too late. An email sent the day before MFA enforcement, or the morning of the change, leaves no time for users to prepare and creates a support spike that could have been entirely avoided.
Two weeks is the right lead time for any change that affects the sign-in process. One week is the minimum for any change that affects how files are shared. The day before any change, send a reminder that references the original communication and provides the support contact.
Users who know what is coming and understand why it is happening are not a change management problem. They are allies.
M365Clarity scans 131 Microsoft 365 configuration checks and shows you exactly which security controls are unconfigured, with plain-English explanations of what each one means. Free to try.
Start free scan → View live demoRelated articles