Permit Exceptions to Security Defaults
Security Defaults nearly provides adequate automatic MFA for organizations that don't utilize licensing that permits Conditional Access, but because it doesn't permit an Exceptions List which would include a Security Group it destroys the functionality of SMTP accounts. It would be provide very functional default MFA status if we could utilize an exception list.
