MFA: where to switch it on first

By the NexusSec team · 4 min read · Published October 2026
Short version: Enforce MFA first on email and its administrator accounts, then on remote access (VPN, remote desktop and remote-support tools), then on firewall, backup and hypervisor consoles, then on finance and payroll systems. Prefer an authenticator app with number matching, or hardware keys for administrators, over SMS. Close the gaps: legacy sign-in protocols, permanent exceptions and unverified help-desk resets.

Many attacks on small and mid-sized businesses start with a password that was phished, reused from a breached website, or guessed. Multi-factor authentication means a stolen password alone is not enough to sign in. That makes it one of the most effective controls available, and one of the most often half-done: available but optional, enforced for some users and not others, or bypassed by an old protocol nobody switched off.

The order to roll it out

  1. Email, administrators first. Password resets for almost everything else land in a mailbox, so whoever controls a mailbox can take over other accounts. Enforce MFA on the email tenant's administrator accounts first, then on every mailbox.
  2. Remote access. VPN, remote desktop gateways and remote-support tools such as AnyDesk or TeamViewer are direct routes into the network. Any of them reachable from the internet without MFA is the most urgent gap you have.
  3. Infrastructure consoles. Firewall, switches, hypervisors, backup and domain administration. There are few of these accounts, so it is quick, and they are the ones an attacker wants most. Backup consoles matter in particular: see backups that survive ransomware.
  4. Finance and payroll. Bank portals generally already require a second factor. Your accounting, payroll and payment-approval systems may not.
  5. Everything that supports single sign-on. Once email accounts have MFA, connect other applications to the same identity provider so they inherit it, instead of each keeping its own password.

Not all MFA is equal

MethodStrengthNotes
SMS or voice codeBetter than nothingExposed to SIM swaps, and to phishing pages that relay the code in real time
Authenticator app codeGoodNot tied to the phone number, but a relaying phishing page can still capture it
Push approval with number matchingGoodNumber matching stops “MFA fatigue”, where users approve a flood of prompts to make them stop
Security keys and passkeys (FIDO2)StrongestResistant to phishing because the key checks the real address of the site. Best for administrators

For most staff, an authenticator app with number matching is the practical default. For administrators, and anyone who approves payments, hardware keys or passkeys are worth the small cost.

The gaps that let attackers around MFA

Plan for the day it fails

Keep two emergency administrator accounts that do not depend on the same phone or sign-in policy as everyone else, protect them with hardware keys, keep their details offline, and alert whenever they are used. Decide in advance how a user who loses their phone gets back in, and write it down, so the answer on the day is not “turn MFA off for them”.

MFA is the first step of the zero-trust checklist, and part of every VPN setup we do.

Frequently asked questions

Is SMS OTP good enough?

It is far better than a password alone and fine as a starting point. Move administrators and payment approvers to an authenticator app or a hardware key first, then everyone else as you can.

Do we need MFA on the VPN if our office PCs are trusted?

Yes. The VPN is reachable from anywhere on the internet. Without MFA, a stolen password is all it takes to connect.

What about shared accounts?

Replace them with named accounts wherever the application allows. Where it does not, keep the shared credentials in a password manager that itself requires MFA, and limit who can see them.

Will MFA annoy staff?

Less than people expect. Number matching takes seconds, and sign-in policies can reduce prompts on managed devices in the office while still requiring MFA elsewhere.

Want MFA enforced everywhere it matters?

We find the accounts and access paths without it, close the legacy gaps, and roll it out in an order your staff can follow.

Book a free consultation