Many attacks on small and mid-sized businesses start with a password that was phished, reused from a breached website, or guessed. Multi-factor authentication means a stolen password alone is not enough to sign in. That makes it one of the most effective controls available, and one of the most often half-done: available but optional, enforced for some users and not others, or bypassed by an old protocol nobody switched off.
The order to roll it out
- Email, administrators first. Password resets for almost everything else land in a mailbox, so whoever controls a mailbox can take over other accounts. Enforce MFA on the email tenant's administrator accounts first, then on every mailbox.
- Remote access. VPN, remote desktop gateways and remote-support tools such as AnyDesk or TeamViewer are direct routes into the network. Any of them reachable from the internet without MFA is the most urgent gap you have.
- Infrastructure consoles. Firewall, switches, hypervisors, backup and domain administration. There are few of these accounts, so it is quick, and they are the ones an attacker wants most. Backup consoles matter in particular: see backups that survive ransomware.
- Finance and payroll. Bank portals generally already require a second factor. Your accounting, payroll and payment-approval systems may not.
- Everything that supports single sign-on. Once email accounts have MFA, connect other applications to the same identity provider so they inherit it, instead of each keeping its own password.
Not all MFA is equal
| Method | Strength | Notes |
|---|---|---|
| SMS or voice code | Better than nothing | Exposed to SIM swaps, and to phishing pages that relay the code in real time |
| Authenticator app code | Good | Not tied to the phone number, but a relaying phishing page can still capture it |
| Push approval with number matching | Good | Number matching stops “MFA fatigue”, where users approve a flood of prompts to make them stop |
| Security keys and passkeys (FIDO2) | Strongest | Resistant to phishing because the key checks the real address of the site. Best for administrators |
For most staff, an authenticator app with number matching is the practical default. For administrators, and anyone who approves payments, hardware keys or passkeys are worth the small cost.
The gaps that let attackers around MFA
- Legacy authentication. Older mail protocols using basic authentication cannot do MFA. Microsoft has been retiring basic authentication in Exchange Online; check what in your office still depends on it, such as a scanner that emails documents or an old application that sends mail.
- Exceptions that became permanent. The director who found it inconvenient, the shared mailbox, the service account. List every exclusion and give each an owner and an end date.
- Session theft. Some phishing kits sit between the user and the real sign-in page and steal the session after the user completes MFA. Phishing-resistant methods, sign-in policies that require a managed device, and shorter sessions for administrators all reduce this.
- Push fatigue. Repeated prompts until someone taps approve. Number matching, and alerts on repeated denials, deal with it.
- Help-desk resets. An attacker who calls the help desk posing as a locked-out employee can ask for MFA to be reset. Verify identity through a second channel before resetting anything.
Plan for the day it fails
Keep two emergency administrator accounts that do not depend on the same phone or sign-in policy as everyone else, protect them with hardware keys, keep their details offline, and alert whenever they are used. Decide in advance how a user who loses their phone gets back in, and write it down, so the answer on the day is not “turn MFA off for them”.
MFA is the first step of the zero-trust checklist, and part of every VPN setup we do.