Why Every Business Needs Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) is the single most effective security control available to small and mid-sized businesses today. Microsoft's own data shows that enabling MFA blocks over 99% of automated account-compromise attacks. Yet most of the Microsoft 365 tenants we audit at new client engagements still don't have it fully enforced. This article covers what MFA is, why it works, how to roll it out without breaking your team's workflow, and the mistakes to avoid.
What MFA actually is
A password alone is one factor: something you know. MFA adds a second factor, usually something you have (your phone), so an attacker with your password still can't log in. When a user signs into Microsoft 365 or your VPN, they enter their password, then approve a prompt on their phone or enter a short code from an authenticator app.
Why MFA is so effective
Nearly every real-world attack against SMB Microsoft 365 tenants starts with a stolen or phished password. MFA breaks that chain. Even with the correct password, the attacker cannot complete the sign-in without physical possession of the user's second factor.
- Blocks credential-stuffing attacks using passwords leaked from other services
- Blocks the majority of phishing attacks that steal passwords
- Required by most modern cyber insurance policies
- Now expected by clients and enterprise vendors as a baseline
The different types of MFA (not all equal)
Best: Authenticator apps and hardware keys
- Microsoft Authenticator, Google Authenticator, Authy: push notifications or 6-digit codes
- FIDO2 hardware keys (YubiKey) for high-value accounts and admins
- Number-matching in Microsoft Authenticator defeats push-fatigue attacks
Acceptable: SMS codes
SMS is far better than no MFA, but it's vulnerable to SIM-swap attacks. Use it as a fallback, not a primary method, and never for administrator accounts.
Do not use: Security questions and email codes
These are not true second factors. If the attacker owns the email, they own the codes. Disable them where possible.
Not sure where your security gaps are?
Our free cybersecurity risk assessment scores your posture across MFA, backup, endpoint protection, and email security, then hands you a prioritized fix list.
Talk to a Security SpecialistHow to roll out MFA without chaos
- Enable MFA on administrator accounts first: that's the highest-value target
- Communicate with staff before enforcement: what will change, why, what to install
- Provide a written guide for enrolling in Microsoft Authenticator
- Enforce with Conditional Access, not per-user MFA, since it scales properly
- Configure trusted locations sparingly: usually the office public IP only
- Have a documented process for lost phones and re-enrollment
Common mistakes we see
- MFA enabled but not enforced, so users can skip it
- Legacy authentication protocols still enabled, allowing MFA bypass
- Admin accounts using the same MFA method as regular users
- Break-glass emergency accounts with no MFA at all (they should have hardware key MFA)
- Shared mailboxes converted to user accounts with MFA disabled
Frequently asked questions
Will MFA slow down our team?
Once enrolled, users approve a prompt in about two seconds and are typically trusted on their device for a period of time. The productivity impact is minimal, while the security impact is enormous.
What if someone loses their phone?
This is why a documented re-enrollment process matters. IT verifies the user's identity through a secondary channel (often in person or via a manager) and issues a temporary access pass to re-enroll.
Does MFA replace strong passwords?
No. It complements them. Passwords should still be long, unique, and stored in a password manager. MFA is your safety net when a password inevitably gets exposed.
Can attackers get around MFA?
Some sophisticated phishing kits can, using real-time proxy attacks. That's why modern conditional access includes device compliance checks and phishing-resistant methods like FIDO2 keys for high-value accounts.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamGet MFA rolled out properly
We deploy Microsoft 365 MFA, Conditional Access, and identity hardening as part of every managed IT engagement, with staff communication and re-enrollment procedures built in.
Technologies mentioned in this article
See what we support around each platform on our supported technologies hub.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Backing Up Primafact Case Files Properly
Case files in Primafact represent years of litigation work that can't be recreated. Here's what a proper ba…
- PCLaw Support for Ontario Law Firms: The IT Side of Running PCLaw
PCLaw handles billing, trust accounting, and time tracking for many Ontario firms. Here's what keeps it run…
- Protecting PCLaw Trust Accounting Data
Trust accounting data inside PCLaw deserves a distinct layer of protection. General infrastructure guidance…
- What Does a Sophos Firewall Actually Do for a Small Business?
A business-grade firewall does far more than block traffic at the edge. Here is what a device like a Sophos…
