Multifactor authentication (MFA) adds another verification step to an account sign-in. Instead of relying only on a password, a user may also need something such as an authenticator app approval, security key or other approved factor.
The key idea is simple.
If a password is exposed, an additional authentication factor can make the stolen password much less useful on its own.
What is MFA?
MFA means using more than one type of evidence to verify identity. The factors generally fall into categories such as something you know, something you have or something you are.
For businesses, a common example is a password combined with an approval or code from an authenticator application.
Why does MFA matter to a business?
A compromised password can give an attacker a route into email, cloud applications and business information. MFA creates an additional barrier between the stolen password and the account.
MFA is not a complete security solution, but it is an important control because it helps reduce the value of password-only attacks.
Where should a small business start?
- Start with administrator and privileged accounts.
- Protect important cloud and business applications.
- Review remote access and other externally accessible services.
- Make sure staff understand what legitimate MFA prompts look like.
- Document how lost devices, changed phone numbers and access problems are handled.
5 common MFA mistakes
1. Making exceptions without a clear reason
Exceptions can be necessary in some environments, but permanent exclusions should be understood and reviewed. Otherwise, accounts outside the control can quietly become a weak point.
2. Protecting users but forgetting administrators
Privileged accounts are particularly important because they can make changes that affect many users or systems. Treat administrative authentication as a priority.
3. Ignoring recovery and support processes
MFA can create access problems when an employee loses a phone or changes their device. A business should have a controlled recovery process rather than relying on ad-hoc resets.
4. Approving unexpected prompts
Staff need to understand that an MFA prompt they did not initiate should be treated as suspicious. Security awareness is part of making MFA effective.
5. Thinking MFA replaces other security controls
MFA helps protect identity, but it does not replace endpoint protection, patch management, secure email, backups, least-privilege access or user awareness.
MFA and Microsoft 365
Microsoft 365 is a common place for businesses to implement MFA because user identities are central to email, collaboration and other cloud services.
A broader Microsoft 365 security review should consider MFA alongside administrator access, device access, conditional access, email security and other configuration controls.
For a deeper look at Microsoft 365 security, read our guide: 5 Microsoft 365 Security Settings Every Business Should Check .
How to introduce MFA without disrupting the business
Good implementation is usually about communication and preparation as much as technology. Tell staff why the change is happening, give clear setup instructions and provide a simple route for genuine access problems.
A phased rollout may be appropriate for some organisations, particularly where there are legacy systems or unusual user workflows that need to be reviewed first.
MFA rollout checklist
- Identify the accounts and services that need protection.
- Prioritise administrator and privileged accounts.
- Choose the authentication methods your business will support.
- Prepare user guidance and recovery procedures.
- Review exceptions and legacy dependencies.
- Monitor sign-in issues and adjust the rollout where necessary.
- Protect administrators with the strongest practical authentication available.
- Document and review MFA exceptions.
- Test lost-device and account-recovery procedures.
- Remove old authentication methods when users leave or devices are replaced.
- Check that important non-Microsoft services are also protected.
Which MFA method should a business use?
Not every authentication method provides the same level of protection or works equally well for every person. The right choice depends on the service being protected, the user's role, the devices they use and the recovery options available to the organisation.
For many businesses, an authenticator app is a practical starting point. Security keys and passkeys can provide stronger protection against phishing where they are supported and appropriate. SMS can be better than password-only access, but organisations should understand its limitations and should not treat a one-time code as the end of their identity-security strategy.
Which accounts should be protected first?
A phased MFA rollout should start with accounts that would cause the greatest impact if compromised. That normally means administrator accounts, email accounts, finance and payroll services, domain and website administration, cloud infrastructure and any service that can reset or recover other accounts.
Prioritise by impact, not convenience.
Protecting a low-risk account while leaving a highly privileged administrator account password-only creates a false sense of security.
MFA fatigue and unexpected authentication requests
Attackers sometimes exploit repeated authentication prompts in the hope that a user will eventually approve one simply to stop the notifications. Staff should know that an unexpected MFA request is suspicious, even if the request looks familiar.
Where the platform supports number matching, phishing-resistant authentication or other stronger controls, consider them for higher-risk users. More importantly, establish a simple rule: deny unexpected prompts and report them immediately.
MFA recovery is part of the security control
A rollout is incomplete if the business has no secure way to recover access when a phone is lost, replaced or reset. Poor recovery processes can lead to administrators bypassing security controls or making rushed changes that are difficult to audit.
- Define who can approve a recovery.
- Verify the user's identity using an independent method.
- Record the recovery action.
- Remove old authentication methods when devices are replaced.
- Review recovery processes periodically.
A simple 30-day MFA rollout plan
Week 1 — Inventory
List important users, administrators, applications and externally accessible services.
Week 2 — Protect priority accounts
Secure administrators, finance-related access, email and other high-impact services first.
Week 3 — User rollout
Provide clear instructions, allow time for setup and monitor genuine access problems.
Week 4 — Review
Check exceptions, recovery procedures, unexpected prompts and accounts that still lack protection.
Administrator MFA: stronger controls for higher-risk accounts
Administrator accounts deserve additional attention because they can change policies, create accounts and alter security settings. Use separate administrative identities where practical, limit who can hold privileged roles and prefer stronger authentication methods for those accounts.
MFA should also be combined with least privilege, logging and regular access reviews. The goal is to reduce both the chance of compromise and the amount of damage a compromised account can cause.
Questions to ask before declaring MFA complete
- Have all privileged accounts been identified?
- Are exceptions documented and reviewed?
- Do staff know how to recognise an unexpected authentication prompt?
- Is there a secure recovery procedure for lost devices?
- Are former employees' authentication methods removed?
- Are high-risk services protected, not just Microsoft 365?
- Is stronger authentication available for administrators?
- Does someone own the ongoing MFA review?
Final thoughts
MFA should be treated as a standard part of modern account security rather than an optional extra. It is relatively straightforward to understand, but it still needs to be implemented thoughtfully and supported by wider security controls.
If you are unsure whether MFA is correctly configured across your business accounts, that is a useful item to include in a wider IT and security review.
Take the next step
Want to know how secure your business accounts are?
Book a Free IT Health Check with NorthWave and review MFA, accounts, devices, backup and other key areas of your IT environment.
Further reading
- NCSC: Secure your important online accounts
- NCSC: Multi-factor authentication
- Microsoft Learn: How Microsoft Entra multifactor authentication works
Authentication capabilities vary between services and subscriptions. Verify the options available in your environment before changing access controls or recovery settings.