A stolen password is one of the easiest ways into a business. Employees reuse passwords, phishing emails get more convincing, and logins get sold on the dark web. Once an attacker has a working password, your email and files could be wide open.
Multi-factor authentication is one of many no-cost tactics that can secure that door. Better yet, you can set up multi-factor authentication across your business in a single afternoon. Here is how to do it.
Multi-factor authentication, or MFA, asks for a second proof of identity after the password. That second proof is usually a code or a prompt on the employee’s phone. With MFA in place, a stolen password alone no longer gets anyone in.
The payoff is significant. According to CISA, the federal cybersecurity agency, using MFA makes you 99% less likely to be hacked. Few security measures deliver that much protection for so little cost and effort.
Start by listing the accounts that would hurt most if someone else got in. For most businesses, that list has four parts:
Write down who holds admin rights on each one, because you will need those people this afternoon. CISA’s small business guidance recommends starting with admin accounts and employees who handle sensitive data.
MFA methods do not all offer the same protection. From strongest to weakest, the options are:
We recommend an authenticator app as your company standard. It is free, works on any smartphone, and is much harder to intercept than a text message. Consider physical security keys for executives, finance staff, and IT administrators. Use text message codes only when a service offers nothing stronger. Any MFA is better than no MFA.
Email is the master key to your business. Almost every other account can be reset through an email link, so protect email before anything else.
In Microsoft 365, an administrator can require MFA for every user from the Microsoft Entra admin center. The security default setting handles it in a few clicks. In Google Workspace, the feature is called 2-Step Verification, and it lives in the Admin console under Security. Both platforms let you set an enforcement date, which gives employees a few days to enroll.
Remember to include shared mailboxes, service accounts, and the administrator accounts themselves. Attackers often look for the one login everyone forgot.
Financial accounts come next, because this is where a break-in turns into lost money. Log in to your banking, payroll, and accounting platforms as an administrator. From there, look for a security setting labeled MFA, two-factor authentication, or 2-step verification. Require it for every user who can view balances, move money, or change vendor payment details.
Many banks also offer a physical token or a separate approval app for wire transfers. If your bank offers one, use it.
Now work down the rest of your list. Most modern business software includes MFA in its security settings at no extra charge.
If your apps support single sign-on, connect them to your Microsoft or Google login. Employees then sign in once, with MFA, and reach everything they need. You get fewer passwords to manage and one place to remove access when someone leaves.
The technology is the easy part. A rollout goes smoothly when people know what is coming. Before the enforcement date, send a short note that covers three things:
Add one rule in bold: never approve a login prompt you did not start. Attackers sometimes flood a phone with requests, hoping a tired employee taps “approve.” An employee who sees that should deny the request and report it right away.
We recommend giving your team as much heads up as possible. If you can, allow them at least a week to prepare. You may want to consider an optional virtual training session for your employees, as well.
Skipping the backup method. Phones get lost, broken, and replaced. Have every employee save backup codes or register a second device during enrollment.
Making exceptions for leadership. Owners and executives are the most targeted people in any company. They need MFA more than anyone.
Treating it as a one-time project. Add MFA enrollment to your new hire checklist. Then review your accounts each quarter for any that slipped through.
A few hours of work shuts down one of the most common ways attackers get into a business. Your passwords can still be stolen, but a stolen password is now far less useful to a criminal.
Some environments are harder than others. You may have older software that does not support MFA, or employees without company phones. At Macro Connect, we help organizations set up multi-factor authentication and manage it as part of a larger security plan. If you would like a second set of eyes on your rollout, let’s talk!