A stolen password is still the most common way into a business. Multi-factor authentication, or MFA, is the single control that does the most to stop it, which is why insurers, clients and the Essential Eight all ask for it. This guide covers how MFA works, which types attackers can get past and where a business should turn it on first.
The short answer
Turn on MFA for every staff account on Microsoft 365, remote access and anything that holds money or client data, starting with admin accounts. Use an authenticator app with number matching at a minimum, and move to passkeys or security keys for admins and anyone attackers are likely to target.
What MFA is
MFA asks for two or more kinds of proof before letting someone sign in:
- Something you know, such as a password or PIN.
- Something you have, such as a phone with an authenticator app, a security key or a registered laptop.
- Something you are, such as a fingerprint or face, used to open the thing you have.
An attacker with a stolen password still needs the second factor, which they usually do not have.
Not all MFA is equal
| Method | How it works | Strength | Notes |
|---|---|---|---|
| Text message code | A code sent to your mobile | Weakest | Codes can be phished or intercepted, and numbers moved to a new SIM |
| Authenticator app code | A six digit code from an app | Better | Still works on a fake sign in page if the user types it in |
| App approval with number matching | Approve the sign in and type the number shown on screen | Good | Stops staff approving prompts they did not start |
| Passkeys, security keys and Windows Hello for Business | The device proves who you are to the real website only | Strongest | Phishing resistant: a fake site receives nothing it can reuse |
How attackers get around weaker MFA
MFA fatigue. The attacker has the password and sends approval prompts again and again until someone taps approve to make them stop. Number matching fixes this.
Fake sign in pages. Modern phishing kits sit between the user and the real Microsoft sign in page. The user enters their password and code, the kit passes them to Microsoft and keeps the session that comes back. Codes and app approvals do not stop this. Phishing resistant methods do, because they only work on the real website.
Accounts without MFA. The most common gap is not a weak method but an account that was left out: an old shared mailbox, a service account, a former staff member’s account that was never closed or a system that was set up before MFA was switched on.
Where to turn it on first
- Admin accounts for Microsoft 365, your domain name, firewall and every cloud service.
- Microsoft 365 for every staff member, including email on phones.
- Remote access: VPN, remote desktop and any remote support tools.
- Accounting, payroll and banking.
- Your CRM, practice management and any system that holds client data.
- Everything else that offers it, including social media accounts and supplier portals.
What the Essential Eight expects
At Maturity Level One, staff use MFA on your own and third party online services that hold sensitive data, and on third party services that hold other data where MFA is available. Customers use it on online services that hold their sensitive data. The MFA must combine something the user has with something they know, or a device unlocked by a PIN or fingerprint, not two passwords. Maturity Level Two requires phishing resistant MFA and extends it to administrators and everyday users signing in to your own systems. Our Essential Eight checklist has every requirement as a question.
MFA in Microsoft 365
Every Microsoft 365 business plan can enforce MFA for all users through security defaults, which is a reasonable start for a very small business. Most businesses are better served by Conditional Access, which lets you require MFA by user, location, device and risk, block old sign in methods that bypass MFA and require phishing resistant methods for admins. Conditional Access needs Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium. See managed Microsoft 365 and our Microsoft 365 plan comparison.
Passwords still matter
MFA is a second lock. Keep the first one strong: a long passphrase of several random words, a different one for every account, stored in a password manager so nobody has to remember them. Change a password when there is a reason to, such as a breach or a staff member leaving, rather than on a fixed schedule that pushes people to predictable patterns.
Rolling it out without a revolt
- Tell staff why, in a short message from the business owner, a week before.
- Register everyone’s second factor before you enforce it, with help on hand.
- Start with admins, then office staff, then everyone else.
- Use number matching and trusted devices so prompts are rare.
- Plan for lost phones: a documented, identity checked way to reset MFA.
Where Austin Technology fits
We set up and manage MFA and Conditional Access for businesses of 10 to 500 staff as part of our managed security services, including passkeys and security keys for admins. For a quick check of your Microsoft 365 settings, book a free IT health check or call us on 1300 787 429.
MFA questions
What is the difference between two factor and multi-factor authentication?
Two factor authentication uses exactly two factors, usually a password and a code. Multi-factor authentication means two or more. In practice people use the terms for the same thing.
Is SMS good enough?
It is much better than a password alone, but it is the weakest option. Codes sent by text can be intercepted or phished, and a mobile number can be moved to another SIM. Use an authenticator app or a passkey where you can.
What is phishing resistant MFA?
A method that cannot be tricked into working on a fake website, such as passkeys, security keys and Windows Hello for Business. The sign in is tied to the real website, so a phishing page receives nothing it can reuse. It is required for Essential Eight Maturity Level Two.
Does Microsoft 365 include MFA?
Yes. Every Microsoft 365 business plan can enforce MFA through security defaults. Conditional Access, which lets you set rules by user, location and device, needs Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium.
Will staff find MFA annoying?
Less than they expect. With number matching, trusted devices and sensible rules, most staff approve a sign in a few times a week. Explaining why it matters before you switch it on makes the biggest difference.
Do we still need strong passwords with MFA?
Yes. MFA is a second lock, not a replacement for the first. Use a long passphrase of several random words for each account, a different one everywhere, kept in a password manager.


