Every page on this site that discusses security eventually says the same four words: enforce MFA everywhere. This is the page that says the rest of the sentence: which kind, in what order, and how to get it onto every account in a business full of humans who did not ask for another thing on their phone. Because the gap between “we have MFA” and “MFA is enforced on everything” is where most of the actual breaches live, and closing it is a project with known snags and known answers.

Why this one control carries so much weight

Passwords fail wholesale: phished, reused across breached sites, guessed by automated spray. Multi-factor authentication means a stolen password alone achieves nothing, which removes the attacker’s cheapest and most common way in. The consequences have hardened around it accordingly: Cyber Essentials now auto-fails any assessment with cloud accounts lacking MFA, no tolerated exceptions, and cyber insurers ask about it by name with premiums and claims riding on the answer. It is simultaneously the highest-value and most externally demanded control an SME can implement, which makes the rollout project unusually easy to justify and unusually important to finish completely.

The methods, ranked honestly

Not all second factors are equal, and the ranking matters because attackers have adapted:

Passkeys and phishing-resistant methods (best)

Passkeys (and hardware security keys) bind the login to the legitimate site cryptographically: a fake Microsoft login page simply cannot harvest them, which defeats the modern phishing kits that proxy real login pages in real time. Support has matured across Microsoft 365 and major platforms, and for admin accounts especially, this tier is worth insisting on.

Authenticator apps (good, the practical default)

App-based push approvals or six-digit codes (Microsoft Authenticator and peers): strong, free, and the sensible default for general staff. One modern caveat: bare push notifications suffer “fatigue attacks”, where an attacker with the password bombards approvals until someone taps yes; number-matching (typing the two digits shown on screen into the app) closes this and should be switched on, as Microsoft now defaults.

SMS codes (better than nothing, worse than assumed)

Text-message codes defeat casual attacks but fall to SIM-swap fraud and phishing proxies. Acceptable as a stepping stone or fallback; not the destination, and not for admin accounts.

The practical policy that falls out: passkeys or number-matched authenticator for everyone, phishing-resistant methods mandatory for admins, SMS only as a temporary bridge.

The rollout, without the revolt

MFA projects fail socially, not technically, and the failure is predictable: a surprise announcement, a Monday-morning lockout queue, a director who refuses, and quiet exceptions that grow until the control is decorative. The sequence that works:

  1. Inventory first. Every cloud service the business touches, not just Microsoft 365: accounting, CRM, banking portals, the subscription long tail. The forgotten service with no MFA is the future incident.
  2. Communicate before enforcing. A short note explaining the what, the why (one recent local incident story does more than policy language), and exactly what staff will do on the day, plus a named person for help. A week’s notice, not an ambush.
  3. Pilot with a friendly group. One team enrols first; their snags (the shared mailbox, the person without a smartphone) become fixes before the wide rollout instead of Monday chaos.
  4. Enrol in waves, enforce with a deadline. Registration windows per team, help on tap, then enforcement dates that actually arrive. In Microsoft 365 this is conditional access or security defaults doing the enforcing, per the hardening guide; grace periods that never end are how estates stay half-covered forever.
  5. Handle the hard cases explicitly, not silently. No smartphone? Hardware keys or desktop authenticator options exist. Shared accounts? Mostly they should stop being shared; where they genuinely must exist, they get their own documented handling. The director who refuses? That account is the single most targeted identity in the business, which is the sentence that usually settles it.
  6. Close the loop. Report enrolment to 100%, kill legacy authentication (the protocols that bypass MFA entirely, and the step most DIY rollouts miss), and fold new starters into enrolment on day one.

For a typical SME the whole arc runs two to four weeks, most of it communication rather than configuration.

Beyond the prompt: conditional access

On Microsoft 365 Business Premium, conditional access turns MFA from a blanket prompt into policy: require it always for admins, skip it on compliant devices in trusted locations to cut prompt fatigue, block sign-ins from countries you never trade with, and demand managed devices for sensitive roles. The user experience improves (fewer prompts, smarter ones) while the security tightens, which is the rare trade both sides like. It is a chunk of the Business Premium tier’s practical value.

Frequently asked questions

What is the best MFA method for a business?

Phishing-resistant methods (passkeys, hardware keys) first, especially for admins; number-matched authenticator apps as the strong default for staff; SMS only as a fallback. The ranking reflects what current phishing kits can and cannot defeat.

Is MFA required for Cyber Essentials?

Effectively yes: the current question set requires MFA on cloud services for all users, and gaps are an automatic fail. It is also the control insurers ask about most consistently.

How disruptive is rolling out MFA?

With communication, piloting and enrolment waves: mildly, for about a fortnight, then it disappears into habit. The horror stories come from surprise enforcement, which is a choice rather than a property of MFA.

What about staff who won’t use their personal phones?

Legitimate and solvable: hardware security keys, desktop authenticator options, or (bluntly) company-funded devices for roles that need them. The one non-answer is exempting the account.

Does MFA stop all account attacks?

No single control does: fatigue attacks target careless push approval (fixed by number matching), and token-theft techniques exist against signed-in sessions (mitigated by conditional access and device management). MFA removes the wholesale attacks; the layered stack handles the retail ones.

We have MFA on email. Are we done?

Almost never: the accounting platform, the CRM, the banking portal and the admin consoles all need it too, and legacy email protocols may be quietly bypassing the MFA you have. The inventory step exists because “MFA on email” and “MFA everywhere” are different security postures wearing the same sentence.

Find out what “everywhere” means for your business

The audit takes an hour: every service listed, every account’s MFA state checked, legacy authentication hunted, and the rollout plan sequenced with the hard cases named. It is part of our free IT health check, and it converts this page from advice into a dated project plan. Get in touch; the password that gets phished next month has already been chosen.