Multi-Factor Authentication isn’t optional – here is why

Digital tablet with a password screen

We still hear it now and then. “We use strong passwords, we’re fine.” MFA feels like another barrier to getting stuff done.  

We understand the instinct, multi-factor authentication (MFA) feels like one more interruption in an already busy day.  

The reality is that a password on its own is not enough to keep a business account safe. The businesses that are still relying on one are the one’s getting hit.  

 

What MFA actually is 

In plain English, MFA means you need more than one thing to prove who you are when you sign in. 

  • Something you know – your password 
  • Something you have – usually a code or approval from an app on your phone 
  • Something you are – a fingerprint or face recognition 

 A password on its own is one factor. MFA adds a second, so that even if someone gets hold of your password, they still cannot sign in as you. 

 

Why passwords on their own no longer work 

Passwords get exposed more often than most people realise. The difference now is the scale and speed at which they are used against you. 

  • Every time a website you’ve used is breached, the passwords from it end up on a list that attackers buy and try against every other service they can think of. 
  • Phishing emails are no longer obvious – modern fake sign-in pages are pixel-perfect copies of the real Microsoft login screen. 
  • Attackers don’t try to guess one password at a time anymore. Automated tools try millions of leaked passwords across thousands of mailboxes overnight. 

If your team reuses any password anywhere, even slightly, the maths is no longer on your side. 

 

Why it’s no longer optional 

Three things have changed in the last couple of years. 

Microsoft now enables MFA by default.  

New Microsoft 365 accounts now have MFA switched on by default, which means MFA is enforced unless somebody actively switches it off.  

Microsoft has made its position very clear and we will not switch off security defaults unless you have Business Premium and can replace it with conditional access that still requires MFA. 

Cyber insurance now expects it.  

Most cyber insurance policies we see renewed in the last twelve months either require MFA on all administrator and user accounts. 

A claim without MFA in place is increasingly likely to be challenged. 

Compliance frameworks require it.  

Cyber Essentials, Cyber Essentials Plus and ISO 27001 all require MFA.  

If your business is working towards any of these, this is non-negotiable. 

 

Making it less painful 

The good news is that modern MFA does not have to mean a code prompt every five minutes. 

Two things make the day-to-day experience much better: 

Use the Microsoft Authenticator app, not SMS.  

Text message codes used to be the standard, but they can be intercepted and SMS-based MFA is now considered the weakest form.  

The Authenticator app uses a simple tap-to-approve prompt and is more secure. 

Conditional Access turns the prompts down.  

Conditional Access (part of Business Premium) lets you set rules so MFA is only prompted when it actually adds value. For example, when signing in from a new device, an unfamiliar location, or outside normal working patterns.  

From a known device on a normal day, it stays out of the way. 

 

Watch out for MFA fatigue 

One last point worth knowing about. Attackers have started exploiting MFA itself by spamming approval prompts at people, dozens of them in a row, hoping you will tap approve just to make them stop. This is called MFA fatigue. 

The fix is simple but important: never approve a sign-in you didn’t trigger yourself. If you see a prompt and you weren’t signing in, deny it and tell us.  

Using the Microsoft Authenticator also helps as it prompts to enter a number that must match the request prior to approval. 

 

In short 

Passwords alone stopped being enough some time ago. MFA is now the minimum bar. Expected by Microsoft, insurers and by every compliance framework worth holding.  

Done well, with the right tools, it sits quietly in the background rather than getting in your way. 

If you’re not sure whether MFA is fully enabled across your business, or whether your setup is using the strongest options give us a call and we’ll review it with you. 

Whatever your IT question – big or small – drop us a message or give us a call. We’ll make sure you get a straightforward answer without the tech-speak. 

Scroll to Top