
What is MFA? A Plain-English Guide for Small Businesses
Of all the security advice I give small business owners, turning on MFA is the single most important one. It blocks roughly 99% of the password-based attacks I see in the wild. It's free, built into Microsoft 365, Google Workspace, banking apps, and most business software. And yet at least a third of the businesses I start working with still don't have it enabled for everyone.
So here is MFA without the jargon: what it is, why it matters, and how to set it up properly so it actually protects you without driving your team mad.
What MFA actually is
MFA stands for multi-factor authentication. You might also hear it called two-factor authentication (2FA), two-step verification, or strong authentication. They all mean roughly the same thing: proving it's really you with more than just a password.
In practice, when you log into something with MFA turned on, you enter your password (something you know) and then approve the login on your phone or type in a code (something you have). An attacker who has stolen your password still can't get in without your phone.
Why "just a password" is no longer enough
Passwords get stolen constantly. Not because people are careless, but because:
- Data breaches leak millions of username/password combinations. If you've used the same password on any other site that later got hacked, it's probably already on a list somewhere.
- Phishing emails trick even careful people into typing passwords into fake login pages.
- Malware on a personal laptop can grab saved passwords and send them home.
Once a criminal has your Microsoft 365 password, they can read every email you've ever sent, impersonate you, set up rules that quietly forward client invoices to them, and use your account to launch attacks on your suppliers. With MFA turned on, none of that happens. The password alone isn't enough.
How MFA works in the real world
A typical login with MFA looks like this:
- You open Outlook on a new laptop and enter your email address and password.
- Your phone buzzes with a notification from the Microsoft Authenticator app.
- You tap "Approve" (sometimes after entering a two-digit number shown on the laptop).
- Outlook finishes signing in.
That's it. Ten seconds of friction on a new device, and then the laptop usually won't ask again for 30 days. Most of my clients stop noticing within a week.
The different types of MFA (not all equal)
Not every MFA method is as strong as the next. In rough order from best to worst:
- Authenticator apps (Microsoft Authenticator, Google Authenticator, Authy): recommended. Free, secure, work offline.
- Physical security keys (YubiKey and similar): the gold standard. A USB or NFC device you tap to approve. Perfect for directors and finance staff.
- Push notifications from your bank or business app: very good, assuming the app itself is secure.
- SMS text codes: better than nothing, but phone numbers can be hijacked ("SIM-swapping"). Avoid where possible, especially for admin accounts.
- Email codes: almost useless; if someone has your email password they'll intercept the code too.
Common mistakes I fix when I take over a new client
"We've got MFA" is rarely the whole story. The most common problems:
- Only some people have it. Usually the directors, not the office junior; attackers love the office junior's mailbox.
- Admin accounts aren't protected. The global admin in Microsoft 365 is the single most valuable target and is sometimes the only account without MFA.
- SMS only. Worth upgrading to an app.
- No backup method. Someone loses their phone and can't log in for two days while IT gets involved.
- "MFA fatigue" attacks. Attackers hammer the login until a bleary user approves a prompt by accident. Microsoft's number-matching prompts fix this; turn them on.
How to roll MFA out without a rebellion
The trick is not to do it all at once on a Monday morning. What actually works:
- Roll out to IT and directors first. Iron out any issues on yourselves.
- Give the team two weeks' notice and a one-page setup guide.
- Run a 20-minute group session to help anyone nervous about installing the app on a personal phone (yes, this comes up; it's fine, the app doesn't see anything else on the phone).
- Turn on "Conditional Access" in Microsoft 365 so MFA is only prompted from untrusted locations or new devices. Most staff will barely notice it after setup.
- Make sure there's a documented break-glass account and a clear reset process.
The bottom line
If you run a small business and you don't have MFA on your Microsoft 365, your banking, and your accounting software, you are one phishing email away from a bad week. Turning it on properly costs nothing and takes an afternoon.
If you'd like a hand setting MFA up for your business, making sure it covers every account (including the forgotten service ones), and training your team, see how we help with cyber security or get in touch.