MFA stops over 99% of account compromise attacks. Here's what it is, how it works, which accounts to protect first, and how to avoid MFA fatigue attacks.
According to Microsoft, multi-factor authentication (MFA) blocks more than 99.9% of account compromise attacks. It's one of the most effective security controls available — and it's free or nearly free to enable on most platforms.
Yet many small businesses still haven't turned it on everywhere they should.
This guide explains what MFA is, why it works, the different types available, and how to roll it out effectively without driving your team crazy.
What Is Multi-Factor Authentication?
Authentication is the process of proving you are who you claim to be. Traditionally, that proof is a password — something you know.
Multi-factor authentication adds one or more additional factors:
- Something you have (a phone, a hardware key)
- Something you are (fingerprint, face ID)
The idea is that even if an attacker steals or guesses your password, they still can't log in without the second factor — which they don't have.
"Two-factor authentication" (2FA) and "multi-factor authentication" (MFA) are often used interchangeably. Technically, MFA can include more than two factors, but in practice, two is the standard for most business applications.
Why Passwords Alone Aren't Enough
Passwords are compromised constantly, through:
- Phishing — fake login pages that capture credentials
- Credential stuffing — attackers use username/password lists from previous breaches to try logging into other services (most people reuse passwords)
- Data breaches — your password from a breached service gets sold in bulk on the dark web
- Keyloggers — malware that records what you type
- Brute force — automated tools that try millions of password combinations
There are literally billions of compromised credentials available online right now. If an employee uses the same password for their work email that they use for a breached shopping site, attackers have it.
MFA means a stolen password alone is useless. Without the second factor, it doesn't get the attacker in.
Types of MFA
SMS Text Message Codes
The most familiar type: log in with your password, receive a 6-digit code via text, enter the code.
- Pros: Easy to use, no app required
- Cons: SMS can be intercepted via SIM-swapping attacks; texts can be delayed; relies on cell service
SMS MFA is better than nothing, but it's the weakest form of MFA. For most business applications, an authenticator app is preferable.
Authenticator App
Apps like Microsoft Authenticator, Google Authenticator, and Authy generate time-based one-time passwords (TOTP) — 6-digit codes that change every 30 seconds. Because they're generated on your device and never transmitted via SMS, they're much harder to intercept.
Microsoft Authenticator also supports push notifications — instead of entering a code, you just tap "Approve" on your phone when you log in.
- Pros: Much harder to intercept than SMS, works offline, fast to use
- Cons: Requires phone app, phone must be accessible
This is the recommended MFA method for most small businesses.
Hardware Security Keys
Physical devices (like a YubiKey) that you plug into a USB port or tap to an NFC reader to authenticate. They're phishing-resistant — they only work on the legitimate site, not a fake lookalike.
- Pros: Strongest protection, phishing-resistant, works without a phone
- Cons: Cost ($25–$60 per key), can be lost, requires setup
Hardware keys are ideal for high-privilege accounts — IT administrators, executives, finance staff — where the risk of compromise is highest.
Biometrics (Face ID / Fingerprint)
Common on mobile devices, increasingly used in business applications. Often used as the "second factor" when unlocking an authenticator app or approving a Microsoft Authenticator push.
Setting Up Microsoft Authenticator
For businesses using Microsoft 365, here's the basic setup process:
- Enable MFA in the Microsoft 365 Admin Center (Security > Authentication methods)
- Require MFA via Conditional Access policies for all users (Business Premium includes this; Standard requires manual configuration)
- Have each user:
- Download the Microsoft Authenticator app on their phone
- Go to aka.ms/mfasetup to configure their account
- Scan the QR code with the app
- Set a deadline for all users to complete enrollment
- After the deadline, enforce MFA for all logins
For Google Workspace, the process is similar through the Admin Console under Security > 2-Step Verification.
Which Accounts to Protect First
If you're rolling out MFA in stages, prioritize in this order:
- Email (Microsoft 365 / Google Workspace) — email is the master key. If an attacker gets into email, they can reset passwords for everything else.
- VPN and remote access — the front door to your internal network
- Banking and financial accounts
- Cloud storage (OneDrive, Google Drive, Dropbox)
- IT management tools (your firewall, server management, DNS)
- CRM, EHR, and other line-of-business software
- Social media and marketing platforms
The first two on this list are critical. Get those protected before anything else.
MFA Fatigue Attacks: The New Threat
As MFA adoption has grown, attackers have developed a workaround: MFA fatigue (also called push bombing).
Here's how it works: The attacker has your username and password (from a phishing attack or breach). They trigger a login attempt, sending an MFA push notification to your phone. Then they do it again. And again. They spam push notifications at all hours hoping you'll eventually tap "Approve" just to make it stop.
This attack has been used against major companies including Microsoft and Uber.
How to protect against MFA fatigue:
- Use number matching in Microsoft Authenticator — the app shows a number that you must match to what's on your screen, making accidental approvals much harder
- Enable additional context in push notifications so users see the app name and location of the login attempt
- Educate users: if they receive an unexpected MFA push, they should deny it and contact IT immediately
- Consider hardware keys for high-risk accounts
Common Objections (and Responses)
"It's too inconvenient for my team." Modern MFA with Microsoft Authenticator typically adds about 5 seconds to the login process. Once users are set up, most find it barely noticeable. The inconvenience of a compromised account is immeasurably worse.
"We're a small business — no one's targeting us." Most credential attacks are automated and indiscriminate. Attackers aren't choosing you specifically; they're running tools against millions of accounts simultaneously. Small businesses are hit constantly.
"Our passwords are strong enough." Strong passwords don't protect against phishing, credential stuffing from third-party breaches, or malware. MFA covers attack vectors that passwords simply can't.
Need Help?
TechniWorx deploys and manages MFA for businesses across Chicagoland, including full Microsoft 365 Conditional Access policy configuration. If you're not sure your MFA setup is properly configured — or you haven't started yet — schedule a free security review and we'll take a look.
