Multi-factor authentication is the highest-value security control available to a small business, by a wide margin. Microsoft's published analysis puts the reduction in account compromise risk above 99%, and no other single measure comes close for the effort involved.
It is also, increasingly, not optional. The FTC Safeguards Rule names it explicitly. Cyber insurers require it as a condition of coverage. Client security questionnaires ask about it directly. The question has moved from whether to deploy it to whether your deployment actually works.
That second question is where most businesses have a problem, because MFA can be present and still be bypassable.
The methods, from weakest to strongest
SMS codes — weak, but better than nothing
Vulnerable to SIM swapping, where an attacker convinces a mobile carrier to transfer your number to their device. Also interceptable in transit. Still enormously better than a password alone, so if SMS is what your staff will actually adopt, deploy it and improve later — but do not use it for administrative accounts.
Authenticator app codes — reasonable
Time-based codes from Microsoft Authenticator, Google Authenticator or similar. No carrier dependency and no SIM swap exposure. Still phishable: a convincing fake login page can capture the code and use it within its validity window.
Push notifications — reasonable, with a caveat
Convenient and widely adopted, but vulnerable to MFA fatigue. An attacker with a valid password sends repeated prompts until the user approves one out of irritation or confusion. This has featured in several significant breaches.
The mitigation is number matching, where the user must enter a digit displayed on the login screen rather than simply tapping approve. Microsoft now enforces this by default, and it should be on everywhere.
Phishing-resistant methods — strongest
FIDO2 security keys, passkeys, and certificate-based authentication are cryptographically bound to the legitimate site, which means a fake login page cannot relay them. This is the only category that genuinely defeats adversary-in-the-middle phishing.
Deploy these for administrative accounts at minimum. Hardware keys cost roughly the price of a decent lunch and eliminate an entire attack class.
The gap that makes MFA useless
The most common serious failure is not weak MFA. It is MFA that can be bypassed entirely because an authentication path exists that never triggers it.
Legacy authentication
Older protocols — IMAP, POP3, SMTP AUTH, and legacy Exchange endpoints — do not support modern authentication and therefore cannot enforce MFA. If these remain enabled on your tenant, an attacker with a valid password can authenticate through them and never see a prompt.
This is the single most important configuration check to perform. Microsoft has been disabling legacy authentication progressively, but exceptions persist in tenants that requested them, and older line-of-business applications sometimes depend on them.
Partial coverage
MFA on email but not on VPN. On the main system but not the finance application. On staff but not on the service accounts that hold the most privilege. Attackers look for the gap rather than the wall.
Excluded accounts
Exclusions accumulate — a break-glass account, an executive who found it inconvenient, a shared mailbox, a vendor's access. Each is a documented bypass. Review the exclusion list; it is usually longer than anyone expects.
Unprotected provider access
Your IT provider's access into your environment is highly privileged. Confirm it is protected by MFA, and specifically that their administrative accounts are not exempted from your policies.
What to protect, in order
- Administrative accounts — global admins, domain admins, anything with elevated privilege. Phishing-resistant methods, no exceptions.
- Email — the account that can reset every other account. Compromised email is the starting point for most business email compromise.
- Remote access — VPN, remote desktop, any external entry point.
- Financial systems — banking, payroll, accounts payable. The direct target of most fraud.
- Line-of-business applications holding client data — practice management, case management, CRM.
- Everything else.
The reason administrative accounts come first is straightforward: an attacker who reaches one does not need to phish anyone else.
Getting it adopted without a revolt
Resistance is normally about disruption rather than security, and most of it is avoidable:
- Configure trusted device and trusted location policies so people are not prompted constantly. Prompting every login is what makes users seek workarounds.
- Roll out in stages by department, starting with IT and leadership. Leadership going first removes the argument that it is for everyone else.
- Explain the reason with a concrete example rather than policy language. Business email compromise resonates because people have heard of it happening.
- Have a defined process for lost or replaced phones before you need it. This is the most common support ticket after rollout.
- Offer hardware keys to anyone who genuinely cannot use a phone, rather than granting an exemption.
Avoid permanent exemptions entirely. Every exemption is an account an attacker only has to find, and exemptions granted as temporary have a strong tendency to become permanent.
The realistic view
MFA is not a complete defence. Session token theft, adversary-in-the-middle phishing kits, and compromised endpoints can all bypass it, which is why conditional access, endpoint detection and monitoring still matter.
But it eliminates the overwhelming majority of credential-based attacks, which remain the most common way small businesses are compromised. Nothing else available at comparable cost changes the risk profile as much — and increasingly, going without it is a decision that also costs you insurance, contracts, and compliance standing.