featured-image-managed-it-services-1

MFA in the workplace: why it is the measure with the best return and how to enable it without stopping anyone

If you could only do one thing for your company's security this month, it should be this. Multi-factor authentication (MFA) — requiring a mobile confirmation in addition to the password — blocks the vast majority of attacks that start with stolen credentials, which are the vast majority of attacks on SMEs. It costs zero in licences in most cases and can be implemented in two weeks. And yet we find companies with 100 workstations where only the administrator has it enabled. This article explains where to enable it first, which methods to choose, the mistakes that create resistance, and a plan that doesn't lock anyone out.

What MFA solves — and what it doesn't

Resolve the most common scenario: someone wrote their password on a fake website, or reused it on a service that suffered a breach, and the attacker tries to log into the email or VPN. Without MFA, they get in. With MFA, they also need to approve it on the victim's mobile phone — and they can't. It doesn't solve everything: it doesn't protect against malicious software already installed on the computer, nor against a user who approves requests without looking (we'll come back to this). But it shuts the door through which most get in.

Where to activate, in order

  • Microsoft 365 (or Google Workspace)email, files, Teams. It's the company's central identity and the number one target. First for all admins, then for all users.
  • Remote accessVPN, remote working environment, published portals. Everything accessible from the internet with a password. If any of them don't support MFA, they are a candidate to be switched off or placed behind something that does — see a VPN is no longer enough.
  • Banks, Finance, Social Security, supplier portalsmost already mandate it; check that methods are up to date and associated with company mobile phones, not former employees'.
  • Equipment managementfirewall, switches, servers, domain and website hosting panel. Few people, high impact.
  • Password manager: mandatory, because it stores everything else.

Which method to choose

  • Authentication application with notification and number to confirm (Microsoft Authenticator and similar): the best balance between security and convenience for most people. The number to confirm prevents someone from approving a request they didn't make.
  • Physical keys (FIDO2)the strongest, phishing-resistant method. Recommended for administrators, management and finance.
  • SMSbetter than nothing, but vulnerable to SIM swapping and interception. Use only as an emergency fallback.
  • Email codes— avoid — if the email is compromised, the second factor is too.

The mistakes that create resistance

Requiring MFA at every login instead of once a day per trusted device — people end up hating it. Failing to plan for those without a company mobile (hardware keys or tokens sort this). Enabling everything on the same day without warning — the helpdesk gets swamped. Not having a recovery method when someone loses their phone — they are locked out of their email for a workday. And most seriously: not explaining “fatigue attacks”. Attackers send dozens of approval requests until the person taps “yes” out of tiredness; matching the number and a sentence in training (“never approve what you didn't ask for”) solves this.

Two-week plan

  • Days 1-2: enable for all administrators. Set the policy: mandatory MFA, session remembered by trusted device, SMS as a fallback only. Prepare a one-page guide with screenshots.
  • Days 3-5Pilot with one department. 15-minute session, mobile phone check-in, test. Gather questions and correct the guide.
  • Days 6-10remaining departments, one per day, with the helpdesk available. Anyone who has not registered by the specified date will be forced to register upon their next login — Microsoft allows this grace period.
  • 11th-14th Daysremote access and equipment. Block the old methods. Check on the dashboard who is not yet covered and resolve on a case-by-case basis.

What do you gain besides security

A GDPR requirement demonstrably fulfilled. A NIS2 demand satisfied (the directive explicitly mentions multi-factor authentication). One fewer point on the cybersecurity insurance questionnaire, which almost always asks for it and adjusts the premium. And fewer requests of “I think someone got into my email” — because they didn't.

How it looks on our clients

In the contracts IT Unlimited MFA is configured in Microsoft 365, on the VPN and on administration equipment as part of the service of Microsoft 365 management And so managed cybersecurity, with conditional access so that unmanaged devices can only access the system via a browser. The monthly report shows the percentage of accounts covered — which should be 100%.

Frequently Asked Questions

Does MFA cost anything?

It is included in most Microsoft 365 and Google Workspace plans. Physical keys cost a few tens of euros per person and are justified for high-risk positions. The real cost is the time for implementation and training.

Will people have to approve at each login?

No, if the policy is configured correctly: once per trusted device, renewed periodically. On new or unknown devices, it always asks — that's the protection.

And what about those who don't want to install company apps on their personal mobile?

Offer alternatives: physical key, hardware token or company mobile phone for roles that justify it. This is not a reason to exempt anyone.

With MFA active, do I still need a password manager?

Yes. MFA protects the account when the password is stolen; the manager ensures that the password is not reused on services that do not have MFA. They are complementary — see the article on password managers in the company.

Do you still have accounts without MFA?

We've activated MFA in Microsoft 365, on remote access and on devices, with 15-minute training per team and without blocking anyone. See our managed cybersecurity for businesses or call 211 459 950.

Read more articles ...

Find out about some of the companies that have already chosen and opted for our IT services

Talk to Us now

Contact Form

Request a quote from DataRoad. We’ll take care of the rest with a prompt and clear response to support your business’s needs.

Tell us what you need. IT support, network installation, cyber security, an office move or simply a second opinion on your IT infrastructure — we’re here to help.

Please fill in the form and a specialist technician will contact you on the same day.

    B2B only, always on contract. We do not do one-off jobs or subcontracting.

    A reply on the same working day. No obligation.

    DataRoad — IT services for businesses
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.