Resource
MFA and password management rollout
Multi factor authentication is the highest value security control available to a small business and the one most often deployed partially. The technical work takes an afternoon. The rollout is where it succeeds or fails, and the most common failure is granting exemptions to exactly the people who need it most.
Coverage order
Most businesses enable MFA on email and stop. The two remaining gaps are where incidents actually begin.
| Account type | Priority |
|---|---|
| Administrative accountsHighest authority, most commonly exempted for convenience | First |
| Remote access and VPNThe entry point most often exploited at this scale | First |
| EmailHighest volume attack surface | First |
| Cloud line of business applicationsFrequently holds the most sensitive data | Second |
| Financial and payroll systemsDirect route to money | Second |
| Internal applicationsLower exposure, but include in the plan | Third |
Running the rollout
Six steps that avoid the resistance most deployments encounter.
- Start with the leadership team, so nobody can argue it is imposed downward
- Deploy an authenticator app rather than SMS where possible, since app based codes are stronger
- Give people a fortnight of notice and a short written explanation of why
- Run a drop in session rather than sending instructions alone
- Set up backup codes or a second method before enforcement, to avoid lockouts
- Enforce with no exemptions, including for executives and administrators
Password managers make MFA stick
Multi factor authentication protects an account after a password is compromised. A password manager reduces how often that happens, and the two work considerably better together.
The practical benefit staff notice immediately is that they stop needing to remember anything, which turns a security control into a convenience. That is the argument to lead with internally rather than the risk argument.
The organisational benefit is shared credentials in a vault rather than a spreadsheet, and the ability to revoke access when someone leaves without changing a password everyone knows.
Common questions
Answered before you ask.
Staff will complain. How do we handle it?
Most resistance disappears within a fortnight, because the actual friction is a prompt every few days rather than every login when conditional access is configured sensibly. Announcing it properly, starting with leadership and running a short drop in session removes most of it. What generates lasting resentment is a chaotic rollout with lockouts.
Is SMS good enough for the second factor?
It is considerably better than nothing and weaker than an authenticator app, because SMS can be intercepted through number porting attacks. Use app based authentication where you can and keep SMS as a fallback for people who genuinely cannot use an app rather than as the default.
What about accounts that cannot support MFA?
Document them, restrict what they can reach, use a long unique password from the vault, and put replacing or upgrading that system on the roadmap. An undocumented exception is a gap. A documented one with a compensating control is a managed risk.
Related
Read next.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Zero trust for small business
What the term means once the marketing is removed.
Security awareness training
Phishing simulation and short, frequent training that changes behaviour.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.