Skip to content

Resource

MFA and password management rollout

Multi factor authentication is the highest value security control available to a small business and the one most often deployed partially. The technical work takes an afternoon. The rollout is where it succeeds or fails, and the most common failure is granting exemptions to exactly the people who need it most.

Coverage order

Most businesses enable MFA on email and stop. The two remaining gaps are where incidents actually begin.

Multi factor authentication coverage priority
Account typePriority
Administrative accountsHighest authority, most commonly exempted for convenienceFirst
Remote access and VPNThe entry point most often exploited at this scaleFirst
EmailHighest volume attack surfaceFirst
Cloud line of business applicationsFrequently holds the most sensitive dataSecond
Financial and payroll systemsDirect route to moneySecond
Internal applicationsLower exposure, but include in the planThird

Running the rollout

Six steps that avoid the resistance most deployments encounter.

  • Start with the leadership team, so nobody can argue it is imposed downward
  • Deploy an authenticator app rather than SMS where possible, since app based codes are stronger
  • Give people a fortnight of notice and a short written explanation of why
  • Run a drop in session rather than sending instructions alone
  • Set up backup codes or a second method before enforcement, to avoid lockouts
  • Enforce with no exemptions, including for executives and administrators

Password managers make MFA stick

Multi factor authentication protects an account after a password is compromised. A password manager reduces how often that happens, and the two work considerably better together.

The practical benefit staff notice immediately is that they stop needing to remember anything, which turns a security control into a convenience. That is the argument to lead with internally rather than the risk argument.

The organisational benefit is shared credentials in a vault rather than a spreadsheet, and the ability to revoke access when someone leaves without changing a password everyone knows.

Common questions

Answered before you ask.

Staff will complain. How do we handle it?

Most resistance disappears within a fortnight, because the actual friction is a prompt every few days rather than every login when conditional access is configured sensibly. Announcing it properly, starting with leadership and running a short drop in session removes most of it. What generates lasting resentment is a chaotic rollout with lockouts.

Is SMS good enough for the second factor?

It is considerably better than nothing and weaker than an authenticator app, because SMS can be intercepted through number porting attacks. Use app based authentication where you can and keep SMS as a fallback for people who genuinely cannot use an app rather than as the default.

What about accounts that cannot support MFA?

Document them, restrict what they can reach, use a long unique password from the vault, and put replacing or upgrading that system on the roadmap. An undocumented exception is a gap. A documented one with a compensating control is a managed risk.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment