Free security check
Home / Blog / Post
Plain-English IT and security

Turn on multifactor sign-in this week: a plain-English guide

SecurityMicrosoft 365By the Paragon MSP team3 min read
Sign in Approve sign-in? 42 Yes No
On this page

Most break-ins at small businesses do not start with a hacker smashing through a firewall. They start with someone signing in with a stolen password. The good news: one setting stops almost all of it, and you can turn it on this week.

97%of identity attacks are password attacks.Source: Microsoft Digital Defense Report 2025
99%+of identity attacks can be blocked by multifactor sign-in.Source: Microsoft Digital Defense Report 2025

What multifactor sign-in is

Multifactor sign-in means a password is not enough to get into an account. After the password, the person also has to prove it is really them with something they carry, usually their phone.

Microsoft calls it multifactor authentication, or MFA. You will also hear "two-step verification." For your business they mean the same thing: a stolen password on its own stops working.

  • Something you know: your password.
  • Something you have: your phone with the Microsoft Authenticator app, or a small security key.
  • Sometimes something you are: a fingerprint or face scan on your device.

Why passwords alone are not enough

Passwords leak in ways your team never sees. A shopping site gets breached. Someone reuses their work password at home. A fake sign-in page collects it in seconds.

Attackers then try those passwords against Microsoft 365 accounts by the thousands, all day, every day. They do not need to be clever. They only need one match.

Multifactor sign-in breaks that chain. Even with the right password, the attacker does not have your phone.

Your five-day plan

You do not need a big project. Here is a simple week that works for most teams of 10 to 150 people.

  1. Monday: list the accounts that matter. Start with Microsoft 365, then your bank, payroll, accounting software, and the place where your website domain is registered. If one of these gets taken over, it hurts.
  2. Tuesday: protect the admins first. Anyone who can change settings, add users, or reset passwords gets multifactor sign-in today. Admin accounts are the keys to everything else.
  3. Wednesday: tell your team what is coming. Send a short note: what is changing, why, and what they will see on their phone. People push back on surprises, not on security.
  4. Thursday: turn it on for everyone. In Microsoft 365 you can switch on security defaults, a free set of baseline protections that includes multifactor sign-in. If you have Microsoft 365 Business Premium, use Conditional Access instead. Conditional Access is a set of rules for who can sign in, from where, and on which devices.
  5. Friday: check who is left. The Microsoft Entra admin center shows which users have set up a second step and which have not. Follow up with each person by name.

Pick the right second step

Not every second step is equally strong. Here is the plain version.

  • Best for most people: the Microsoft Authenticator app with number matching. The screen shows a number, and you type it into your phone. That stops people from approving a prompt by accident.
  • Best for admins: a passkey or a physical security key. These cannot be fooled by a fake sign-in page.
  • Better than nothing: text message codes. They work, but a criminal can sometimes move your phone number to their own SIM card. Use them only as a backup.
Teach this one rule. If your phone asks you to approve a sign-in you did not start, say no. Then tell IT. It means someone has your password.

When people push back

Someone will say it is annoying. Fair. Here is how to keep it painless.

  • With the right settings, most people only see a prompt on a new device or after some time has passed, not every time they open email.
  • Set it up together in a short team meeting, so nobody gets stuck alone.
  • Shared mailboxes should not have their own sign-in at all. Give people access through their own accounts instead.
  • Lead from the top. When the owner turns it on first, everyone else follows.

What to do next

Turning on multifactor sign-in is the single biggest security step most small businesses can take. Security defaults cost nothing extra in Microsoft 365, and the rollout fits in one week.

If you want a second set of eyes, our free Microsoft 365 security check shows who has multifactor sign-in turned on and who does not. It takes 30 minutes, and you keep the report.

Related planSecureIncludes identity protection for Microsoft 365.

Want to know where your business stands today?

Get my free Microsoft 365 security check

Not sure where to start?

Book the free Microsoft 365 security check. It takes 30 minutes, and you keep the report.