Most break-ins at small businesses do not start with a hacker smashing through a firewall. They start with someone signing in with a stolen password. The good news: one setting stops almost all of it, and you can turn it on this week.
What multifactor sign-in is
Multifactor sign-in means a password is not enough to get into an account. After the password, the person also has to prove it is really them with something they carry, usually their phone.
Microsoft calls it multifactor authentication, or MFA. You will also hear "two-step verification." For your business they mean the same thing: a stolen password on its own stops working.
- Something you know: your password.
- Something you have: your phone with the Microsoft Authenticator app, or a small security key.
- Sometimes something you are: a fingerprint or face scan on your device.
Why passwords alone are not enough
Passwords leak in ways your team never sees. A shopping site gets breached. Someone reuses their work password at home. A fake sign-in page collects it in seconds.
Attackers then try those passwords against Microsoft 365 accounts by the thousands, all day, every day. They do not need to be clever. They only need one match.
Multifactor sign-in breaks that chain. Even with the right password, the attacker does not have your phone.
Your five-day plan
You do not need a big project. Here is a simple week that works for most teams of 10 to 150 people.
- Monday: list the accounts that matter. Start with Microsoft 365, then your bank, payroll, accounting software, and the place where your website domain is registered. If one of these gets taken over, it hurts.
- Tuesday: protect the admins first. Anyone who can change settings, add users, or reset passwords gets multifactor sign-in today. Admin accounts are the keys to everything else.
- Wednesday: tell your team what is coming. Send a short note: what is changing, why, and what they will see on their phone. People push back on surprises, not on security.
- Thursday: turn it on for everyone. In Microsoft 365 you can switch on security defaults, a free set of baseline protections that includes multifactor sign-in. If you have Microsoft 365 Business Premium, use Conditional Access instead. Conditional Access is a set of rules for who can sign in, from where, and on which devices.
- Friday: check who is left. The Microsoft Entra admin center shows which users have set up a second step and which have not. Follow up with each person by name.
Pick the right second step
Not every second step is equally strong. Here is the plain version.
- Best for most people: the Microsoft Authenticator app with number matching. The screen shows a number, and you type it into your phone. That stops people from approving a prompt by accident.
- Best for admins: a passkey or a physical security key. These cannot be fooled by a fake sign-in page.
- Better than nothing: text message codes. They work, but a criminal can sometimes move your phone number to their own SIM card. Use them only as a backup.
When people push back
Someone will say it is annoying. Fair. Here is how to keep it painless.
- With the right settings, most people only see a prompt on a new device or after some time has passed, not every time they open email.
- Set it up together in a short team meeting, so nobody gets stuck alone.
- Shared mailboxes should not have their own sign-in at all. Give people access through their own accounts instead.
- Lead from the top. When the owner turns it on first, everyone else follows.
What to do next
Turning on multifactor sign-in is the single biggest security step most small businesses can take. Security defaults cost nothing extra in Microsoft 365, and the rollout fits in one week.
If you want a second set of eyes, our free Microsoft 365 security check shows who has multifactor sign-in turned on and who does not. It takes 30 minutes, and you keep the report.
Want to know where your business stands today?