Multi-factor sign in (MFA): why a stolen password shouldn’t open your email

Passwords leak. It’s usually not anyone’s fault. It’s what happens next that matters.

With email in the cloud, a stolen password can be used from anywhere in the world. Multi-factor sign in (MFA) asks for a second proof, like a prompt on your phone, so the password alone isn’t enough. Insurers commonly ask about it. Here’s how it works and how we set it up.

What is multi-factor sign in?

Multi-factor authentication (MFA) means signing in with two or more different kinds of proof: something you know (a password or PIN), something you have (your phone or a security key) and something you are (a fingerprint or face). Someone who steals your password still doesn’t have your phone or your key.

Why it matters

If you own the business

  • Email takeover leads to wire fraud. An attacker inside a real mailbox can send a convincing “new banking details” email to your clients or your bookkeeper.
  • Insurers commonly ask. Multi-factor sign in on email and remote access is a common question on cyber insurance forms. Read your policy and answer honestly.
  • It protects client and patient data stored in email and cloud files.

If you run the office

  • One tap on a phone, most of the time. Trusted devices don’t ask every time.
  • New staff and lost phones are handled. We set up new people and reset lost devices, so it isn’t on you.
  • Fewer “did you send this?” emails to explain to the owner.

Not all second factors are equal

From strongest to weakest. Any of them is far better than a password alone.

Phishing-resistant: security keys and passkeys

A physical key (FIDO2) or a passkey on your device, or Windows Hello for Business. They only work on the real site, so a fake sign-in page can’t capture them.

Strong: authenticator app with number matching

Microsoft Authenticator or Google’s prompts on your phone. Number matching asks you to type the number shown on screen, which defeats “just tap approve” spam.

Better than nothing: text message codes

A code by SMS. Codes can be intercepted or a phone number hijacked (SIM swap), so we move people off SMS where we can.

How we set it up

  1. Multi-factor sign in on email, remote access and business systems. Every account, including the owner’s and every admin account.
  2. Microsoft 365: Conditional Access policies with number matching on every sign-in prompt. (Conditional Access comes with Microsoft 365 Business Premium, or with a Microsoft Entra ID P1 licence.) Older sign-in methods that skip MFA are blocked. Microsoft 365
  3. Google Workspace: 2-Step Verification enforced for every user. Google Workspace
  4. Authenticator app with number matching for everyone. Security keys for every admin account.
  5. Remote desktop is never exposed to the internet. Remote access goes through secure methods that require MFA.
  6. Always a break-glass admin account. A separate emergency admin account, kept locked away, so a lost phone or a locked admin never shuts the business out of its own systems.

What MFA doesn’t do

MFA stops most password-only attacks, but it isn’t magic. Some phishing kits trick people into signing in through a fake page that passes the sign-in through and steals the session. Phishing-resistant methods, Conditional Access, DNS filtering, monitoring and security awareness training close those gaps.

Common mistakes we see

  1. Exempting the owner or the admin account “because it’s annoying”. Those are the accounts attackers want most.
  2. Turning it on for email but not for remote access or the accounting and banking systems.
  3. Leaving old sign-in methods switched on that let an app sign in with only a password.
  4. Approving a prompt you didn’t start. If your phone asks and you didn’t sign in, deny it and call us.
  5. SMS only for everyone, forever.
  6. No plan for a lost phone, so the business gets locked out of its own admin account.

Multi-factor sign in questions

Will my team hate it?

Usually for about a week. After that it’s one tap on a phone, and trusted devices don’t ask every time.

Is MFA the same as two-step verification or 2FA?

Close enough. Google calls it 2-Step Verification. 2FA means exactly two factors. MFA means two or more.

What if someone loses their phone?

Call us. We confirm who they are, reset their sign in and set up the new phone. Every office we set up has a break-glass admin account, so the business is never locked out.

Does MFA mean we can’t be hacked?

No. It blocks most password-only attacks. No provider can promise an attack will never happen. Layers lower the chance and the damage.

Can staff use their personal phones?

Many offices do, with the authenticator app. If staff prefer not to, a small security key works without a phone.

Is every account in your office covered?

Most offices have at least one that isn’t. Call if something looks wrong now, or book a free IT review. No pressure, no jargon.