All systems operational · Ormskirk, North West England

How to Configure Multi Factor Authentication

Learn how to configure multi factor authentication for your business, reduce account risk and support staff with a clear, practical rollout plan safely.

A compromised Microsoft 365 account can turn an ordinary working day into a serious business incident. One convincing phishing email, a reused password or a lost device may be enough to expose customer data, financial information and internal systems. To configure multi factor authentication properly is one of the most effective steps a business can take to reduce that risk without making everyday work unnecessarily difficult.

Multi factor authentication, often shortened to MFA, asks a user to prove their identity using more than a password. That additional check might be an approval prompt on a mobile app, a time-based code, a security key or, in some cases, a text message. Passwords can be guessed, stolen and reused. A second factor means a password alone is far less useful to an attacker.

For small and mid-sized businesses, the objective is not simply to switch MFA on. It is to introduce it in a way that protects the systems people actually use, accounts for different working patterns and gives staff clear support when something changes.

Start with the accounts that matter most

MFA should cover every cloud service that holds business information or gives access to it. Email is usually the first priority, particularly Microsoft 365 or Google Workspace, because email inboxes are commonly used to reset passwords for other services. Remote access, accounting platforms, customer relationship management systems, file storage, payroll, password managers and administrative portals should follow closely behind.

Administrative accounts deserve special treatment. These accounts can create users, change security settings, access large volumes of data or disable protections. Each administrator should have their own named account, protected by MFA, rather than sharing a generic login. It is also sensible to use separate accounts for day-to-day work and administration, so elevated access is only used when required.

Before rollout, create a simple inventory of systems, account owners and access methods. This identifies older applications or supplier-managed services that may not support modern authentication. Those exceptions need a plan, not an assumption that they are safe because they are less visible.

How to configure multi factor authentication well

The exact menu options depend on your chosen platform, but a sound deployment follows the same practical sequence. Begin by confirming your licences and identity platform support the policies you intend to use. In Microsoft 365 environments, this will often mean configuring MFA through Microsoft Entra ID and using Conditional Access where licensing permits. Other providers offer comparable controls.

Next, choose your permitted verification methods. Authentication apps are generally the best starting point for most staff. They are straightforward to use, work without mobile signal once configured for codes, and are more resistant to interception than SMS. Number matching or similar approval protections can reduce the risk of staff accepting repeated, fraudulent push notifications.

Security keys are a strong option for administrators, finance teams and employees handling particularly sensitive information. They can also help staff who do not want to use a personal mobile phone for authentication. SMS can be useful as a temporary fallback, but it should not be the preferred method where safer alternatives are available. Text messages can be delayed, intercepted or targeted through SIM-swap fraud.

Set a registration period rather than forcing everyone to enrol without notice. During that period, users can register an authentication app or security key while they still have support available. After the deadline, require MFA for sign-in. A phased approach, starting with leadership, IT administrators and higher-risk teams, allows the business to resolve issues before wider enforcement.

Make the user experience part of the security plan

MFA is often resisted when it arrives as an unexplained prompt during a busy morning. Clear communication changes that. Tell staff when the change is happening, why it is being introduced and what they need to do. Keep instructions short, use screenshots where appropriate and explain how to get help if their phone is replaced, lost or unavailable.

It is worth being direct about one crucial rule: staff should never approve an unexpected sign-in request. An approval request they did not initiate can mean someone has obtained their password. They should deny it and report it promptly. This small piece of guidance can prevent an attempted account takeover from becoming a breach.

Avoid treating every user identically. A field engineer, a warehouse colleague on a shared terminal and a finance manager working with payment details may need different methods and policies. The right balance depends on the devices they use, the sensitivity of the data they access and the operational impact if they cannot sign in.

Use policies that reflect real business risk

Once MFA is active, conditional access policies can make protection more targeted. For example, you may require MFA whenever a user signs in from outside the UK, from an unfamiliar device or when accessing sensitive administrative services. You might allow a longer sign-in session on a managed office device but require a fresh check for a personal device or remote connection.

These choices should be considered carefully. Overly aggressive prompts can lead to frustration and workarounds, while policies that are too relaxed may leave unnecessary gaps. The key is to understand how people work before setting rules. Review sign-in data after rollout and adjust based on genuine activity, not guesswork.

Legacy authentication needs particular attention. Older email clients, devices and applications may use protocols that cannot complete MFA. Leaving them active can provide a route around your new controls. Where possible, replace or update them. If an exception is unavoidable, document who owns it, limit its permissions and set a date to review or remove it.

Protect the recovery process

The recovery process is where otherwise good MFA deployments can fail. If anyone can call a helpdesk, answer a few easily found questions and reset a factor, an attacker may bypass the protection you have put in place.

Create a clear identity verification process for lost phones, new devices and locked-out users. It should define who can authorise a reset, how identity is checked and how the action is recorded. For senior leaders and privileged accounts, consider a more stringent verification route. Keep emergency access accounts for genuine outages, protect them with strong controls and monitor their use closely. They are not everyday workarounds.

Recovery codes should be stored securely, not left in an inbox or written on a desk note. Similarly, avoid setting one person up as the sole administrator for MFA. A planned absence, illness or account issue should not prevent the business from managing access.

Test before you enforce

Pilot the setup with a small group that represents different roles, devices and locations. Test signing in from the office, home and mobile networks. Test a new phone enrolment, a lost-device scenario, an administrator login and access to any critical line-of-business application.

Ask practical questions. Can staff complete registration without technical language? Does the service desk know how to help without weakening identity checks? Are travelling employees able to authenticate when abroad? Does a shared mailbox or multifunction printer rely on a password-based process that needs redesigning?

Testing also gives you a realistic view of support demand. The first few days of a rollout normally generate questions. Planning for extra support is far better than leaving employees unable to access email, files or customer systems at the start of the working day.

MFA is a control, not the whole answer

Multi factor authentication materially reduces the risk of password-based attacks, but it does not make an organisation immune to fraud. Attackers can still use convincing phishing messages, persuade users to approve a request, steal browser sessions or exploit poorly protected devices.

MFA works best alongside strong password management, device updates, endpoint protection, backup and recovery planning, staff awareness training and regular access reviews. When an employee leaves, their account must be disabled promptly. When roles change, permissions should change too. Security is most effective when it becomes part of normal operational housekeeping.

For businesses without an in-house IT security team, a managed IT partner can help assess existing sign-in risks, configure appropriate policies, support staff during rollout and review the controls as the business changes. Blowfish Technology approaches this work in practical terms: protecting the services your people rely on while keeping the process clear and manageable.

A well-configured MFA rollout should leave staff with one simple habit: pause when a sign-in request appears, verify it is theirs, and ask for help if it is not. That moment of care can protect far more than a single account.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.