Cybersecurity
How to set up multi-factor authentication in Microsoft 365
September 2, 2026 · 5 min read
Multi-factor authentication (MFA) is the single most effective thing a small business can do to protect its email. Stolen passwords are cheap and common; a second factor is what stops a stolen password from becoming a stolen mailbox.
Why MFA matters more than a strong password
Most business email compromises do not start with a sophisticated hack. They start with a password that was reused somewhere else, guessed, or typed into a convincing fake login page. Once an attacker has that password, they sign in as your employee, read email quietly for a few weeks, and then send an invoice with their own bank details on it.
MFA breaks that chain. Even with the correct password, the attacker is stopped at a second prompt they cannot answer.
Before you turn it on
- Make a list of every account, including shared mailboxes, owners, and anyone who only logs in occasionally.
- Decide on the method: an authenticator app is far safer than text messages.
- Warn your team a few days ahead so the prompt is not a surprise.
- Identify any device or app that logs in with a stored password — old printers that scan to email and legacy mail clients are the usual culprits.
Turning MFA on
- Sign in to the Microsoft 365 admin center with an administrator account.
- Open Identity (Microsoft Entra), then Protection, then Conditional Access or Security defaults, depending on your licensing.
- Enable the policy that requires multi-factor authentication for all users.
- Have each user install Microsoft Authenticator on their phone and complete the enrollment prompt at their next sign-in.
- Confirm every user has enrolled — the admin center shows who has not.
Keep at least one administrator account with a recorded, securely stored recovery method. Locking every admin out of your own tenant is a bad afternoon.
The mistakes that cause lockouts
- Enrolling MFA on a phone that the employee is about to replace.
- Forgetting shared mailboxes and service accounts used by scanners or line-of-business software.
- Relying only on text messages, which can be intercepted through SIM swapping.
- No documented process for when someone loses or wipes their phone.
What good looks like afterward
Every user signs in with an app prompt, admins have a tested recovery path, legacy sign-in methods are blocked, and you can see enrollment status at a glance. If that is not where your tenant stands today, it is worth a review.
Ready to stop worrying about your technology?
Start with a free IT Health Check, or tell us about the problem you are dealing with today.
