All resources

Cybersecurity

How to set up multi-factor authentication in Microsoft 365

September 2, 2026 · 5 min read

Multi-factor authentication (MFA) is the single most effective thing a small business can do to protect its email. Stolen passwords are cheap and common; a second factor is what stops a stolen password from becoming a stolen mailbox.

Why MFA matters more than a strong password

Most business email compromises do not start with a sophisticated hack. They start with a password that was reused somewhere else, guessed, or typed into a convincing fake login page. Once an attacker has that password, they sign in as your employee, read email quietly for a few weeks, and then send an invoice with their own bank details on it.

MFA breaks that chain. Even with the correct password, the attacker is stopped at a second prompt they cannot answer.

Before you turn it on

  • Make a list of every account, including shared mailboxes, owners, and anyone who only logs in occasionally.
  • Decide on the method: an authenticator app is far safer than text messages.
  • Warn your team a few days ahead so the prompt is not a surprise.
  • Identify any device or app that logs in with a stored password — old printers that scan to email and legacy mail clients are the usual culprits.

Turning MFA on

  1. Sign in to the Microsoft 365 admin center with an administrator account.
  2. Open Identity (Microsoft Entra), then Protection, then Conditional Access or Security defaults, depending on your licensing.
  3. Enable the policy that requires multi-factor authentication for all users.
  4. Have each user install Microsoft Authenticator on their phone and complete the enrollment prompt at their next sign-in.
  5. Confirm every user has enrolled — the admin center shows who has not.

Keep at least one administrator account with a recorded, securely stored recovery method. Locking every admin out of your own tenant is a bad afternoon.

The mistakes that cause lockouts

  • Enrolling MFA on a phone that the employee is about to replace.
  • Forgetting shared mailboxes and service accounts used by scanners or line-of-business software.
  • Relying only on text messages, which can be intercepted through SIM swapping.
  • No documented process for when someone loses or wipes their phone.

What good looks like afterward

Every user signs in with an app prompt, admins have a tested recovery path, legacy sign-in methods are blocked, and you can see enrollment status at a glance. If that is not where your tenant stands today, it is worth a review.

Ready to stop worrying about your technology?

Start with a free IT Health Check, or tell us about the problem you are dealing with today.