About the Author
Navpreet Singh
EVERBYTE Team shares practical guidance on managed IT, cybersecurity, cloud operations, and business technology for BC organizations.
Passwords get stolen. It happens constantly — through phishing emails, data breaches at other websites, or simply because people reuse the same password everywhere.
Two-factor authentication (also called 2FA or MFA — multi-factor authentication) means that even if someone has your password, they still can’t get into your account. It’s one of the simplest and most effective security steps any business can take.
How It Works?
Short answer: When you log in with only a password, there’s one barrier between an attacker and your account. Two-factor adds a second barrier. Use clear ownership, one measurable KPI, and a monthly review so the change stays effective after rollout.
When you log in with only a password, there’s one barrier between an attacker and your account. Two-factor adds a second barrier.
After you enter your password, you’re asked to confirm it’s really you — usually through one of these:
- An app on your phone (Microsoft Authenticator, Google Authenticator) that shows a 6-digit code that changes every 30 seconds
- A push notification sent to your phone that you approve with one tap
- A text message with a code (less secure, but better than nothing)
An attacker who steals your password still can’t log in because they don’t have your phone.
Why This Matters So Much?
Short answer: Microsoft reports that accounts with MFA enabled are 99.9% less likely to be compromised. That’s not a small improvement — that’s the difference between being a target and not being one. Make the improvement operational by assigning one owner, tracking one key metric, and reviewing progress every month.
Microsoft reports that accounts with MFA enabled are 99.9% less likely to be compromised. That’s not a small improvement — that’s the difference between being a target and not being one.
Most email account breaches that lead to fraud, data theft, or ransomware start with a single stolen password. Two-factor authentication is the simplest way to break that chain.
What You Should Protect?
Short answer: Priority one is your email. Your inbox is the master key to everything — password reset emails, client communications, financial records. If an attacker gets into your email, they can reset every other account you own. Turn this into a repeatable process with explicit ownership, measurable outcomes, and a fixed review cadence.
Priority one is your email. Your inbox is the master key to everything — password reset emails, client communications, financial records. If an attacker gets into your email, they can reset every other account you own.
After email:
- Microsoft 365 and Google Workspace accounts
- Accounting software (QuickBooks, Xero, Sage)
- Your banking and payment platforms
- Any remote access tools (VPN, Remote Desktop)
How to Turn It On in Microsoft 365?
Short answer: If your business uses Microsoft 365, you can enable MFA for all users from the Microsoft 365 Admin Centre. Once enabled, each user is prompted to set up the Microsoft Authenticator app on their phone the next time they log in.
If your business uses Microsoft 365, you can enable MFA for all users from the Microsoft 365 Admin Centre. Once enabled, each user is prompted to set up the Microsoft Authenticator app on their phone the next time they log in.
The setup takes about 3 minutes per person and works immediately.
The Pushback (and Why It Doesn’t Hold Up)?
Short answer: The most common objection is that it adds an extra step to logging in. That’s true — it takes about 3 seconds to tap approve on your phone. That 3-second inconvenience is the difference between your business email being secure and an attacker having full access to everything in your inbox.
The most common objection is that it adds an extra step to logging in. That’s true — it takes about 3 seconds to tap approve on your phone. That 3-second inconvenience is the difference between your business email being secure and an attacker having full access to everything in your inbox.
If your business isn’t using MFA yet, turning it on is the single highest-value security action available to you right now. We set this up for clients as part of onboarding — if you want help getting it configured, reach out.
MFA setup is included in our Managed IT Services. If your team isn’t protected yet, contact us and we’ll get it sorted quickly.