DLC Tech Solutions - IT Support for Small Business
    Back to Blog

    Multi-Factor Authentication: Why 'We Have It' Isn't the Same as 'We Use It Properly'

    MFA is one of the most effective security controls available, but only if it is enforced, on the right platforms, with the right method, and a sensible recovery process.

    1 May 20267 min read

    Multi-factor authentication is one of the most widely recommended security controls in existence. Virtually every serious security framework includes it. Most modern platforms support it. And yet it remains one of the most inconsistently implemented things we see when we look at how businesses are actually set up.

    "We have MFA" is very different from "our critical systems are effectively protected by MFA". Here is what the gap often looks like.

    MFA Is On, But Not Enforced

    One of the most common setups we see: MFA is available and some staff have enabled it, but it is not required. Which means that in any given organisation, you might have some users protected and some not, and the attacker only needs to find the ones who are not.

    If MFA is worth having, it is worth enforcing. No opt-in. Required, for everyone, for every account that matters.

    The Wrong Method Is Being Used

    Not all MFA is equal:

    • SMS one-time codes: better than nothing, but vulnerable to SIM-swapping and interception
    • App-based authenticators (Microsoft Authenticator, Google Authenticator, Authy): significantly stronger
    • Hardware keys (like YubiKey): stronger still

    For most SMEs, app based authentication is the right balance of security and usability. If you are using SMS codes as your primary second factor, it is worth upgrading.

    It's Only on Email

    Email is the most obvious place to start with MFA, but it is not the only attack surface. Cloud storage, accounting software, CRM systems, HR platforms, remote access tools, if they hold sensitive data or give access to financial systems, they should have MFA enabled.

    Do a quick audit: what would an attacker be able to access if they had one member of staff's username and password? Every door on that list needs MFA.

    MFA Fatigue Attacks

    A newer and increasingly common attack: flood a user's authenticator app with MFA approval requests, hoping they will eventually click "approve" just to make it stop. It sounds crude, but it works.

    Modern platforms allow you to configure number matching. The app shows a number that matches one on the login screen, you have to type it, not just tap approve. This defeats the attack. If you are using Microsoft 365 or similar, check your MFA configuration.

    No Process for Lost or New Devices

    What happens when someone gets a new phone and can no longer access their authenticator codes? If the answer is "they call IT and we turn MFA off for them temporarily", that is a gap attackers know about and exploit via social engineering.

    Have a documented process for MFA recovery that does not involve just disabling it.

    The Takeaway

    MFA is one of the single most effective controls available. The Microsoft Digital Defense Report has consistently found that MFA blocks the overwhelming majority of account compromise attacks. But it only works if it is implemented properly, enforced, on the right platforms, with the right method, and with a sensible recovery process.

    If you are not certain your MFA setup covers all of the above, get in touch for a Microsoft 365 security review.

    Stay informed

    Get expert cyber security insights delivered to your inbox.

    Stay Updated

    Subscribe to receive the latest insights on cyber security, compliance, and data protection.