Skip to main content

IT security

What is MFA (multi-factor authentication)?

MFA (multi-factor authentication) stops the vast majority of automated attacks. See how it works, and why Microsoft is making it mandatory.

In short

Multi-factor authentication (MFA) means that a login requires at least two independent proofs of identity: something you know (a password), something you have (a phone or security key) or something you are (a fingerprint or face).

Even if an attacker steals the password through phishing or a data breach, the account cannot be taken over without the second factor. That makes MFA relevant for every business with Microsoft 365, email or remote access, and Microsoft is gradually making it mandatory in its cloud services.

According to Microsoft's own figures, MFA blocks over 99 percent of automated account attacks, but the effect depends on the method: authenticator apps with number matching and passkeys are markedly stronger than SMS codes, and MFA must cover administrator accounts and legacy protocols, not just ordinary users.

MI Support IT implements MFA correctly in Microsoft 365 and Entra ID with Conditional Access, closes the gaps and makes sure the whole organisation is covered.

Back to the glossary

What is MFA (multi-factor authentication)?

MFA (multi-factor authentication, also called two-factor authentication, two-step verification or 2FA) means that a login requires at least two independent proofs of identity: something you know (a password), something you have (a phone or security key) or something you are (a fingerprint or face). Even if an attacker steals the password, for example via phishing or a data breach, the account cannot be taken over without the second factor.

MFA is the single security measure with the greatest effect relative to the effort: Microsoft's own figures show that it blocks over 99% of automated account attacks. But the method matters. From weakest to strongest: SMS codes (can be bypassed via SIM swapping), authenticator apps with push and number matching, and at the top FIDO2/passkeys, which are phishing resistant because the authentication is cryptographically bound to the genuine site.

How to set up MFA in Microsoft 365

In a Microsoft environment, MFA is managed centrally via Microsoft Entra ID. The overall steps:

  1. Enable security defaults or Conditional Access: the latter gives fine-grained control over when and where MFA is required.
  2. Have users register Microsoft Authenticator as the primary method, with a backup method for lost phones.
  3. Block legacy protocols (IMAP/POP), which otherwise bypass MFA entirely.
  4. Cover administrator accounts, service access and VPN, which are the typical gaps in practice.

What is Microsoft Authenticator?

Microsoft Authenticator is Microsoft's free app for iOS and Android, which most businesses use as their primary MFA method. At login, the app sends a push notification, the user approves, and with number matching the user must enter a number from the login screen into the app. That stops "MFA fatigue", where users reflexively tap approve on a fake request. The app can also generate one-time codes without network access and act as a passkey, so the password can eventually be phased out entirely.

MFA vs. 2FA: are they the same?

Almost. 2FA (two-factor authentication) requires exactly two factors; MFA is the umbrella term for two or more. All 2FA is therefore MFA, but not the other way around. In practice the words are used interchangeably, and two-step verification is another name for the same principle. What matters is not the terminology, but that the factors are independent: a password plus a code sent to the same email account does not count.

Why is MFA becoming mandatory?

Microsoft is making MFA mandatory across more and more surfaces: first for administrator portals such as the Azure Portal and the Microsoft 365 admin centre, and gradually more broadly via enforced security policies. The reason is simple: the vast majority of compromised accounts did not have MFA enabled. The requirements and timeline are documented at learn.microsoft.com. Combined with SSO, the result is one strongly protected login instead of many weak ones.

How MI Support IT can help

We implement MFA correctly in Microsoft 365 and Entra ID with Conditional Access, close legacy gaps and make sure employees, administrators and remote access are all covered, as part of ongoing IT security. If you need a review of your setup, contact us.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.