Practical cyber security guidance

Multi-factor authentication (MFA) for small businesses

MFA is one of the most important controls for protecting business accounts, but not every MFA method offers the same resistance to phishing. The aim is to make stolen passwords far less useful while keeping sign-in practical for staff.

Frequently asked questions

6 practical answers.

### What is MFA?

Multi-factor authentication requires more than one form of evidence before access is granted. This reduces the chance that a stolen or reused password alone can compromise an account.

### Which accounts should have MFA first?

Prioritise administrator accounts, Microsoft 365 and email, remote access, finance systems, password managers, backup administration, domain and DNS accounts, and other services that can be used to reset or control business systems.

### Are text-message codes good enough?

Any properly implemented second factor can improve protection over password-only access, but stronger phishing-resistant options should be preferred for important accounts where supported.

### What are phishing-resistant authentication methods?

Methods based on FIDO2, such as security keys and appropriately implemented passkeys, are designed so authentication is bound to the legitimate service and is much harder to relay through a fake sign-in page.

### Should administrator accounts use stronger MFA?

Yes. Privileged accounts have greater impact if compromised, so they should normally receive the strongest practical authentication controls and should not be used for routine work.

### Can MFA stop every account takeover?

No. MFA significantly reduces risk but does not remove malicious consent, session theft, compromised devices, poor recovery processes or social engineering. It needs to sit inside a wider identity and device strategy.

Related guidance

Keep improving the control set.