Microsoft 365 multi-factor authentication: what to turn on first
If you do one security thing this quarter, make it this. Stolen passwords are how most small-business breaches start, and multi-factor authentication is the control that makes a stolen password nearly worthless.
Start with administrators, not everyone
Global administrator accounts are the highest-value target in your tenant, and there are usually only a handful of them. Enable multi-factor authentication on those first, verify it works, and confirm you have a documented break-glass account stored somewhere safe and offline. Doing administrators first means that if the wider rollout goes badly, the people who can fix it still have access.
Turn off legacy authentication before you rely on MFA
This is the step most rollouts skip, and it quietly undoes the work. Older mail protocols cannot present a second factor, so if they remain enabled an attacker can often bypass your new policy entirely by connecting through one of them. Check for anything still using them, migrate it, then block legacy authentication tenant-wide. If you enable MFA but leave those protocols open, you have bought less protection than you think.
Choose the method, and it is not SMS
Text message codes are better than nothing and worse than everything else, because phone numbers can be moved to an attacker's device through the carrier. An authenticator app with number matching is the sensible default for most businesses. For administrators and anyone handling payments, hardware security keys are worth the cost and the small amount of friction.
Expect the two things that always break
Shared mailboxes accessed with a shared password, and devices in back offices or on shop floors that nobody has logged into properly in years. Both will surface within a day of enforcement. Neither should be solved by exempting them: shared mailboxes should be converted to proper delegated access, and the forgotten devices need an owner. An exception granted during rollout becomes permanent.
Communicate once, clearly, before you enforce
Tell staff what will change, on what date, and what to do if they get locked out. A single clear message a week ahead prevents most of the support load. The rollouts that generate complaints are the ones where people discovered the change by being locked out of their email on a Monday morning.
What good looks like when you are done
Every account has a second factor, legacy authentication is blocked, administrators use phishing-resistant methods, the break-glass account is documented and stored offline, and you have a written record of any exception with a date for removing it. That is a week of work for most small businesses and it closes the single largest hole in the average environment.
More from Nixitek
What an IT assessment should actually give you
How to tell a genuine IT and security assessment from a sales document, what deliverables…
Why your AWS bill keeps growing, and five places to look first
The most common causes of cloud cost creep on AWS and Azure, in the order we usually find…
SPF, DKIM and DMARC, explained without the jargon
What the three email authentication records do, why partial setup is the most common…