Skip to content
Serving Dallas, Irving and the DFW metroplex (214) 000-0000 hello@nixitek.com
NIXITEK

Home / Insights

Microsoft 365 multi-factor authentication: what to turn on first

Published 2026-08-04

If you do one security thing this quarter, make it this. Stolen passwords are how most small-business breaches start, and multi-factor authentication is the control that makes a stolen password nearly worthless.

Start with administrators, not everyone

Global administrator accounts are the highest-value target in your tenant, and there are usually only a handful of them. Enable multi-factor authentication on those first, verify it works, and confirm you have a documented break-glass account stored somewhere safe and offline. Doing administrators first means that if the wider rollout goes badly, the people who can fix it still have access.

Turn off legacy authentication before you rely on MFA

This is the step most rollouts skip, and it quietly undoes the work. Older mail protocols cannot present a second factor, so if they remain enabled an attacker can often bypass your new policy entirely by connecting through one of them. Check for anything still using them, migrate it, then block legacy authentication tenant-wide. If you enable MFA but leave those protocols open, you have bought less protection than you think.

Choose the method, and it is not SMS

Text message codes are better than nothing and worse than everything else, because phone numbers can be moved to an attacker's device through the carrier. An authenticator app with number matching is the sensible default for most businesses. For administrators and anyone handling payments, hardware security keys are worth the cost and the small amount of friction.

Expect the two things that always break

Shared mailboxes accessed with a shared password, and devices in back offices or on shop floors that nobody has logged into properly in years. Both will surface within a day of enforcement. Neither should be solved by exempting them: shared mailboxes should be converted to proper delegated access, and the forgotten devices need an owner. An exception granted during rollout becomes permanent.

Communicate once, clearly, before you enforce

Tell staff what will change, on what date, and what to do if they get locked out. A single clear message a week ahead prevents most of the support load. The rollouts that generate complaints are the ones where people discovered the change by being locked out of their email on a Monday morning.

What good looks like when you are done

Every account has a second factor, legacy authentication is blocked, administrators use phishing-resistant methods, the break-glass account is documented and stored offline, and you have a written record of any exception with a date for removing it. That is a week of work for most small businesses and it closes the single largest hole in the average environment.

Start with an assessment, not a contract

A short scoping call, then a fixed-price review of your security, cloud and support setup. You keep the findings either way.