4 min read

Multi-Factor Authentication for Small Businesses: What It Is and How to Switch It On

Multi-Factor Authentication for Small Businesses: What It Is and How to Switch It On

Multi-factor authentication (MFA) asks for a second proof of identity on top of your password, usually a tap or a code on your phone, and most small businesses can switch it on for free from their Microsoft 365 or Google Workspace admin settings.

It's one of the cheapest security wins available, and still one of the most skipped. According to the government's Cyber Security Breaches Survey 2025/2026, only 47% of UK businesses require any form of it. Among large businesses the figure is 90%.

How does multi-factor authentication protect my online accounts?

MFA protects your accounts by making a stolen password useless on its own. An attacker would also need something only you have, usually your phone.

That matters because passwords get stolen constantly, most often through phishing. 38% of UK businesses experienced a phishing attack last year. With MFA in place, the person who typed their password into a fake login page has made a mistake. Without it, they've handed over the account.

What are the common types of MFA methods available today?

The common MFA methods are text message codes, authenticator apps, security keys and biometrics such as a fingerprint or face scan.

  • SMS codes: a six-digit code sent by text.
  • Authenticator app codes: a code that refreshes every 30 seconds in an app such as Microsoft Authenticator or Google Authenticator.
  • Push notifications: your phone asks "Is this you signing in?" and you approve it, often by matching a number on screen.
  • Security keys and passkeys: a physical USB or NFC key, or a credential stored on your device and unlocked with your fingerprint or face.

What multi-factor authentication methods are considered the most secure?

Security keys and passkeys built on the FIDO2 standard are the most secure MFA methods, because they can't be phished.

The NCSC's recommended types of MFA put FIDO2 credentials first. A key only works with the genuine website it was registered to, so a fake login page gets nothing. Authenticator apps with number matching come next. The NCSC notes they can be worn down by "prompt fatigue", where attackers send approval requests until someone taps yes to make them stop. Codes and text messages sit lower down the list.

Security keys are sold by UK IT suppliers and by the manufacturers directly. For most small teams, though, an authenticator app is the practical starting point.

What is the difference between SMS and app-based multi-factor authentication?

SMS codes arrive by text message, while app-based codes are generated on your phone itself, which makes apps harder to intercept or hijack.

A text can be redirected if a criminal persuades your mobile network to move your number to their SIM. An authenticator app doesn't rely on the phone network at all. The NCSC treats SMS as a last resort, for systems that offer nothing better. It's still far better than no MFA, so don't turn it off while you plan the move to an app.

How do I enable multi-factor authentication on my email account?

You enable MFA for business email from your admin centre: security defaults in Microsoft 365, or 2-Step Verification in Google Workspace.

Microsoft 365

  1. Sign in to the Microsoft Entra admin centre as a Global Administrator.
  2. Go to Entra ID > Overview > Properties and select Manage security defaults.
  3. Set security defaults to Enabled and save.

Microsoft's security defaults are free, require every user to register for MFA, and block older sign-in methods that bypass it. Businesses with Entra ID P1 licences can use Conditional Access for more control instead.

Google Workspace

  1. In the Admin console, go to Security > Authentication > 2-step verification.
  2. Tick Allow users to turn on 2-Step Verification and leave enforcement off for now.
  3. Once your team has enrolled, return and set enforcement to On.

Google's own deployment guide recommends letting people enrol before enforcing, so nobody gets locked out.

Which MFA solution is best suited for a small business with remote employees?

For most small businesses with remote staff, the best MFA solution is the one already built into Microsoft 365 or Google Workspace, paired with an authenticator app on each person's phone.

It costs nothing extra and protects email and cloud files wherever people log in from. Most business apps can also sign in through it, so one MFA setup covers them too. Remote access tools and VPNs should sit behind the same MFA. A separate MFA platform only earns its place once you have systems your main account can't protect.

What are the key considerations for implementing MFA across an organisation?

The key considerations are making sure every account is covered and having a plan for when someone loses their phone.

  • Start with admin and finance accounts, then roll out to everyone.
  • Tell people before you switch it on. Explain why, and when.
  • Cover every cloud service, not just email. Under the Cyber Essentials update that took effect on 27 April 2026, a cloud service that offers MFA but doesn't have it switched on means an automatic fail. The NCSC's Cyber Essentials overview explains the scheme, and our guide to recent Cyber Essentials changes covers what it asks for.
  • Decide who can reset MFA, and how they confirm the request is genuine.

What steps should I take if I lose my device used for MFA?

If you lose your MFA device, contact your IT partner or admin straight away so they can revoke it and register a new one.

  1. Report it immediately. A lost phone with an approved authenticator is a risk until it's removed.
  2. Use a backup method if you set one up, such as a second device or backup codes.
  3. Re-register MFA on your replacement device once your admin has reset it.
  4. Change your password if the phone was stolen rather than lost.

Set up a backup method for every account now, while it's easy. It turns a lost phone from a lockout into a minor inconvenience.

Right. Let's talk.

MFA stops a stolen password getting in. Noble IT's cyber security service adds 24/7 identity threat detection, which flags when a login looks wrong even after MFA has been passed. You carry on with your day.

Not sure whether MFA is switched on across all your accounts? Unsure which ones Cyber Essentials would flag? A 360 Review will tell you. No obligations.

Book Your 360 Review

Statistics: Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology and the Home Office, published 30 April 2026.