What multi factor authentication actually stops, and how to turn it on this week
22 July 2026 · 7 min read · Optimum IT Solutions

Multi factor authentication is the cheapest meaningful security improvement most small businesses can make, and it is still not switched on everywhere. Here is what it does, what it does not, and how to get it done.
Multi factor authentication means proving who you are with more than one thing: something you know, such as a password, plus something you have, such as your phone or a security key. The point is simple. A password can be stolen without you noticing, and a second factor cannot be stolen from a database on the other side of the world.
It is the least glamorous item on any security list and comfortably the highest value one for a business of ordinary size. It is also the one that most often stalls, not because anyone disagrees with it, but because nobody wants to be the person who locks the finance director out on a Friday.
What it genuinely stops
Be clear about the threat it addresses, because that is what tells you how much to rely on it.
- Passwords leaked from somewhere else. People reuse passwords, and breaches at unrelated services are constant. Attackers take those lists and try them against business email. A second factor makes the correct password useless on its own.
- Guessable and sprayed passwords. Automated attempts against common passwords across many accounts at once are a permanent background activity on the internet, and they are aimed at whoever has not put a second step in the way.
- Ordinary phishing. When someone is tricked into typing their password into a fake page, the attacker ends up with a password and a locked door. The unexpected prompt on the user's phone is also the alarm that tells you the password needs changing.
- Old sessions and forgotten devices. Combined with sensible sign in policies, it limits how much value a stale or stolen device retains.
What it does not stop
Anyone who tells you multi factor authentication ends the problem is overselling it. There are known ways around it, and knowing them tells you which method to choose.
The first is prompt fatigue. If the attacker has the password, they can request approval over and over until a tired person taps approve to make it stop. This is why simple approve or deny prompts are weaker than they look, and why number matching, where you have to type a number shown on the screen you are signing in to, is worth turning on.
The second is interception in real time. A convincing fake login page can pass your details straight through to the real service as you type them, including the code, and capture the resulting session. Codes and push approvals do not defend against this. Passkeys and hardware security keys do, because they are tied to the genuine website address and simply will not work on a copy.
The third is the phone number itself. Codes by text can be diverted by someone persuading a mobile provider to move a number to a new card. Text codes are still far better than nothing, and they are the weakest of the common options.
And none of it helps if someone is talked into making a payment or sending a file. Multi factor authentication protects the login. It does not protect judgement.
Which method to choose
In rough order of strength, and all of them beat a password alone.
- Passkeys or a physical security key. Strongest available, resistant to the fake page problem, and increasingly pleasant to use. Worth it for administrators and anyone handling money.
- An authenticator app with number matching. A good default for most staff. Free, quick, and works without signal.
- An authenticator app with a six digit code. Fine, marginally more friction, no worse in practice.
- A code by text or a phone call. The weakest common option and still a large improvement on nothing. Use it for the person who genuinely cannot manage an app, not as the standard.
- Email to another address. Avoid where you can. If the email account is the thing being protected, this quickly becomes circular.
A workable order for this week
The reason rollouts fail is almost never technical. It is that everyone is asked to change at once, on a busy day, with no warning. Do it in this order instead.
- Start with the administrator accounts, today. These are the accounts that can change everything else, and they are the ones attackers want. Every account with administrative rights over your email, files or systems gets a second factor before anybody else does.
- Create and record a break glass route. Before enforcing anything widely, make sure there is a way back in if a phone is lost or broken: a second registered method for each person, saved recovery codes stored somewhere safe and offline, and a named person who can help. This single step prevents the disaster story everyone is afraid of.
- Cover money and email next. Finance, payroll, anyone who can move funds or change bank details, and the shared or generic mailboxes that nobody feels ownership of and everybody uses.
- Tell people the day before, in one short message. What is changing, what they will see, what to do, and who to contact. Two minutes of warning removes most of the support calls.
- Roll out to everyone else in groups, not all at once. A department at a time is easier to support and far less disruptive when something unexpected turns up.
- Then close the back doors. Older ways of connecting that cannot handle a second factor will happily bypass everything you have just done, so they need switching off. This is the step most often forgotten, and it is the one that decides whether the rollout was real.
The follow up that makes it stick
Once it is on, a few small things keep it useful. Check that every account really is covered rather than most of them, including service accounts and the odd mailbox nobody claims. Sort out what happens when someone gets a new phone, because that is the moment people quietly ask for the requirement to be removed and it never gets put back.
It is also worth adding sensible conditions on top, such as challenging sign ins from unfamiliar places or unmanaged devices. That is where multi factor authentication stops being a checkbox and starts being a working control, and it is a natural next step rather than something to do on day one.
None of this is difficult, and it is the sort of work that quietly never reaches the top of anyone's list. If it has been on yours for a while, we can do the rollout with you, or simply look at what you already have and tell you honestly whether the gaps that remain are worth worrying about.
Related
Want a straight answer on this?
Tell us the job that is costing you the most time. We will look at it and tell you honestly what, if anything, is worth doing about it. The first conversation is free.
Get a quote
