Getting Started

MFA Setup Guide: Protect Your Small Business Today

HB
HMC Bot
7 min read

The Single Most Effective Security Control You Can Implement

If you only do one thing to improve your business's cyber security, make it this: enable multi-factor authentication (MFA) on every account that supports it.

Microsoft's security research has consistently shown that MFA blocks over 99.2% of account compromise attacks. The Australian Signals Directorate (ASD) lists MFA as one of the Essential Eight mitigation strategies. And virtually every cyber insurance provider in Australia now requires MFA as a condition of coverage.

Despite this, the ACSC's Small Business Survey found that only around 40% of Australian small businesses have MFA enabled on all their critical accounts. This guide will help you close that gap.

What Is MFA and Why Does It Matter?

Multi-factor authentication (also called two-factor authentication or 2FA) requires you to verify your identity using two or more different factors when logging in:

  • Something you know: your password
  • Something you have: your phone, a hardware key, or an authenticator app
  • Something you are: fingerprint, face recognition

Even if an attacker steals your password through phishing, a data breach, or brute force, they still cannot access your account without the second factor. It is that simple -- and that effective.

Types of MFA: Pros and Cons

Not all MFA methods are equally secure. Here is a comparison to help you choose the right approach for your business:

MFA Method Security Level Pros Cons
SMS codes Basic Easy to set up; no extra app needed; works on any phone Vulnerable to SIM swapping and interception; relies on mobile coverage
Authenticator apps (Microsoft Authenticator, Google Authenticator, Authy) Good More secure than SMS; works offline; free; push notifications for easy approval Requires smartphone; can be lost if phone is replaced without backup
Hardware security keys (YubiKey, Titan Key) Excellent Phishing-resistant; cannot be intercepted remotely; extremely reliable Cost ($40-$100 per key); can be physically lost; not supported by all services
Passkeys (device biometrics) Excellent Phishing-resistant; seamless user experience; no codes to enter Still being adopted; not yet supported by all business tools
Our recommendation: For most Australian SMEs, authenticator apps offer the best balance of security, cost, and usability. Use hardware keys for high-value accounts like domain admin and banking. SMS is better than nothing, but move away from it as your primary MFA method as soon as practical.

MFA is such a foundational control that it sits at the heart of the IDIA framework's Identity pillar. IDIA organises every cybersecurity control into four pillars -- Identity, Data, Infrastructure, and Assurance -- and the Identity pillar treats MFA as a non-negotiable starting point for access control and authentication. Without it, every other security control you implement is built on a weaker foundation, because a single compromised password can bypass them all.

Step-by-Step: Enabling MFA on Common Business Tools

Microsoft 365

Microsoft 365 is the most widely used business platform in Australia. Enabling MFA is straightforward:

  1. Sign in to the Microsoft 365 admin centre (admin.microsoft.com) as a global admin.
  2. Navigate to Users > Active users.
  3. Click Multi-factor authentication in the top menu bar.
  4. Select all users (or specific users) and click Enable.
  5. Each user will be prompted to set up MFA on their next login -- they will need to install the Microsoft Authenticator app on their phone.

Better option: If you have Microsoft 365 Business Premium or above, use Security Defaults or Conditional Access policies to enforce MFA organisation-wide. Security Defaults are free and enable MFA for all users automatically.

Google Workspace

  1. Sign in to the Google Admin console (admin.google.com).
  2. Go to Security > Authentication > 2-Step Verification.
  3. Check Allow users to turn on 2-Step Verification.
  4. To enforce it, select Enforcement > Turn on enforcement and choose a start date.
  5. Users will be guided through setup on their next login -- they can use Google Authenticator, phone prompts, or a hardware key.

Banking and Financial Platforms

Most Australian banks (CommBank, NAB, Westpac, ANZ) have their own authentication methods built into their mobile apps. Ensure:

  • Push notification approval is enabled (rather than SMS codes where possible)
  • Biometric login (fingerprint or face) is enabled on the banking app
  • Transaction verification is turned on for transfers above a set threshold
  • Authorised signatories each have their own login -- never share banking credentials

Accounting Software (Xero, MYOB, QuickBooks)

Your accounting software holds some of your most sensitive business data. All major platforms support MFA:

  • Xero: My Xero > Account Settings > Security > Enable MFA. Supports authenticator apps.
  • MYOB: My Account > Security Settings > Two-factor authentication. Supports authenticator apps and SMS.
  • QuickBooks Online: Account and Settings > Security > Sign-in & security > Two-step verification. Supports SMS and authenticator apps.

Other Critical Accounts

Do not overlook these commonly-targeted accounts:

  • Domain registrar (e.g., VentraIP, Crazy Domains, GoDaddy) -- if someone compromises this, they can redirect your website and email
  • Website hosting and CMS (WordPress admin, Shopify, Squarespace)
  • Social media accounts (Facebook Business, Instagram, LinkedIn)
  • Cloud storage (Dropbox, OneDrive, Google Drive)
  • Password manager (this should have the strongest MFA of all)

Tips for Rolling Out MFA to Your Team

The biggest challenge with MFA is not technical -- it is getting your team on board. Here is how to make the rollout smooth:

  1. Communicate the "why" first. Explain that MFA protects the business and their own personal accounts. Share the stat: 99.2% of account attacks are blocked by MFA.
  2. Provide clear instructions. Send step-by-step guides with screenshots. Better yet, walk through setup with staff in person or via a short video call.
  3. Set a deadline. Give staff a reasonable window (e.g., two weeks) to set up MFA, then enforce it. Do not leave it optional indefinitely.
  4. Plan for backup access. Ensure staff set up backup MFA methods (e.g., backup codes, a second phone number) in case they lose their primary device.
  5. Support the less tech-savvy. Some staff will need hands-on help. Budget 15-30 minutes per person for setup support. It is time well spent.
  6. Lead by example. Enable MFA on your own accounts first. If the boss does it, the team follows.

Common Concerns (and How to Address Them)

  • "It's too inconvenient." Modern MFA is fast -- a single tap on a push notification or a glance at your phone. Most services only prompt for MFA when you log in from a new device or location, not every single time.
  • "What if I lose my phone?" Set up backup codes during initial configuration. Store them securely (printed in a safe, or in a password manager). Some authenticator apps (like Authy and Microsoft Authenticator) support cloud backup.
  • "We're too small to be targeted." The ACSC reports that 43% of cyber attacks target small businesses. Attackers use automated tools that scan for easy targets -- a business without MFA is exactly that.
  • "Our MSP handles security." Your MSP can enable and manage MFA for you, but you need to make the decision to require it. Ask your MSP about MFA enforcement today if it is not already in place.

MFA as Part of a Broader Security Strategy

MFA is powerful, but it is not a silver bullet. It should be part of a layered security approach that includes strong passwords, regular updates, staff training, and a solid cyber security checklist. Be aware that advanced phishing attacks in 2026 can attempt to bypass MFA through real-time token interception -- which is why phishing-resistant methods like hardware keys and passkeys are the gold standard for high-value accounts.

Check Your MFA Coverage Today

How confident are you that MFA is enabled across all your critical business accounts? Platforms like How's My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical domains -- including MFA coverage -- in under 10 minutes. See exactly where you have gaps and close them before an attacker finds them first.

Share

How secure is your business?

Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.

Try CYBER9 Free