What Is Multi-Factor Authentication (MFA)?
Multi-factor authentication requires users to verify their identity with two or more factors before accessing a system. It is the single most effective security control a business can implement, blocking over 99% of automated account compromise attacks.
Quick answer
Multi-factor authentication requires a user to prove their identity with two or more separate factors before they can sign in, not just a password. It is the single most effective control a UK business can switch on, blocking over 99% of automated account compromise attacks and now treated as a baseline by insurers and most compliance frameworks.
MFA Methods Explained
Different MFA methods offer different levels of security and usability.
Authenticator App
Apps like Microsoft Authenticator generate time-based codes. More secure than SMS and works offline. Recommended for most businesses.
SMS Codes
A one-time code sent via text message. Better than no MFA, but vulnerable to SIM-swapping attacks. Use as a fallback, not primary method.
Hardware Security Keys
Physical devices (FIDO2/WebAuthn) that plug into USB or use NFC. The most secure MFA method — phishing-resistant and tamper-proof.
Biometric
Fingerprint or facial recognition on devices. Convenient and secure when combined with device-based authentication.
MFA Methods Compared
Security and usability trade-offs across common MFA methods.
| Feature | SMSBasic | Auth AppRecommendedRecommended | Security KeyHighest security |
|---|---|---|---|
| Phishing resistant | Partial | ||
| Works offline | |||
| SIM-swap resistant | |||
| User convenience | High | High | Medium |
| Cost per user | Free | Free | £20–£50 |
| Meets |
If you run security for a 10–500 staff business, MFA is the cheapest, highest-impact thing on your list. This guide explains how it works, which methods to trust, where attackers still get through, and how AMVIA rolls it out. As a security-first managed cybersecurity partner, we configure MFA correctly across Microsoft 365 every week, so the advice here is what we actually do, not theory.
What are the three factors of authentication?
A "factor" is a category of evidence that you are who you claim to be. MFA combines at least two of the three so that stealing one is not enough. A password alone is one factor; add a phone prompt and you have two. The categories are independent on purpose.
- Something you know — a password, PIN or passphrase.
- Something you have — a phone running an authenticator app, or a hardware security key.
- Something you are — a fingerprint or face, read by the device.
The strength of MFA comes from forcing an attacker to defeat two unrelated categories at once. A phished password is useless without the physical key sitting in your pocket. The NCSC sets out the same model in its multi-factor authentication guidance for organisations.
Which MFA methods are most secure?
Not all MFA is equal. The method you choose decides whether you stop ordinary credential theft only, or also resist targeted phishing. Authenticator apps are the right default for most businesses; hardware keys protect your highest-risk accounts; SMS is a last resort because it can be intercepted.
Authenticator app
SMS codes
Hardware security keys
Biometric
MFA methods compared
| Property | SMS code | Authenticator app | Hardware security key |
|---|---|---|---|
| Phishing resistant | No | Partial | Yes |
| Works offline | No | Yes | Yes |
| SIM-swap resistant | No | Yes | Yes |
| User convenience | High | High | Medium |
| Cost per user | Free | Free | £20–£50 |
| Best used for | Fallback only | Most staff | Admin & finance accounts |
Can MFA be bypassed by attackers?
Yes, weak MFA can be bypassed, which is why method choice matters. Adversary-in-the-middle (AitM) phishing relays your login in real time, and MFA fatigue spams push prompts until a tired user taps approve. SMS is exposed to SIM swapping. Phishing-resistant methods close these gaps.
The defences that hold up are number-matching push notifications and hardware security keys, both of which break the AitM and fatigue playbooks. Pair them with strong email filtering, because phishing is still the front door. With 85% of businesses that experienced a breach identifying phishing as the vector (DSIT 2025), combining phishing-resistant MFA with managed email security gives you the strongest practical defence.
Which accounts should have MFA enabled first?
Start with the accounts that hand an attacker the keys to everything else. Administrator and global-admin accounts, email mailboxes, remote access such as VPN and RDP, finance and payment systems, and cloud service dashboards are the first targets in almost every intrusion. Protect these before worrying about low-privilege users.
- Global administrator and IT admin accounts
- Email and Microsoft 365 sign-ins
- Remote access: VPN, RDP and any web portal
- Finance, payroll and banking systems
- Cloud and SaaS admin consoles
With 22% of breaches involving compromised credentials (Verizon DBIR 2025), putting MFA on high-privilege accounts first removes your most exploitable attack surface fast. AMVIA enforces this through Microsoft Defender for Business and Conditional Access, so admin sign-ins simply cannot complete without a strong second factor.
Why do cyber insurers require MFA as a policy condition?
Insurers require MFA because credential-based attacks drive a large share of the most expensive claims, and MFA removes most of them. Policies now routinely specify that MFA must be live on email, VPN and cloud services as a precondition of cover. No MFA can mean a declined claim, not just a higher premium.
The economics are blunt. The average cost of the most disruptive breach is £3,550 (DSIT 2025), and insurers see materially fewer and less severe claims from MFA-enabled organisations. If you are arranging or renewing cover, read our UK cyber insurance guide so the MFA box is genuinely ticked before the assessor checks.
How should a UK business roll out MFA?
Roll out in priority order, not all at once. Enable phishing-resistant MFA on admin and email accounts first, switch on number-matching to kill fatigue attacks, then extend to all staff with an authenticator app. Hand hardware keys to your highest-risk users. Document exceptions and review them.
In Microsoft 365 this means enforcing MFA through Conditional Access rather than per-user toggles, disabling legacy authentication protocols that bypass MFA entirely, and registering a backup method so nobody gets locked out. This is exactly what our Microsoft 365 MFA setup service delivers, and it sits inside a wider zero trust model where identity, not the network perimeter, is the control point. One provider, security-first, Microsoft-certified — configured once, properly.
Frequently Asked Questions
Two-factor authentication (2FA) is MFA with exactly two factors — typically a password plus a phone code. MFA is the broader term covering two or more factors. In practice most business sign-ins use 2FA, and the terms are often used interchangeably. The security principle is identical: never rely on a password alone.
No. A password manager stores and generates strong, unique passwords, which protects the "something you know" factor. MFA adds a second, independent factor on top. They solve different problems and work best together: a manager stops password reuse, while MFA stops a stolen password from being enough to log in.
Barely, when configured well. With number-matching push notifications, signing in adds a single tap on a phone, and trusted devices can be remembered for a set period under Conditional Access. The friction is tiny next to the cost of a credential-based breach, and most users adapt within days of rollout.
SMS MFA is far better than none, but it is the weakest method because it is exposed to SIM-swapping and interception. The NCSC and Microsoft both recommend moving to an authenticator app or hardware key. Keep SMS only as a temporary fallback while you migrate staff to stronger methods.
Yes. Every Microsoft 365 business plan includes MFA, and security defaults enable it out of the box. For real control you should enforce it through Conditional Access and disable legacy authentication, which security defaults alone do not fully cover. AMVIA configures this properly as part of a Microsoft 365 hardening project.
For a typical 10–500 staff business, a phased Microsoft 365 rollout takes days to a few weeks, not months. Admin and email accounts are secured first, then staff are enrolled in waves with an authenticator app. The work is mostly policy design and user communication, not technical complexity.
Deploy MFA Across Your Business
AMVIA can deploy and manage MFA across your organisation — Microsoft 365, VPN, cloud apps, and more.
Protect your business → Get Cybersecurity Assessment