What Is Multi-Factor Authentication (MFA)?

Multi-factor authentication requires users to verify their identity with two or more factors before accessing a system. It is the single most effective security control a business can implement, blocking over 99% of automated account compromise attacks.

Quick answer

Multi-factor authentication requires a user to prove their identity with two or more separate factors before they can sign in, not just a password. It is the single most effective control a UK business can switch on, blocking over 99% of automated account compromise attacks and now treated as a baseline by insurers and most compliance frameworks.

MFA Methods Explained

Different MFA methods offer different levels of security and usability.

Authenticator App

Apps like Microsoft Authenticator generate time-based codes. More secure than SMS and works offline. Recommended for most businesses.

SMS Codes

A one-time code sent via text message. Better than no MFA, but vulnerable to SIM-swapping attacks. Use as a fallback, not primary method.

Hardware Security Keys

Physical devices (FIDO2/WebAuthn) that plug into USB or use NFC. The most secure MFA method — phishing-resistant and tamper-proof.

Biometric

Fingerprint or facial recognition on devices. Convenient and secure when combined with device-based authentication.

MFA Methods Compared

Security and usability trade-offs across common MFA methods.

Feature
SMSBasic
Auth AppRecommendedRecommended
Security KeyHighest security
Phishing resistantPartial
Works offline
SIM-swap resistant
User convenienceHighHighMedium
Cost per userFreeFree£20–£50
Meets

If you run security for a 10–500 staff business, MFA is the cheapest, highest-impact thing on your list. This guide explains how it works, which methods to trust, where attackers still get through, and how AMVIA rolls it out. As a security-first managed cybersecurity partner, we configure MFA correctly across Microsoft 365 every week, so the advice here is what we actually do, not theory.

What are the three factors of authentication?

A "factor" is a category of evidence that you are who you claim to be. MFA combines at least two of the three so that stealing one is not enough. A password alone is one factor; add a phone prompt and you have two. The categories are independent on purpose.

  • Something you know — a password, PIN or passphrase.
  • Something you have — a phone running an authenticator app, or a hardware security key.
  • Something you are — a fingerprint or face, read by the device.

The strength of MFA comes from forcing an attacker to defeat two unrelated categories at once. A phished password is useless without the physical key sitting in your pocket. The NCSC sets out the same model in its multi-factor authentication guidance for organisations.

Which MFA methods are most secure?

Not all MFA is equal. The method you choose decides whether you stop ordinary credential theft only, or also resist targeted phishing. Authenticator apps are the right default for most businesses; hardware keys protect your highest-risk accounts; SMS is a last resort because it can be intercepted.

Authenticator app

SMS codes

Hardware security keys

Biometric

MFA methods compared

PropertySMS codeAuthenticator appHardware security key
Phishing resistantNoPartialYes
Works offlineNoYesYes
SIM-swap resistantNoYesYes
User convenienceHighHighMedium
Cost per userFreeFree£20–£50
Best used forFallback onlyMost staffAdmin & finance accounts

Can MFA be bypassed by attackers?

Yes, weak MFA can be bypassed, which is why method choice matters. Adversary-in-the-middle (AitM) phishing relays your login in real time, and MFA fatigue spams push prompts until a tired user taps approve. SMS is exposed to SIM swapping. Phishing-resistant methods close these gaps.

The defences that hold up are number-matching push notifications and hardware security keys, both of which break the AitM and fatigue playbooks. Pair them with strong email filtering, because phishing is still the front door. With 85% of businesses that experienced a breach identifying phishing as the vector (DSIT 2025), combining phishing-resistant MFA with managed email security gives you the strongest practical defence.

Which accounts should have MFA enabled first?

Start with the accounts that hand an attacker the keys to everything else. Administrator and global-admin accounts, email mailboxes, remote access such as VPN and RDP, finance and payment systems, and cloud service dashboards are the first targets in almost every intrusion. Protect these before worrying about low-privilege users.

  • Global administrator and IT admin accounts
  • Email and Microsoft 365 sign-ins
  • Remote access: VPN, RDP and any web portal
  • Finance, payroll and banking systems
  • Cloud and SaaS admin consoles

With 22% of breaches involving compromised credentials (Verizon DBIR 2025), putting MFA on high-privilege accounts first removes your most exploitable attack surface fast. AMVIA enforces this through Microsoft Defender for Business and Conditional Access, so admin sign-ins simply cannot complete without a strong second factor.

Why do cyber insurers require MFA as a policy condition?

Insurers require MFA because credential-based attacks drive a large share of the most expensive claims, and MFA removes most of them. Policies now routinely specify that MFA must be live on email, VPN and cloud services as a precondition of cover. No MFA can mean a declined claim, not just a higher premium.

The economics are blunt. The average cost of the most disruptive breach is £3,550 (DSIT 2025), and insurers see materially fewer and less severe claims from MFA-enabled organisations. If you are arranging or renewing cover, read our UK cyber insurance guide so the MFA box is genuinely ticked before the assessor checks.

How should a UK business roll out MFA?

Roll out in priority order, not all at once. Enable phishing-resistant MFA on admin and email accounts first, switch on number-matching to kill fatigue attacks, then extend to all staff with an authenticator app. Hand hardware keys to your highest-risk users. Document exceptions and review them.

In Microsoft 365 this means enforcing MFA through Conditional Access rather than per-user toggles, disabling legacy authentication protocols that bypass MFA entirely, and registering a backup method so nobody gets locked out. This is exactly what our Microsoft 365 MFA setup service delivers, and it sits inside a wider zero trust model where identity, not the network perimeter, is the control point. One provider, security-first, Microsoft-certified — configured once, properly.

Frequently Asked Questions

Deploy MFA Across Your Business

AMVIA can deploy and manage MFA across your organisation — Microsoft 365, VPN, cloud apps, and more.