Security

Multi-Factor Authentication Should Be Enabled Wherever It Is Available

Passwords alone are no longer enough for important business accounts. Multi-factor authentication adds another layer of protection when credentials are lost, reused, or stolen.

A password proves that someone knows a secret. It does not prove that the person entering it is the account owner.

Multifactor authentication, commonly called MFA, requires another form of verification in addition to the password. That additional step can prevent a stolen password from providing immediate access to email, files, financial systems and administrative tools.

The main point

Trustline recommends enabling MFA wherever a business account supports it, beginning with the accounts that create the greatest risk.

Prioritize:

  • Administrator and owner accounts
  • Business email
  • Banking, payroll and financial platforms
  • Remote access and VPN accounts
  • Cloud storage and collaboration services
  • Password managers
  • Human resources and customer systems
  • Social media, website and domain accounts

CISA recommends phishing-resistant MFA when it is available. Passkeys and FIDO security keys can provide stronger protection against fraudulent sign-in pages than methods that require users to type or approve a reusable code.

Any MFA is generally better than relying on a password alone, but the available methods do not provide equal protection.

Choose the strongest practical method

Passkeys and hardware security keys

Passkeys and FIDO security keys are designed to verify the legitimate service before completing authentication. This makes them resistant to many common phishing techniques.

They are particularly appropriate for:

  • Administrators
  • Executives
  • Finance personnel
  • Domain and website owners
  • Accounts that control other accounts
  • Employees with access to sensitive information

Organizations should register an approved backup method so the loss of one device or key does not create an unnecessary lockout.

Authentication apps and number matching

Authentication apps may generate time-based codes or display sign-in approval requests.

When push notifications are used, number matching and clear sign-in details can help employees distinguish a legitimate request from an unexpected one.

Employees should approve a request only when they initiated the sign-in and the displayed details make sense.

Codes sent by text message or phone call

Codes delivered through text messages or phone calls may be the only MFA option on some platforms.

They remain useful when the alternative is no MFA, but they should not be treated as the strongest available method. Move sensitive accounts to a more phishing-resistant option when the platform supports one.

Create an organization-wide standard

Avoid enabling MFA one account at a time without a recovery or support plan.

A practical rollout should:

  1. Inventory business accounts.
  2. Identify the most sensitive and privileged accounts.
  3. Select the strongest practical method each platform supports.
  4. Require separate accounts for separate employees.
  5. Register approved backup or recovery methods.
  6. Store recovery codes securely and outside the user’s everyday device.
  7. Pilot the process before organization-wide enforcement.
  8. Explain how employees should report unexpected prompts or lost devices.

Review recovery information regularly. Remove old phone numbers, personal email addresses and former employees’ devices.

Treat unexpected prompts as warnings

Never approve an MFA request you did not initiate.

Repeated prompts may be an attempt to pressure someone into approving access. An unexpected code or approval request may also mean that someone already knows the password.

Employees should report unexpected prompts through the organization’s established security or IT process.

MFA does not replace other safeguards

MFA should be combined with:

  • Unique passwords
  • Secure password management
  • Device protection
  • Account and sign-in monitoring
  • Prompt employee offboarding
  • Limited administrator privileges
  • Reliable account-recovery procedures

MFA is an important control, not a complete security program.

What to avoid

Do not:

  • Share one account among multiple employees.
  • Approve unexpected sign-in requests.
  • Store recovery codes beside the password they protect.
  • Use personal accounts to own company services.
  • Leave former employees’ recovery methods attached to accounts.
  • Create permanent exceptions without regular review.

Shared accounts make it difficult to determine who approved a sign-in, changed a setting or still has access.

When to involve IT

Involve IT when:

  • Selecting an organization-wide MFA method
  • Enforcing MFA across multiple platforms
  • Protecting administrator access
  • Migrating to passkeys or security keys
  • Planning recovery and backup methods
  • Reviewing a service that does not support MFA

The brief inconvenience of an additional verification step is small compared with the disruption that can follow an account takeover.

Need help strengthening identity and access across your environment? Book a consultation.

Sources and further reading

On this page
More Insights

Related Posts

Explore more from The Infrastructure Journal.

Protection

A Backup Is Not Complete Until It Has Been Tested

Having backup software is not the same…
Strategy

When Your Business Needs a Technology Roadmap

A technology roadmap helps organizations plan upgrades,…
Cloud

What to Know Before Moving Business Systems to the Cloud

Cloud services can improve access and flexibility,…
Get Started

Start with a solid foundation

Build systems that support your business without constant fixes or workarounds.