If there is one security action that delivers more protection per minute of effort than almost anything else, it is enabling multi-factor authentication on your business accounts. Research from Microsoft has found that MFA blocks over 99% of account compromise attacks, meaning an attacker who has your password still cannot get in. It is one of the most impactful things you can do, and for most businesses, it can be set up in a single afternoon without any technical expertise.
Here is how to do it, platform by platform.
What is MFA and why does it matter?
Multi-factor authentication adds a second layer of verification beyond your password. Even if an attacker obtains your login credentials through a phishing email, a data breach, or credential stuffing, they cannot access your account without also having access to your second factor, which is typically a code generated by an app on your phone or a biometric confirmation.
SMS-based codes are better than nothing, but authenticator apps are more secure because SMS can be intercepted through SIM-swapping attacks, whereas authenticator apps generate codes locally on your device without touching the mobile network.
Step 1: Prioritise your most critical accounts
You do not need to enable MFA everywhere simultaneously. Start with the accounts whose compromise would be most immediately damaging:
- Business email (Microsoft 365, Google Workspace)
- Banking and financial platforms
- Cloud storage and file sharing (OneDrive, SharePoint, Google Drive)
- Remote access tools and VPNs
- Any platform that holds customer data or payment information
Step 2: Choose your authenticator app
Download one of the following on each employee’s work smartphone:
- Microsoft Authenticator: integrates seamlessly with Microsoft 365 and Azure
- Google Authenticator: works across a wide range of platforms
- Authy: adds cloud backup for your codes, useful if you change devices frequently
Step 3: Enable MFA on Microsoft 365
- Sign in to the Microsoft 365 Admin Centre at admin.microsoft.com
- Navigate to Users, then Active Users
- Select Multi-Factor Authentication from the top menu
- Select the users you want to enable it for, or select all
- Click Enable, then confirm
- Each user will be prompted to set up MFA the next time they sign in
For stronger protection, enable Conditional Access policies through Azure Active Directory, which allows you to require MFA only under certain conditions (such as logging in from outside the office) or require it for all logins globally.
Step 4: Enable MFA on Google Workspace
- Sign in to admin.google.com as an administrator
- Go to Security, then 2-Step Verification
- Select Allow users to turn on 2-Step Verification
- To enforce it across the organisation, select On โ for all users and uncheck the option to allow users to turn it off
- Users will be prompted to enrol on their next login
Step 5: Enable MFA on banking and finance platforms
Most South African business banking platforms now support some form of MFA, though the implementation varies by provider. Log into your business banking portal and navigate to Security Settings or Account Settings, where you should find an option to enable two-step verification or a transaction authentication process. If you are unsure, contact your bank directly, because this is a configuration worth prioritising.
Step 6: Brief your team
The most common point of resistance to MFA rollout is staff frustration with the added step at login. A brief team communication that explains why MFA is being implemented, what they will need to do, and who to contact if they have trouble enrolls people in the process rather than making them feel it is being done to them. Frame it as protecting their accounts as much as the businesses, because it genuinely is.
What to do after MFA Is enabled
- Review your MFA logs monthly to check for failed authentication attempts, which can indicate targeted attacks
- Establish a process for employees who lose access to their authenticator app, such as when they change phones, so they are not locked out of critical accounts
- Consider MFA fatigue attacks, where attackers send repeated approval requests hoping someone accidentally approves one, and brief staff not to approve requests they did not initiate
Need help rolling out MFA or evaluating your broader identity security posture? Siyaxhuma can assess your current setup and implement the right controls for your business. Get in touch today.