Passwords get stolen, guessed and reused — it’s a fact of life. Billions of leaked credentials circulate online, and attackers know most people reuse the same handful of passwords across work and personal accounts. Multi-factor authentication (MFA) is the simple control that makes a stolen password far less useful, because signing in also requires something only the real user has — a code, an app approval or a security key.
It’s not a new idea, and it’s not glamorous. But year after year it remains the single highest-impact, lowest-cost security step a business can take. Microsoft has reported that MFA blocks the overwhelming majority of automated account-compromise attacks — in the region of 99% of them. Very few security measures deliver that kind of return for so little effort.
Why a password alone isn’t enough
A password is a single secret, and single secrets leak. They get phished, captured by malware, exposed in third-party breaches, or simply guessed when they’re weak or reused. Once an attacker has a valid password, an account protected by that password alone is wide open — and from one compromised mailbox they can read sensitive mail, reset other passwords, invoice your customers fraudulently or move sideways into the rest of your systems.
MFA breaks that chain. Even with the correct password, an attacker is stopped at the second step, because they don’t have the user’s phone or key. The stolen password becomes close to worthless on its own.
Where MFA matters most
The goal is coverage. A door left unlocked anywhere undermines the locks everywhere else, so MFA belongs on every account that matters — and especially on:
- Email — the master key to most other accounts, because so many reset links land there.
- Microsoft 365 / Google Workspace — your documents, identities and admin controls.
- Finance and banking — the obvious target for fraud.
- Remote access and VPNs — the front door for hybrid and home workers.
- Administrator accounts — the keys to the kingdom, where a compromise does the most damage.
Not all MFA is equal
The most familiar form is a code by text message, and while any MFA is far better than none, SMS codes are the weakest option — they can be intercepted or defeated by SIM-swapping. Authenticator apps (with push approvals or one-time codes) are stronger and free, and hardware security keys are stronger still for your highest-risk accounts. There’s also “MFA fatigue”, where attackers spam approval prompts hoping a user taps accept out of habit — which is why number-matching and a little staff awareness matter alongside the technology.
Make it secure and usable
Here’s the catch: security that gets in the way is security people work around. If MFA prompts users twenty times a day, they’ll look for shortcuts — and shortcuts create gaps. The trick is configuring it sensibly: trusting known devices and locations, applying conditional rules so prompts appear when risk is genuinely higher, and choosing methods staff find quick and painless. Done well, MFA is something your team barely notices day to day, yet it quietly shuts down the most common route attackers take into a business.
How Lumen MSP can help
We roll out MFA for clients across Microsoft 365 and the other systems that matter, configured to be secure but not painful — strong protection that doesn’t slow people down. We pair it with the wider essentials (sensible access control, monitoring and staff awareness) so your defences hold together rather than relying on any single control.
If you’re not certain MFA is switched on everywhere it should be, that’s worth fixing today. See our cyber security services or call 0333 335 0170 and we’ll review it with you.
Further reading: NCSC and Microsoft guidance on multi-factor authentication.
