Multi-Factor Authentication for Business
Multi-factor authentication requires a second proof of identity beyond the password, so a stolen or guessed credential is not enough to get into an account on its own. It is the single highest-value security control available to an Australian SME, and it is the one most insurers and enterprise customers now ask about by name. 4iT designs, deploys and manages MFA across Microsoft 365, remote access, banking and line of business systems, including the parts most rollouts miss.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner
Insurer-ready
Evidence MFA is enforced across your business
End to end
Coverage, deployment, and recovery, not just the prompt

Key facts
- MFA stops the attack that most often reaches small businesses: a valid password, obtained from an unrelated breach or a phishing page, used to sign in.
- Not all MFA is equal. SMS codes are the weakest common form, app-based approval is better, and phishing-resistant methods such as passkeys and hardware keys are the strongest. Microsoft retires its own SMS and voice authentication in Entra ID on 1 February 2027.
- Coverage decides the outcome. MFA on email but not on remote access, or enabled for staff but not administrators, leaves the door it was meant to close still open.
- Conditional access is what makes MFA tolerable, applying stronger checks to risky sign-ins and staying quiet for routine ones on managed devices.
- MFA is a named requirement in most Australian cyber insurance applications and a control in the Essential Eight, so the evidence matters as much as the deployment.
- 4iT deploys MFA as a managed control, including the exceptions register, the recovery process, and the reporting an insurer or auditor will ask for.
Why is MFA the control worth doing first?
Because it defeats the most common route into a small business. The attack pattern is rarely sophisticated: credentials leak in someone else’s breach, or a convincing login page harvests them, and the same details are tried against Microsoft 365, banking and remote access. Without a second factor, a valid password is a working key. With one, the attacker has the password and still cannot get in.
It is also cheap relative to what it prevents. For most SMEs the licensing is already owned, and the work is configuration and change management rather than new spend. That combination, high impact and low cost, is why it belongs ahead of almost everything else on a security roadmap. For the plain-English explanation of how it works, see what is multi-factor authentication.
Where do MFA rollouts usually fall short?
Coverage gaps, almost every time. The common ones we find are administrator accounts left exempt because the exemption was convenient during setup and never removed, legacy authentication protocols still enabled so a sign-in can bypass the policy entirely, service and shared accounts with no second factor, and third-party systems outside the identity platform such as banking portals, accounting software and the payroll system.
The second failure is method. A deployment that satisfies the box-tick with SMS codes is materially weaker than one using app-based approval or a phishing-resistant method, because modern phishing kits relay a code in real time and SIM swapping is a genuine risk. The third is the recovery path: if a lost phone means an administrator disables MFA to get someone working, the control is optional in practice. Each of those is a specific thing to check rather than a matter of opinion.
What does 4iT do?
We start by establishing where you stand: which accounts have MFA, which methods are in use, whether legacy authentication is still open, and which systems sit outside the identity platform. That inventory is usually the first time a business sees the gaps written down. Then we design the policy set, using conditional access so the checks scale with risk instead of prompting people constantly, which is what drives the complaints that get a rollout reversed.
Deployment is staged, with administrators first, then staff by group, with the exceptions register documented and time-limited rather than permanent. We set up and test the recovery process before it is needed, register a second method per user so a lost phone is an inconvenience rather than a lockout, and close legacy authentication. After that it is ongoing: new starters are enrolled as part of onboarding, exceptions get reviewed rather than forgotten, and the reporting is kept in a form you can hand to an insurer.
MFA is one layer of identity control and works alongside identity and access management, password management and security awareness training.
How does MFA affect insurance and compliance?
It is now a standard question rather than a nice-to-have. Australian cyber insurance applications commonly ask whether MFA is enabled, on which systems, and for which accounts, and the answers affect both the premium and whether a claim is paid. Answering yes when coverage is partial is a risk in itself, because the detail gets examined after an incident rather than before.
MFA is also one of the Essential Eight mitigation strategies, so it carries weight in any assessment against that framework and in the security questionnaires larger customers send before signing. What is being asked for in practice is evidence: which accounts are covered, what methods are permitted, how exceptions are handled and who reviews them. We produce that as part of the service. See cyber insurance readiness and Essential Eight.
Frequently Asked Questions
It stops the overwhelming majority of attempts, but not all of them, and the gap is worth understanding. Phishing kits that sit between the user and the real sign-in page can capture a password and a one-time code and relay both within the code's short validity window, which defeats SMS and app-code methods. Push approval with number matching is harder to abuse, and phishing-resistant methods such as passkeys and hardware keys close it properly because there is no code to hand over. MFA remains the control to deploy first; the method you choose decides how much it really covers.
Badly configured, yes, and that is usually why rollouts get abandoned. Prompting people on every sign-in from a known device is unnecessary and it trains staff to approve requests without reading them, which creates its own risk. Conditional access is the answer: routine sign-ins from a managed device on a known network pass quietly, and the checks tighten for unfamiliar locations, unmanaged devices or higher-risk actions. Configured that way, most staff see a prompt occasionally rather than daily.
They should have a second registered method, which is the point of setting one up during enrolment rather than after the first lockout. With a backup method in place it is a self-service reset. Without one it becomes an administrator task, and the shortcut people reach for is disabling MFA on the account to get the person working, which quietly removes the control. We set the recovery process up and test it at deployment, because the moment it is needed is the worst time to discover it was never configured.
Only if you extend it there, and this is the gap most businesses have. MFA on your identity platform covers what authenticates against it, which typically means email, Teams, SharePoint and any application connected to single sign on. Banking portals, accounting and payroll systems, remote access, and industry-specific software often have their own separate MFA settings that have to be enabled individually. Part of the work is inventorying those systems and turning it on in each one, because an attacker will use whichever door was left open.
If you are not certain which of your accounts and systems are covered, that is the place to start. We can inventory it, close the gaps, configure conditional access so staff are not prompted needlessly, and give you the evidence your insurer wants. Request a callback and we will map out where you stand.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







