MFA Is Not Optional: What Small Businesses Keep Getting Wrong
Multi-factor authentication has been the top recommended security control for years. Every security framework includes it. Cyber insurance carriers require it. The advice to turn it on has been repeated so many times it has almost become background noise. And yet small businesses keep getting it wrong. Not by skipping it entirely, but by setting it up halfway, covering the wrong accounts, or treating it as a checkbox rather than a control. Here is where the gaps usually are.
What MFA actually does
A password is one factor: something you know. MFA adds a second: something you have (a code from an app, a push notification, a hardware key) or something you are (biometrics). The point is that a stolen or guessed password alone is no longer enough to get in.
This matters because passwords get stolen constantly. Phishing, credential stuffing, data breaches at other services your staff use — your employees' passwords are almost certainly available somewhere online right now. MFA is what makes a stolen password useless.
Where small businesses get it wrong
The most common mistake is partial coverage. A business turns on MFA for email but leaves the accounting software, the file storage, the remote access tool, and the HR platform unprotected. An attacker who cannot get into email will try the next door. If that one is open, the damage is the same.
- Email only — Microsoft 365 or Google Workspace is covered, but nothing else is. Every other business application is one stolen password away from a breach.
- SMS codes instead of an authenticator app — text message codes can be intercepted via SIM-swapping attacks. An authenticator app like Microsoft Authenticator or Google Authenticator is significantly more secure.
- MFA turned on but not enforced — many setups allow MFA to be bypassed or skipped. If a user can opt out or dismiss the prompt, some will. Enforcement needs to be required, not optional.
- No coverage for admin accounts — standard user accounts get MFA but IT admin accounts, which have access to everything, do not. Admin accounts are the highest-value target.
- Legacy protocols left open — older email protocols like IMAP and POP3 bypass modern authentication entirely. If these are not blocked, MFA on the account does not fully protect it.
What MFA cannot protect against
MFA is not a complete security solution. It is one layer of a larger defense. It does not protect against an attacker who has already gained access through other means, against insider threats, or against malware already running on a device.
There is also a growing category of attack called MFA fatigue, where an attacker triggers repeated push notification requests until a tired or distracted employee taps approve just to make them stop. Training your staff to recognize and report unexpected MFA prompts matters as much as turning MFA on.
How to actually set it up right
- Cover every business application that has a login, not just email. Cloud storage, accounting software, payroll platforms, remote access tools — all of it.
- Use an authenticator app, not SMS codes. Microsoft Authenticator, Google Authenticator, or Duo are all solid choices.
- Make MFA mandatory. Remove the ability for staff to skip or bypass it.
- Block legacy authentication protocols in Microsoft 365 or your email platform. Your IT provider can do this in under an hour.
- Apply stricter controls to admin and privileged accounts. Consider hardware security keys for those accounts.
- Train staff to treat unexpected MFA prompts as a red flag, not an inconvenience to dismiss.
MFA done right stops the majority of credential-based attacks. MFA done halfway gives you a false sense of coverage while leaving real gaps open. If you are not certain your setup is enforced across every application, with the right method, and with legacy protocols blocked, it is worth having someone check. We do that as part of a free security review for small businesses in the Chicago area.
Questions about your IT setup?
We work with small businesses and accounting firms across the Chicago area. Start with a free CPA Cybersecurity & IT Risk Review and we will tell you honestly what we see.