How to Set Up MFA for Your Small Business (Microsoft 365 Guide)

If you run a small business on Microsoft 365, you have probably heard that you should turn on multi-factor authentication. Maybe your insurance carrier asked about it on a cyber liability questionnaire. Maybe a bigger client’s IT department asked. Or maybe you watched a business down the street lose an email account to a phishing scam and decided it was time.

You have probably also hesitated, because the fear is real. Flip the wrong switch and suddenly the copier will not scan, the bookkeeper is locked out, and your least technical employee is calling you from the parking lot.

This guide walks you through requiring MFA in Microsoft 365 the calm way: which setting to turn on, how to get your team through it without drama, what to do about the one old app that breaks, and the handful of mistakes that cause most of the pain.

Why MFA is worth the hassle

MFA (multi-factor authentication) means a password alone is not enough to sign in. You also need something you physically have, usually your phone. That matters because passwords fail constantly. People reuse them across sites, they get caught by fake login pages that look exactly like the real Microsoft screen, and they show up in breach dumps for sale online.

With MFA on, a criminal who has your password still hits a wall. Microsoft’s own security team has said for years that requiring a second factor stops the overwhelming majority of automated account takeover attempts. Email account compromise is one of the most common ways small businesses get breached, and MFA is the control that does the most to prevent exactly that. A few extra seconds at sign-in is one of the best trades in all of security.

Two ways to require it: Security defaults vs Conditional Access

Microsoft 365 gives you two paths, and picking the right one up front saves a lot of confusion later.

Security defaults is the simple switch. It is free on every Microsoft 365 plan, it requires MFA for everyone in the company, and it blocks the old sign-in methods that skip MFA entirely. You turn it on in the Microsoft Entra admin center (entra.microsoft.com): open Identity, then Overview, then the Properties tab, then click Manage security defaults. There are no exceptions and almost nothing to configure, which is exactly why it works so well for most companies with a couple dozen people or fewer.

Conditional Access is the rule builder. It requires Entra ID P1, which is included in Microsoft 365 Business Premium. Instead of one switch, you write policies: require MFA for everyone, skip the extra prompt on the office network, block sign-ins from countries you never do business in, require MFA every single time for admin accounts. You get more control and more responsibility, because a badly written policy can lock everyone out, including you.

Plain rule of thumb: on Business Basic or Standard with no unusual needs, turn on Security defaults today. On Business Premium, or if you already know you need exceptions, use Conditional Access and start from Microsoft’s built-in policy templates rather than a blank page.

Get Microsoft Authenticator on every phone first

Before you flip anything on, have everyone install the Microsoft Authenticator app. It is free on iPhone and Android, and it is much stronger than text-message codes because it uses number matching: the sign-in screen shows a two-digit number, and you confirm it in the app, which makes it hard for an attacker to trick someone into approving a login they did not start.

Once MFA is required, each person sees a “More information required” prompt at their next sign-in and gets walked through scanning a QR code with the app. Even better, anyone can register early at aka.ms/mfasetup before enforcement begins. Get everyone registered ahead of the deadline and the big scary MFA day becomes a non-event.

Roll it out without a mutiny

Most MFA horror stories are rollout stories, not technology stories. The fix is communication and sequencing, not a different product.

  • Announce it a week ahead with one honest sentence about why: “A stolen password should not be enough to read our email or our customers’ information.”
  • Pilot with two or three people first, including yourself, so you hit the surprises before the whole team does.
  • Walk your less technical folks through setup live, in person or on a quick call. It takes about ten minutes per person and buys enormous goodwill.
  • Enforce on a Tuesday or Wednesday morning, never at 4pm on a Friday.
  • Have everyone register a second method (a backup phone number or a second device) the same day they set up the app.
  • Expect a few days of “it’s asking me for a number” questions, then near silence. The prompts become routine within a week.

What to do about the one app that breaks

Almost every rollout has one: a copier that scans to email, an old accounting add-on that syncs a mailbox, an ancient email program on somebody’s home computer. These usually rely on basic authentication, meaning username and password only, so requiring MFA (or turning on Security defaults, which blocks basic authentication outright) stops them cold.

Resist the urge to turn MFA off for the whole company because a copier complained. Start by checking whether the vendor has a firmware or software update that supports modern authentication, because many do. For scan-to-email specifically, Microsoft supports device-friendly options like direct send that do not need a user password at all. If nothing else works, scope the workaround to one dedicated account with a long random password and the narrowest permissions possible, then put a reminder in your calendar to replace that device or app. App passwords still exist in some configurations, but Microsoft is retiring them and Security defaults does not allow them, so treat them as a last resort, not a plan.

Common mistakes that undo the whole effort

The setup itself is the easy part. These are the gaps we see most often when reviewing small business tenants.

  • Treating SMS codes as the permanent answer. Text messages are better than nothing, but they can be phished and stolen through SIM swapping. Use them as a backup and make the Authenticator app the primary method.
  • Registering only one method. A dropped phone should be an errand, not a lockout. Every user needs a backup method, and you should test the recovery process once before you actually need it.
  • Ignoring shared mailboxes and service accounts. Nobody should sign in to a shared mailbox directly, so block sign-in on those accounts entirely. Any service account that must remain needs a long random password and the tightest restrictions you can apply.
  • Skipping the break-glass account. Keep one emergency admin account with a very long password stored offline (a printed copy in a safe is fine), excluded from Conditional Access policies, so a bad policy or an outage can never lock you out of your own tenant.

Key Takeaways

  • MFA is the single most effective control against email account takeover, and requiring it is free on every Microsoft 365 plan.
  • Use Security defaults if you want one simple switch, and Conditional Access (included with Business Premium) if you need exceptions and finer control.
  • Get Microsoft Authenticator on every phone and register backup methods before you enforce anything.
  • Never disable MFA company-wide for one stubborn app; scope the exception to a single locked-down account instead.
  • Text-message codes are a backup, not a destination.

If you want your team confident with MFA and phishing basics before you flip the switch, book our free 30-minute remote security awareness session at /free-training/, delivered over video call in English, Spanish, or Portuguese, with no obligation.


LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.

Scroll to Top