Call NowFree Quote
Cybersecurity

Multi-Factor Authentication for Perth Businesses - Setup Guide

If there is one security control that will prevent more breaches than any other, it is multi-factor authentication. Over 90% of successful account takeover attacks - where a criminal gains access to your email, Microsoft 365, or banking - involve stolen or guessed passwords. MFA stops almost all of them.

What Is Multi-Factor Authentication?

Multi-factor authentication (MFA), also called two-factor authentication (2FA), requires a user to verify their identity using two or more factors when logging in:

  • Something you know - your password
  • Something you have - a code from an authenticator app, an SMS, or a hardware token
  • Something you are - fingerprint or face recognition

Even if an attacker obtains your password - through phishing, data breach, or brute force - they cannot log in without also having your second factor. For most accounts, that means having physical access to your phone.

Why Perth Businesses Are Targeted

Account takeover attacks are not targeted - they are automated. Attackers run credential stuffing tools that attempt millions of username/password combinations stolen from previous data breaches against business email systems. If your staff reuse passwords from other accounts (and statistically, most people do), those accounts are at risk.

The consequences of a compromised business email account can include:

  • Business email compromise (BEC) scams - fraudulent invoice payment requests sent to your clients or suppliers
  • Access to sensitive client data stored in email or Microsoft 365
  • Lateral movement - using the compromised account to attack other systems
  • Ransomware deployment - access to email often leads to broader network access

MFA for Microsoft 365 - The Most Important One

For most Perth businesses, Microsoft 365 is the priority. It contains your email, Teams conversations, SharePoint files, and OneDrive data - often the most sensitive information in the organisation.

Microsoft 365 MFA setup:

  • Go to the Microsoft 365 Admin Centre → Users → Active Users → Multi-factor authentication
  • Enable MFA for all users - do not leave any accounts exempt, including admin accounts (especially admin accounts)
  • Set the default method to the Microsoft Authenticator app, not SMS. Authenticator app codes are more secure than SMS, which can be intercepted via SIM-swapping
  • Configure Conditional Access policies to enforce MFA every time, or at minimum for sign-ins from new devices or outside Australia

Microsoft 365 Business Premium includes Conditional Access. If you are on Business Basic or Business Standard, you can use Security Defaults, which enforces MFA for all users - enable it immediately if you haven't already.

Authenticator Apps vs SMS Codes

SMS is better than nothing, but it is the weakest MFA method. SIM-swapping attacks (where a criminal convinces your telco to transfer your number to their SIM) can defeat SMS-based MFA. For business accounts, use an authenticator app:

  • Microsoft Authenticator - best for Microsoft 365 environments, supports number matching and push notifications
  • Google Authenticator - widely compatible, simple time-based codes
  • Duo - enterprise-grade, good for businesses with complex environments

Other Systems That Need MFA

Microsoft 365 is the priority, but MFA should be enabled on every system that supports it:

  • Banking and financial platforms - most Australian business banks now offer or require MFA
  • Accounting software - Xero, MYOB, QuickBooks all support MFA
  • Password managers - your password manager is the keys to the kingdom; it must have MFA
  • VPN and remote access - anyone connecting remotely to your systems must use MFA
  • Cloud storage - Dropbox, OneDrive, Google Drive accounts
  • Practice management software - particularly relevant for healthcare, legal, and accounting practices

Rolling Out MFA to Your Team

The biggest obstacle to MFA adoption is not technical - it is staff resistance. Common objections and responses:

"It takes too long"

Modern MFA with Conditional Access only prompts for the second factor when logging in from a new device or location. On familiar devices, it is transparent. The extra 3 seconds is worth not having your business email compromised.

"I don't have a smartphone"

Hardware tokens (FIDO2 keys like YubiKey) are an alternative for users without smartphones. They plug into a USB port and require a button press to authenticate.

"What if I lose my phone?"

Set up backup methods: a secondary phone number, recovery codes stored securely, or an IT administrator who can reset MFA for users. Never leave users locked out permanently.

MFA Is Not Enough on Its Own

MFA is critical, but it is one layer of a proper security posture. Businesses should also have endpoint protection, email filtering, regular backups, and a security awareness training program. Think of MFA as closing the most common entry point - it dramatically reduces your risk, but it is not a complete security solution.

Frequently Asked Questions

Is SMS-based MFA good enough, or should businesses use an authenticator app?

SMS is better than no MFA at all, but it's the weakest method available, since SIM-swapping attacks can intercept text-based codes. An authenticator app, like Microsoft Authenticator, is generally recommended as the default for business accounts instead.

Does MFA need to be enabled on every single account, or just email?

Email and Microsoft 365 should be the priority since they hold the most sensitive data for most businesses, but MFA is worth enabling anywhere it's supported, banking, accounting software, password managers, and VPN access all included. Leaving any one of these exempt just shifts the risk rather than removing it.

What if a staff member loses the phone their authenticator app is on?

This is a common concern but a solvable one, setting up backup methods like a secondary phone number, securely stored recovery codes, or having an IT administrator able to reset MFA for a user avoids anyone being locked out permanently. It's worth having this process defined before it's actually needed.

Is MFA enough on its own to protect a business from a cyberattack?

No, MFA is one of the most effective single controls available, but it's still one layer of a broader security posture. Endpoint protection, email filtering, regular tested backups, and staff awareness training all still matter alongside it.

We configure and enforce MFA across Microsoft 365 and all key business systems for Perth businesses - as part of managed IT or as a standalone engagement.

Cybersecurity Services →

Is MFA enabled on all your business accounts?

Call 0433 087 091 - we'll audit your current MFA coverage and get it configured correctly across your Microsoft 365 environment and key business systems.

Book a Security Review

For related reading, see our guides to Email Security for Perth Businesses and Secure File Sharing for Perth Businesses.

Share this article