Multi-factor authentication phone and security key

Multi-factor authentication (MFA)—also called 2FA or two-step verification—adds a second proof beyond the password. Even if a password is stolen from a breach or phishing site, the attacker still needs your phone prompt, authenticator code, or hardware key.

Where MFA matters most for business

  • Email (Microsoft 365 / Google Workspace)
  • VPN and remote desktop gateways
  • Banking, payroll, and accounting portals
  • Cloud admin consoles and domain registrar accounts
  • Password manager and backup vaults

Better and worse MFA methods

  • Stronger: authenticator app codes, hardware security keys (FIDO2), phishing-resistant passkeys where supported
  • Acceptable: push prompts—if staff know not to approve surprise prompts
  • Weaker but better than nothing: SMS codes (SIM-swap risk exists; still enable if it is the only option)

Staff coaching that prevents MFA fatigue attacks

  • Never approve a login prompt you did not just initiate
  • If prompts keep arriving, change the password and call IT—someone may have the password already
  • Prefer app-based MFA over SMS for admin accounts

Microsoft explains MFA options for work accounts at Microsoft Authenticator help. Google’s overview: Google authentication tools.

Learn more on our Two Factor Authentication page.


Need help putting this into practice for your business? Contact SabatAge or call (845) 475-8468. We support Hudson Valley and Orange County businesses with practical security and managed IT.

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe

SabatAge blog—IT news, tips, and stories for Hudson Valley businesses