StormDotCom Logo
Back to Cyber Security & Compliance

Cyber Security & Compliance

Multi-Factor Authentication: The Single Best Step to Protect Your Business

Passwords on their own are no longer enough. For most Cape Town businesses, switching on multi-factor authentication is the fastest, cheapest and most effective security upgrade available. Here's what it is and how to do it.

Published: August 20267 min read

Where to switch on MFA first

Microsoft 365 / email

Essential

Enforce MFA across the whole tenant via security defaults or admin policies.

Admin accounts

Essential

Use the strongest methods; Microsoft already requires MFA on admin portals.

Banking & accounting

Essential

Switch on MFA everywhere you hold or move money.

Client data apps

High

Protect any system holding personal or confidential client information (POPIA).

Cloud storage & social

High

Enable MFA on OneDrive, cloud apps and business social accounts.

Personal accounts

Recommended

Start with email and bank; expand to the rest over time.

A password is a single key. If someone steals or guesses it, they can walk straight into your email, your bank details and your client data. Multi-factor authentication (MFA) fixes this simply: it adds a second step that proves the person logging in is genuinely you. For most businesses it is the single most effective security measure you can switch on — and it is easier than you think.

What is multi-factor authentication?

MFA requires a user to prove their identity using at least two different factors before access is granted. The three classic factors are:

Something you know

A password, PIN, or answer to a security question.

Something you have

A smartphone authenticator app, a code sent by text, or a hardware key.

Something you are

A fingerprint, face scan, or other biometric.

The point is that a fraudster who has your password still cannot get in, because they do not also have your phone or your fingerprint. Even if your password is leaked in a data breach, that alone is not enough to access the account.

Why it matters so much

The evidence for MFA is remarkably strong. Microsoft's own security research has found that more than 99.9% of compromised accounts had no multi-factor authentication enabled, and that enabling MFA can block over 99.9% of automated account-compromise attacks. Put simply, the vast majority of account break-ins that hurt businesses happen because MFA simply was not switched on.

For South African businesses under POPIA, this matters double. A stolen password that exposes client personal information is not just a business headache — it can be a compliance incident. MFA dramatically lowers the odds of that happening in the first place.

The common ways to add a second factor

Authenticator app

A free app on a phone (such as Microsoft Authenticator or Google Authenticator) that generates a one-time code or approves a login tap.

SMS or email code

A one-time code sent to a phone or inbox. Simple, though less secure than an app.

Push notification approval

A prompt on your phone asking "Is it you?" — you tap approve or deny.

Hardware security key

A small physical key (like a USB or NFC device) you plug in or tap. Very strong, used for high-value accounts.

Biometrics

Fingerprint or face recognition on the device you are using.

Corporate security policies

Everything above is often managed centrally so all staff are protected consistently.

Where to turn it on

The highest-risk targets come first. For almost every business that means your Microsoft 365 and email accounts, your admin accounts, and anything that holds financial or client data. Microsoft now requires multi-factor authentication for Azure and other admin portals as part of its own security defaults — a sign of how standard MFA has become.

If you use Microsoft 365, MFA is part of the built-in security defaults and can be enforced across your tenant so every user must use it. Beyond that, switch it on for your bank, your accounting software, your social media, and any app that holds data you would not want lost.

Do it well — a few practical cautions

  • Prefer an authenticator app over SMS codes — text messages can be intercepted and redirected.
  • Set up a recovery method (a second device or backup code) so you are never locked out if you lose your phone.
  • Be aware of “MFA fatigue” — never approve a login prompt you did not trigger; report it instead.
  • For administrators and finance staff, consider the strongest methods such as a hardware key.

The bottom line

Multi-factor authentication is not a cure-all, and motivated attackers still try to get around it. But it is the difference between a password you can handle being exposed and an attacker actually getting in. For the cost and effort involved, nothing else moves the needle as much. If you do one security upgrade this year, make it this one.

Key Takeaways

  • MFA adds a second step so a stolen password alone is not enough to get in
  • Microsoft research: over 99.9% of compromised accounts had no MFA enabled
  • Start with email, Microsoft 365, banks and anything holding client data
  • Prefer an authenticator app over SMS codes, and set up a recovery method
  • Never approve an MFA prompt you didn't trigger — that's an attack signal

Not Sure If MFA Is Set Up Across Your Business?

StormDotCom can review your Microsoft 365 setup and switch on multi-factor authentication for every user — so the accounts most at risk are protected properly. Book a free assessment and we'll show you exactly where you stand.

Book a Free IT Assessment