Security Guide

How to set up multi-factor authentication on every account

MFA blocks 99.9% of automated attacks. Here’s how to turn it on for every account that matters.

Why it matters
The single highest-ROI security action you can take
99.9%
of automated credential attacks blocked by MFA (Microsoft)
80%
of data breaches involve compromised credentials
$4.88M
average cost of a data breach in 2024 (IBM)

A strong password is not enough. Passwords get reused, phished, leaked in data breaches, and guessed. Multi-factor authentication (MFA) adds a second verification step — usually a time-based code from an app or a push notification — that makes stolen passwords useless to attackers.

Enabling MFA takes about 3 minutes per account. There is no single security action with a better return on that time investment.

Authenticator apps
Which app should you use?
Best for M365

Microsoft Authenticator

The right choice for any Microsoft 365 environment. Supports passwordless sign-in, push notifications, and number matching to prevent MFA fatigue attacks.

Universal

Google Authenticator

Simple and reliable for personal accounts and Google Workspace. Now supports cloud backup to Google account. No push notifications — generates 6-digit codes.

Best for recovery

Authy

Best choice if account recovery is a priority. Multi-device sync, encrypted cloud backup, and desktop app. Good for individuals managing many accounts.

Step-by-step setup
Turn on MFA for the accounts that matter most
☁️

Microsoft 365

1

Sign in at aka.ms/mfasetup or go to your Microsoft Account → Security → Advanced Security Options.

2

Select “Add a new way to sign in or verify.” Choose Authenticator app.

3

Install Microsoft Authenticator on your phone. Scan the QR code shown on screen.

4

Approve the test notification on your phone to complete setup.

5

Admins: Enforce MFA for all users in Microsoft Entra (Azure AD) → Security → Conditional Access, or enable Security Defaults.

📧

Google / Gmail

1

Go to myaccount.google.com → Security → 2-Step Verification.

2

Click “Get started” and enter your password if prompted.

3

Choose Authenticator app from the list (preferred over SMS). Scan the QR code.

4

Enter the 6-digit code from the app to confirm, then click Turn On.

🍎

Apple ID

1

On iPhone/iPad: Settings → [Your Name] → Sign-In & Security → Two-Factor Authentication.

2

On Mac: Apple menu → System Settings → [Your Name] → Sign-In & Security → Two-Factor Authentication.

3

Follow the prompts to add a trusted phone number. Apple sends verification codes to trusted devices automatically.

💼

LinkedIn

1

Click your profile photo → Settings & Privacy → Sign in & security → Two-step verification.

2

Select “Authenticator app” and click Set up.

3

Scan the QR code with your authenticator app, enter the 6-digit code to verify, and save.

Authenticator app vs SMS
Why the app is safer than a text message

SMS-based MFA is far better than nothing — but it has known weaknesses. If a site offers an authenticator app option, use it.

Common questions
FAQ
What if I lose my phone and can’t get into my accounts?

This is the most common concern — and it’s manageable. Most platforms provide backup codes when you set up MFA. Print them and store them in a safe location. Authy’s multi-device sync also helps. For business accounts, your IT admin can reset MFA. The risk of being locked out is far lower than the risk of account compromise without MFA.

Does MFA slow me down every time I log in?

For most accounts, no. Once a device is marked as trusted, you only see MFA challenges when signing in from a new device or browser, or after an extended period. Microsoft Authenticator push notifications take about 3 seconds. The mild inconvenience is worth the protection.

We have 50 employees. How do we enforce MFA across the whole company?

In Microsoft 365, enable Security Defaults (free) or Conditional Access policies (requires Azure AD P1, included in M365 Business Premium). In Google Workspace, go to Admin console → Security → 2-Step Verification → Enforcement. Both approaches let you enforce MFA for all users within a few clicks, with a grace period for users to enroll.

Want us to enforce MFA across your whole organization?

We can configure Conditional Access or Google Workspace enforcement policies and make sure no account slips through.

Get a Free IT Assessment →