Skip to main content
Illustration of a masked hacker reaching for a business login screen while a person enters their password, illustrating the risk multi-factor authentication protects against.

All businesses should adopt MFA. Now.

| Pat Midzio |

Updated July 28, 2026

Last year, one of our larger clients came within a single login attempt of a serious breach. An employee’s password had leaked somewhere else online — the kind of leak that happens quietly, on some other site with weaker protections than yours, with no way to know it happened until it’s used against you. An attacker had that password and tried it against the client’s VPN. It worked. What stopped the attacker cold was the second step: without the matching approval on the employee’s phone, the login attempt just sat there, denied. Multi-factor authentication was the only thing standing between a valid, correct password and a foothold on that entire network.

That kind of attempt isn’t rare anymore — we’ve seen a real, sustained increase over the past year in brute-force attacks aimed specifically at business VPNs, and we’re far from the only ones. In June 2026, CISA confirmed that more than 86,000 internet-facing FortiGate VPN devices worldwide had been compromised by attackers running exactly this kind of campaign: scanning for exposed login portals, then hammering them with lists of leaked and default credentials. CISA’s own recommendation in response was to enable phishing-resistant MFA on every external gateway and administrative interface — the same layer that stopped the attempt against our client.

Why This Is Happening Right Now

Attackers don’t need to guess your password anymore. They can buy it. Billions of credentials from past breaches at other companies are circulating for sale, and automated tools spend all day, every day, trying them against business logins everywhere: email, VPNs, banking portals, anything internet-facing. A strong password doesn’t change much here — strength only helps against someone guessing it, and a leaked password was never guessed in the first place. What actually stops an attacker from using it is having something else standing in the way. That’s what MFA provides. A password alone is a single lock. MFA means the attacker also needs something they don’t have: your phone, your key, or you.

What MFA Actually Means

Multi-factor authentication requires at least two of the following before letting someone in:

  • Something you know — a password or PIN.
  • Something you have — a phone with an authenticator app, a physical security key, or a one-time code.
  • Something you are — a fingerprint or face scan.

Single-factor is a password alone. Two-factor (2FA) adds one more of the above — commonly a password plus a code. MFA is the broader term for using two or more factors, and it’s what we mean whenever we talk about “turning on MFA” for a client.

Does MFA Actually Work?

Yes — dramatically. In a peer-reviewed study of its own Azure Active Directory accounts, Microsoft found that MFA reduced the risk of account compromise by 99.22% across the board, and by 98.6% even for accounts whose passwords had already leaked. Over 99.99% of MFA-enabled accounts in the study stayed secure for the full period. That’s consistent with what stopped the attack on our client’s VPN: the password being compromised didn’t matter once MFA was in the way.

MFA isn’t flawless, though, and it’s worth knowing where it can still be beaten. The 2025 Verizon Data Breach Investigations Report found “prompt bombing” — repeatedly sending MFA approval requests until a tired or distracted employee taps “approve” by mistake — showed up in 14% of incidents involving MFA, and more technical bypasses like SIM-swapping or adversary-in-the-middle attacks accounted for roughly 4% of breaches. Those numbers are exactly why we’re moving clients toward phishing-resistant MFA — passkeys and physical security keys — rather than stopping at app-based codes. We’ll get into that next.

What We Actually Deploy for Clients

For Microsoft 365 environments — the large majority of our clients — we standardize on Microsoft Authenticator. For platforms outside the Microsoft ecosystem, we help clients set up an authenticator app of their choosing — usually Google Authenticator or Authy. We also layer in Conditional Access, which makes MFA smarter rather than more annoying — it can require that extra verification step only when a login looks unusual, like an unfamiliar device or location, instead of prompting for it every single time.

Looking ahead, we’re actively pushing clients toward passkeys and physical keys like YubiKeys instead of app-based codes. This isn’t just a preference — it’s catching up to where the industry is headed. Microsoft has announced it’s retiring SMS- and voice-based MFA entirely by February 2027, with passkeys becoming the default for new sign-ins starting September 2026. Some of our clients still have staff using the SMS text-code option, and that path is going away regardless of what we’d prefer — so now’s the time to move off it, not after the deadline forces the issue. Adoption is already well underway elsewhere: the FIDO Alliance reported in 2026 that roughly 5 billion passkeys are now in active use worldwide, and 68% of organizations have deployed or are actively deploying passkeys for employee sign-in. Passkeys and YubiKeys sidestep the prompt-bombing and SIM-swap risks entirely — there’s no code to intercept and no prompt to accidentally approve.

Rolling It Out Without a Revolt

How you roll MFA out depends on your situation, but for most of our clients it’s everyone, all at once, rather than a slow department-by-department phase-in. Waiting just leaves a gap open longer than it needs to be.

The most common pushback we hear has nothing to do with security — it’s employees who don’t want to install a work-related app on their personal phone. It’s a fair concern, and the honest answer usually resolves it: Microsoft Authenticator doesn’t give your employer access to anything else on your phone. It’s a single-purpose app that generates approval prompts, full stop. Once that’s explained clearly, most of the resistance goes away. A smaller number of staff members opt for SMS codes instead of the app — understandable, but worth steering people away from now, since that option is being phased out industry-wide over the next several months anyway.

The Insurance Angle

Every cyber insurance application we’ve seen in the past couple of years asks about MFA directly, and we’ve heard from at least one carrier that they simply won’t write a policy for a business that doesn’t have it enabled. That’s not an outlier position — Corvus by Travelers states plainly that it requires MFA on remote access, email access, and administrative access as a condition of the coverage it underwrites. We don’t have visibility into exactly how the presence or absence of MFA moves your premium — that’s a conversation for your broker — but in our experience, once clients understand it’s often the difference between qualifying for a policy at all, rolling it out stops being a hard conversation.

The Bottom Line

A leaked password is no longer a rare event — it’s closer to a matter of time. MFA is the layer that turns a leaked or guessed password from “game over” into “attempt denied,” which is exactly what it did for our client’s VPN. It’s inexpensive, it’s fast to roll out, and — increasingly — it’s not optional if you want to qualify for cyber insurance in the first place. If your business isn’t running MFA everywhere it can be, today is a good day to start.

Book a Free Consultation

Not sure where your business stands — which systems still allow single-factor logins, whether Conditional Access rules like geographic login restrictions make sense for you, or whether it’s time to move off SMS codes toward passkeys? Let’s talk. Book a time on my calendar and we’ll walk through where the gaps are and what a realistic rollout would look like, as part of a broader cybersecurity program built for your business.

Frequently Asked Questions

Two-factor authentication (2FA) is a subset of MFA that uses exactly two factors — typically a password plus a one-time code. MFA is the broader term for using two or more factors from different categories (something you know, something you have, something you are). In practice, most business MFA setups are technically 2FA — a password plus an app-based approval — and the terms get used interchangeably.

It’s better than nothing, but it’s the weakest form of MFA still in common use, and it’s being phased out. Microsoft is retiring SMS and voice MFA entirely by February 2027, with passkeys becoming the default starting September 2026. If your team still relies on text-message codes, it’s worth moving to an authenticator app or passkey now rather than waiting for the cutoff.

No. Microsoft Authenticator is a single-purpose app that generates approval prompts and codes — it doesn’t give your employer visibility into your other apps, messages, photos, or location. This is the most common concern we hear from employees, and it’s the first thing worth clarifying before a rollout.

Increasingly, yes. Every cyber insurance application we’ve seen recently asks about MFA directly, and Corvus by Travelers states outright that MFA on remote access, email, and administrative access is a requirement of the coverage it underwrites. Some carriers have told us they won’t write a policy at all without it. Check with your specific broker or carrier, but treat “do you have MFA” as a question you need a confident yes to.

A passkey replaces your password entirely with something tied to your device — a fingerprint, face scan, or security key — that can’t be phished or guessed the way a password or text code can. The FIDO Alliance reports roughly 5 billion passkeys now in active use worldwide, and it’s the direction the whole industry, including Microsoft, is moving. We’re actively pushing clients toward passkeys and physical keys like YubiKeys, and it’s worth asking your IT provider about a plan to get there if you haven’t already.

Deny it, and report it right away — don’t just dismiss it and move on. That prompt means someone has your password and is trying to get past the second step, a tactic known as “prompt bombing” that shows up in a meaningful share of MFA-related breaches. An unexpected prompt is a strong signal your password needs to be changed immediately, even though the login itself was blocked.