The Password Guide: 7 Steps To Creating Unhackable Passwords
What NIST says makes a strong password in 2026: 15+ characters, no forced symbols or 90-day resets, one password per account, a password manager and...
4 min read
Dylan Borden
:
Aug 10, 2023, 11:00:00 AM
Multi-factor authentication (MFA) means a stolen password isn't enough to get into your accounts. Microsoft says MFA can block more than 99.2% of account compromise attacks, and it's included at no extra cost in every Microsoft 365 business plan. The catch: it only works if it's turned on for everyone, legacy sign-ins are blocked, and your team knows not to approve a prompt they didn't start.
Here's the real question: not "should we use MFA?" but "is it actually on for every account, and is it the kind attackers can't talk their way past?" We regularly meet businesses that believe they have MFA, then find the owner's account, a shared mailbox or an old admin login that never got it.
Key takeaways

Most business account takeovers start with a password someone else already has. It was phished by a fake Microsoft login page, reused from a site that got breached, or guessed in a "password spray" that tries common passwords across thousands of accounts. With MFA on, each of those attacks hits a second wall: the attacker has the password but not your phone, your fingerprint or your security key.
Microsoft's own numbers make the case. It says MFA "can block more than 99.2% of account compromise attacks," and that "more than 99.9% of compromised accounts don't have MFA." That's why Microsoft now requires MFA to sign in to Azure and its admin portals.
What most businesses don't realize is what a single compromised mailbox costs. Once an attacker is in, they read your invoices, learn how your team writes, and send a perfectly timed "updated wire instructions" email from a real account. MFA is the cheapest way to stop that before it starts.
For clients who need more control, like MFA on VPNs, remote desktop or non-Microsoft apps, we deploy Duo as a premium option.
An attacker who already has your password tries to sign in over and over, sending prompt after prompt to your phone, hoping you'll tap "Approve" just to make it stop. Sometimes they follow up with a call pretending to be IT. Number matching defeats the spam version because you can't approve without the number on the attacker's screen. The rule for your team is simple: if you didn't just try to sign in, deny it and tell IT. An unexpected prompt means someone has your password, so it's time to change it.
For most Microsoft 365 clients, we start with Microsoft's security defaults, which require every user to register for MFA, always require it for admins and block legacy authentication, at no extra cost. Then we:
MFA is part of the "Secured" foundation of our cybersecurity framework, alongside a business-grade firewall, endpoint protection, email security and offsite backup. Pair it with unique passwords from a password manager, covered in our password guide. Not sure where you stand? Take our cybersecurity tier quiz.
MFA requires a second proof of identity after your password, such as approving a sign-in in an authenticator app, using your fingerprint or face, or plugging in a security key. A stolen password alone isn't enough to get in.
No. Every Microsoft 365 business plan can use MFA through Microsoft's security defaults at no extra cost. Business Premium adds Conditional Access for finer control, like requiring stronger methods for admins or blocking sign-ins from certain countries.
It's far better than no MFA, but it's the weakest option. Codes can be intercepted or talked out of people. An authenticator app with number matching is stronger, and passkeys or Windows Hello are phishing-resistant.
Deny it and tell IT right away. An unexpected prompt means someone has that person's password, so it should be changed immediately and recent sign-ins reviewed.
IT verifies who they are through a set process, removes the old device and helps them register a new one. Having a backup method set up in advance, and a reset process that can't be talked around, keeps a lost phone from becoming a lockout or a security gap.
Sometimes, through MFA fatigue attacks, fake login pages that relay codes, or older sign-in methods that skip MFA. Number matching, blocking legacy authentication and moving key accounts to phishing-resistant methods like passkeys close most of those gaps.
We get it. Nobody wants a Monday morning of locked-out employees. We roll out MFA in the right order, close the gaps attackers look for and train your team on what to do with an unexpected prompt, with local engineers who answer the phone when someone gets stuck. Talk to our team about your current setup.
What NIST says makes a strong password in 2026: 15+ characters, no forced symbols or 90-day resets, one password per account, a password manager and...
What DNS filtering does, how DNSFilter and Cisco Umbrella compare, and why we recommend DNSFilter for most 20 to 75 person businesses.
Are password managers worth it for a business? The honest pros and cons, how to handle the risks, and what to look for in a business password manager.