Multifactor Authentication for Business: What MFA Does and Which Methods Are Strongest
MFA adds another identity check beyond the password. It's one of the most effective, lowest-cost protections available for email, remote access and administrator accounts, and it's required outright under CMMC for defense contractors.
Any MFA Is Better Than None, but Not All MFA Is Equal
Text messages and approval prompts stop many password-only attacks, but they can be targeted through SIM swapping, push fatigue and adversary-in-the-middle phishing. Passkeys, FIDO2 security keys and other phishing-resistant methods provide stronger protection because they're bound to the legitimate service rather than a code that can be relayed or guessed.
Start with high-risk accounts
Protect administrators, executives, finance, email and remote access first.
Close enrollment gaps
Confirm every user is enrolled and remove weak exceptions.
Plan the upgrade
Move critical users toward passkeys or FIDO-based authentication.
How to Require MFA in Microsoft 365 and Google Workspace
Most businesses run one of these two platforms for email and core productivity tools. Here's how to require MFA for every user in each.
Microsoft 365 / Entra ID
- Sign in to the Microsoft Entra admin center as a Global Administrator or Security Administrator.
- Go to Protection, then Conditional Access.
- Create a new policy, assign it to all users or a targeted group, and set the target resources to All cloud apps.
- Under Grant, select Require multifactor authentication.
- Set the policy to On and save. Test it against a pilot group before rolling out organization-wide.
- Under Identity, then Authentication methods, disable weaker legacy methods like SMS where possible and prioritize the Microsoft Authenticator app with number matching, or a FIDO2 security key for privileged accounts.
Google Workspace
- Sign in to the Google Admin console.
- Go to Security, then Authentication, then 2-Step Verification.
- Select the organizational unit to enforce, then turn on Allow users to turn on 2-Step Verification, followed by Enforcement.
- Choose an enforcement date to give users time to enroll before it's required.
- Under 2-Step Verification methods, prioritize security keys and Google prompt over SMS for stronger protection.
For other systems, remote access tools, banking portals, payroll software, and industry-specific applications, check the account or admin security settings for an MFA or two-step verification option, and enable it the same way: for every user, not just administrators.
MFA Is a Hard Requirement Under CMMC
MFA is required for military contractors subject to the Cybersecurity Maturity Model Certification. It's a hard requirement at CMMC Level 2 and above, rooted in NIST SP 800-171 practice 3.5.3, which mandates MFA for both privileged and non-privileged accounts accessing systems that store, process or transmit Controlled Unclassified Information. Local access, network access and remote access all fall under this requirement.
Assessors look for documented implementation, not just the presence of an MFA tool. A written policy that reflects what's actually configured matters as much as the technology itself. If your business still relies on single-factor authentication anywhere in scope, closing that gap before a formal CMMC assessment is one of the more disruptive items to leave until late.
From Basic MFA to Phishing-Resistant Authentication
SMS and voice codes
Widely available and better than password-only access, but dependent on the phone network and vulnerable to number takeover and social engineering.
Authenticator app codes
Time-based codes don't depend on cellular delivery, but a user can still be tricked into entering the code on a fraudulent site.
Push notifications with number matching
Convenient, and number matching reduces the risk of an employee accidentally approving a prompt they didn't request.
Passkeys and FIDO2 security keys
Designed to resist phishing because the credential only works with the correct website or application. See our guide to passkeys for business for rollout guidance.
Put Better Authentication Rules in Writing
Free Editable Download
Business Password and Authentication Policy Toolkit
Download the editable Microsoft Word toolkit and customize it for your systems, policies, MFA, passkeys, shared accounts, vendor access and offboarding.
Download the Word ToolkitQuestions Business Leaders Ask
What does MFA mean?
Multifactor authentication requires two or more different types of evidence, such as a password and a registered device or biometric.
Is a text-message code considered MFA?
Yes. It's better than password-only authentication, although app-based and phishing-resistant methods generally provide stronger protection.
Can hackers bypass MFA?
Some MFA can be bypassed through phishing, push fatigue, account recovery abuse or stolen session tokens. Phishing-resistant methods reduce these risks.
Does CMMC require MFA?
Yes. CMMC Level 2 and above requires MFA for both privileged and non-privileged accounts accessing systems that handle Controlled Unclassified Information, rooted in NIST SP 800-171 practice 3.5.3.
Continue Building a Stronger Password Program
Protect Accounts Before Stolen Credentials Become a Business Crisis
STACK Cybersecurity helps businesses roll out MFA across email, remote access and administrative accounts, then move toward passkeys and other phishing-resistant methods over time.
Talk With STACK Cybersecurity