Multifactor authentication

Multifactor Authentication for Business: What MFA Does and Which Methods Are Strongest

MFA adds another identity check beyond the password. It's one of the most effective, lowest-cost protections available for email, remote access and administrator accounts, and it's required outright under CMMC for defense contractors.

Executive summary

Any MFA Is Better Than None, but Not All MFA Is Equal

Text messages and approval prompts stop many password-only attacks, but they can be targeted through SIM swapping, push fatigue and adversary-in-the-middle phishing. Passkeys, FIDO2 security keys and other phishing-resistant methods provide stronger protection because they're bound to the legitimate service rather than a code that can be relayed or guessed.

Start with high-risk accounts

Protect administrators, executives, finance, email and remote access first.

Close enrollment gaps

Confirm every user is enrolled and remove weak exceptions.

Plan the upgrade

Move critical users toward passkeys or FIDO-based authentication.

Setup steps

How to Require MFA in Microsoft 365 and Google Workspace

Most businesses run one of these two platforms for email and core productivity tools. Here's how to require MFA for every user in each.

Microsoft 365 / Entra ID

  1. Sign in to the Microsoft Entra admin center as a Global Administrator or Security Administrator.
  2. Go to Protection, then Conditional Access.
  3. Create a new policy, assign it to all users or a targeted group, and set the target resources to All cloud apps.
  4. Under Grant, select Require multifactor authentication.
  5. Set the policy to On and save. Test it against a pilot group before rolling out organization-wide.
  6. Under Identity, then Authentication methods, disable weaker legacy methods like SMS where possible and prioritize the Microsoft Authenticator app with number matching, or a FIDO2 security key for privileged accounts.

Google Workspace

  1. Sign in to the Google Admin console.
  2. Go to Security, then Authentication, then 2-Step Verification.
  3. Select the organizational unit to enforce, then turn on Allow users to turn on 2-Step Verification, followed by Enforcement.
  4. Choose an enforcement date to give users time to enroll before it's required.
  5. Under 2-Step Verification methods, prioritize security keys and Google prompt over SMS for stronger protection.

For other systems, remote access tools, banking portals, payroll software, and industry-specific applications, check the account or admin security settings for an MFA or two-step verification option, and enable it the same way: for every user, not just administrators.

Compliance

MFA Is a Hard Requirement Under CMMC

MFA is required for military contractors subject to the Cybersecurity Maturity Model Certification. It's a hard requirement at CMMC Level 2 and above, rooted in NIST SP 800-171 practice 3.5.3, which mandates MFA for both privileged and non-privileged accounts accessing systems that store, process or transmit Controlled Unclassified Information. Local access, network access and remote access all fall under this requirement.

Assessors look for documented implementation, not just the presence of an MFA tool. A written policy that reflects what's actually configured matters as much as the technology itself. If your business still relies on single-factor authentication anywhere in scope, closing that gap before a formal CMMC assessment is one of the more disruptive items to leave until late.

MFA hierarchy

From Basic MFA to Phishing-Resistant Authentication

SMS and voice codes

Widely available and better than password-only access, but dependent on the phone network and vulnerable to number takeover and social engineering.

Authenticator app codes

Time-based codes don't depend on cellular delivery, but a user can still be tricked into entering the code on a fraudulent site.

Push notifications with number matching

Convenient, and number matching reduces the risk of an employee accidentally approving a prompt they didn't request.

Passkeys and FIDO2 security keys

Designed to resist phishing because the credential only works with the correct website or application. See our guide to passkeys for business for rollout guidance.

Free policy toolkit

Put Better Authentication Rules in Writing

Free Editable Download

Business Password and Authentication Policy Toolkit

Download the editable Microsoft Word toolkit and customize it for your systems, policies, MFA, passkeys, shared accounts, vendor access and offboarding.

Download the Word Toolkit
Frequently asked questions

Questions Business Leaders Ask

What does MFA mean?

Multifactor authentication requires two or more different types of evidence, such as a password and a registered device or biometric.

Is a text-message code considered MFA?

Yes. It's better than password-only authentication, although app-based and phishing-resistant methods generally provide stronger protection.

Can hackers bypass MFA?

Some MFA can be bypassed through phishing, push fatigue, account recovery abuse or stolen session tokens. Phishing-resistant methods reduce these risks.

Does CMMC require MFA?

Yes. CMMC Level 2 and above requires MFA for both privileged and non-privileged accounts accessing systems that handle Controlled Unclassified Information, rooted in NIST SP 800-171 practice 3.5.3.

Related resources

Continue Building a Stronger Password Program

STACK Cybersecurity

Protect Accounts Before Stolen Credentials Become a Business Crisis

STACK Cybersecurity helps businesses roll out MFA across email, remote access and administrative accounts, then move toward passkeys and other phishing-resistant methods over time.

Talk With STACK Cybersecurity