top of page
it support sheffield

Cybersecurity

Is multi-factor authentication enough to protect a business?

By Steve Harper  |  8 min read  | Last updated:

12 August 2026 at 08:13:42

Is MFA Enough?

TL;DR

Multi-factor authentication significantly reduces the risk of account compromise, but it is not enough on its own.


Attackers may still gain access through fraudulent approval requests, convincing phishing pages, stolen browser sessions, compromised devices or weak account-recovery processes. Businesses should combine MFA with conditional access, managed devices, security monitoring, employee training and phishing-resistant authentication for sensitive accounts.


Key Takeaways

  • Every business should use MFA wherever it is available.

  • MFA can still be bypassed or misused.

  • Some authentication methods provide stronger protection than others.

  • Unexpected MFA requests should always be treated as suspicious.

  • Administrator and high-risk accounts need particularly strong authentication.

  • MFA should be combined with device, identity and email security.

  • Recovery and fallback methods must be protected too.

Is MFA enabled - or properly protecting your business?


IT Desk can review your Microsoft 365 identity security, MFA coverage, Conditional Access and device controls. We can identify unprotected accounts, improve authentication methods and help your employees recognise suspicious sign-in requests.



Can hackers bypass MFA?

Yes, although MFA makes account compromise considerably more difficult.


MFA requires the user to provide more than one form of authentication. This means that stealing a password may not be enough for an attacker to access the account.


However, attackers increasingly use techniques designed to trick users into completing the additional authentication step or to steal an authenticated session after MFA has already been completed.


The possibility of bypass does not mean MFA is ineffective. It means businesses should treat it as one important layer of security rather than a complete solution.


How can MFA be bypassed?

Common attack methods include:


MFA fatigue

An attacker who has obtained a password may repeatedly trigger authentication notifications on the employee’s phone.


The attacker hopes the employee will approve one of the requests to stop the notifications or because they assume it relates to a legitimate sign-in.


This is sometimes called MFA fatigue, push bombing or prompt bombing.


Adversary-in-the-middle phishing

A convincing phishing site may sit between the employee and the legitimate login service.


The employee enters their password and completes MFA, believing they are signing in normally. The attacker captures the authenticated session information and uses it to access the account.


This is why a standard authentication-app approval is not considered completely phishing-resistant.


Session-token theft

After a user signs in, the service may issue a token that allows the session to remain authenticated.


If malware or another attack steals this token, the criminal may be able to replay it without completing the original MFA process again. Microsoft specifically advises organisations to prepare for token-theft attacks even when MFA is deployed.


Social engineering

An attacker may contact the employee, service desk or mobile provider and attempt to manipulate account recovery or authentication settings.


For example, they may try to:

  • Register a new authentication method

  • Reset the existing MFA configuration

  • Move a mobile number to another SIM

  • Obtain a temporary access credential

  • Persuade the employee to disclose a verification code

  • Convince IT support that they are the legitimate user


Unprotected accounts or systems

MFA cannot protect an account if it is not actually required.


Businesses sometimes enable MFA for most users while leaving gaps such as:

  • Old or forgotten accounts

  • Service accounts

  • Legacy applications

  • Emergency-access accounts

  • Administrator portals

  • Third-party cloud services

  • External supplier accounts

  • Protocols that do not support modern authentication


Attackers will often look for the route where the strongest controls have not been applied.


Are all types of MFA equally secure?

No.


Different authentication methods provide different levels of protection against phishing, interception and social engineering.


Methods can include:

  • Codes sent by text message

  • Codes generated by an authentication application

  • Push notifications

  • Number-matching approvals

  • Hardware security keys

  • Passkeys

  • Windows Hello for Business

  • Certificate-based authentication


Text messages and standard approval notifications still offer valuable protection compared with using a password alone. However, they can be more exposed to phishing, social engineering and user error than phishing-resistant methods.


The NCSC recommends selecting MFA methods according to the organisation’s risk and using stronger methods for access to sensitive information.


Microsoft supports phishing-resistant authentication methods such as passkeys, FIDO2 security keys, Windows Hello for Business and certificate-based authentication in appropriate configurations.


What is phishing-resistant MFA?

Phishing-resistant MFA uses cryptographic methods connected to the legitimate service being accessed.


This makes it much harder for a fraudulent website to capture and reuse the employee’s authentication.


Depending on the business environment, phishing-resistant methods may include:

  • FIDO2 security keys

  • Passkeys

  • Windows Hello for Business

  • Certificate-based authentication


These methods are especially important for:

  • Global administrators

  • Security administrators

  • Finance users

  • Senior leaders

  • Employees with access to sensitive data

  • IT support personnel

  • Users regularly targeted by phishing


A business may introduce stronger methods to high-risk users first before expanding them across the organisation.


Does Microsoft Authenticator make an account completely secure?

No authentication application can make an account completely secure.


Microsoft Authenticator can provide strong protection, especially when features such as number matching and additional sign-in context are used. However, users can still be deceived into approving fraudulent requests.


The wider account configuration also matters.


For example:

  • Is MFA required for every relevant sign-in?

  • Are legacy authentication methods blocked?

  • Is the device managed?

  • Are risky sign-ins monitored?

  • Can the user register a new authentication method without additional checks?

  • Are administrator accounts separated from everyday accounts?

  • Are sign-in sessions reviewed and revoked following suspected compromise?


The application is one component of the identity-security setup.


What should I do if I receive an MFA request I did not initiate?

Deny the request and report it immediately.


An unexpected authentication request may mean that someone already knows the account password and is attempting to complete the login.


The employee should:

  1. Reject the request.

  2. Avoid approving further prompts.

  3. Contact the organisation’s IT support or security team.

  4. Change the password using a trusted device and genuine sign-in page if instructed.

  5. Review recent sign-in activity.

  6. Follow the business’s account-compromise procedure.


Repeated prompts should not be treated as a harmless technical fault until they have been investigated.


Is MFA enough to stop phishing?

MFA does not stop phishing emails from reaching employees.


It can prevent a stolen password from being used successfully, but some phishing attacks are designed to steal the second factor or authenticated session as well.


Businesses should still use:

  • Email filtering

  • Anti-phishing protection

  • Employee awareness training

  • Safe reporting processes

  • Domain authentication

  • Web and link protection

  • Security monitoring

  • Incident-response procedures


MFA reduces the consequences of many credential-phishing attacks, but it does not remove the need to detect and block phishing.


For an introduction to how MFA works, read What Is Multi-Factor Authentication?.


What protection should businesses use alongside MFA?

A layered identity-security setup may include:


Conditional access

Conditional Access can apply different requirements based on factors such as the user, device, location, application and detected risk.

For example, the business might block access from an unmanaged device or require stronger authentication for an administrator.


Managed devices

Microsoft Intune or another device-management platform can help ensure that computers and mobile devices meet the organisation’s security requirements before accessing company data.


Endpoint protection

MFA cannot compensate for a device infected with malware. Endpoint detection, antivirus protection, patching and restricted administrative privileges help reduce the risk of session and information theft.


Sign-in monitoring

Unusual locations, devices, authentication registrations and access patterns should be monitored and investigated.


Least-privilege access

Employees should have only the access required for their role. Administrator accounts should not be used for routine email and web browsing.


Employee training

Employees need to recognise fraudulent sign-in pages, unexpected approval requests and attempts to obtain verification codes.


Secure recovery processes

Account-recovery and MFA-reset procedures should verify the user properly. Otherwise, attackers may bypass strong authentication by targeting the recovery process.


Does every employee need MFA?

MFA should be required for everyone accessing business systems where the service supports it.


It is particularly important for:

  • Microsoft 365

  • Remote access

  • Cloud storage

  • Finance and banking systems

  • Customer databases

  • HR platforms

  • Password managers

  • Administrative accounts

  • Backup systems

  • Supplier and procurement portals


Applying MFA only to senior employees or administrators leaves other accounts available as possible entry points.


Standard users may still have access to email, company documents, customer details and internal conversations that attackers can exploit.


Can MFA prevent a business email compromise attack?

It can prevent many account-takeover attempts, particularly those relying on stolen passwords.


However, business email compromise can still occur through:

  • Stolen authenticated sessions

  • Fraudulent approval requests

  • Compromised supplier accounts

  • Email spoofing

  • Manipulation without account access

  • Weak account-recovery procedures

  • A compromised employee device


Payment and bank-detail changes should therefore be verified through a trusted second communication method, regardless of whether MFA is enabled.


What should a business check after enabling MFA?

Businesses should confirm:

  • MFA covers every relevant user and application.

  • Administrator accounts use appropriately strong authentication.

  • Legacy authentication is blocked where possible.

  • Users have more than one secure recovery method.

  • Old authentication methods are removed.

  • New authentication registrations generate alerts where appropriate.

  • Sign-in and risk information is monitored.

  • Service-desk reset procedures verify identities properly.

  • Employees know how to report unexpected prompts.

  • Emergency-access accounts are secured and monitored.

  • Third-party applications are included in the review.


Simply switching MFA on is not the end of the project. Its coverage, method and supporting controls should be reviewed regularly.

Related Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

bottom of page