.png)
Cybersecurity
Is multi-factor authentication enough to protect a business?
By Steve Harper | 8 min read | Last updated:
12 August 2026 at 08:13:42

TL;DR
Multi-factor authentication significantly reduces the risk of account compromise, but it is not enough on its own.
Attackers may still gain access through fraudulent approval requests, convincing phishing pages, stolen browser sessions, compromised devices or weak account-recovery processes. Businesses should combine MFA with conditional access, managed devices, security monitoring, employee training and phishing-resistant authentication for sensitive accounts.
Key Takeaways
Every business should use MFA wherever it is available.
MFA can still be bypassed or misused.
Some authentication methods provide stronger protection than others.
Unexpected MFA requests should always be treated as suspicious.
Administrator and high-risk accounts need particularly strong authentication.
MFA should be combined with device, identity and email security.
Recovery and fallback methods must be protected too.
Is MFA enabled - or properly protecting your business?
IT Desk can review your Microsoft 365 identity security, MFA coverage, Conditional Access and device controls. We can identify unprotected accounts, improve authentication methods and help your employees recognise suspicious sign-in requests.
Can hackers bypass MFA?
Yes, although MFA makes account compromise considerably more difficult.
MFA requires the user to provide more than one form of authentication. This means that stealing a password may not be enough for an attacker to access the account.
However, attackers increasingly use techniques designed to trick users into completing the additional authentication step or to steal an authenticated session after MFA has already been completed.
The possibility of bypass does not mean MFA is ineffective. It means businesses should treat it as one important layer of security rather than a complete solution.
How can MFA be bypassed?
Common attack methods include:
MFA fatigue
An attacker who has obtained a password may repeatedly trigger authentication notifications on the employee’s phone.
The attacker hopes the employee will approve one of the requests to stop the notifications or because they assume it relates to a legitimate sign-in.
This is sometimes called MFA fatigue, push bombing or prompt bombing.
Adversary-in-the-middle phishing
A convincing phishing site may sit between the employee and the legitimate login service.
The employee enters their password and completes MFA, believing they are signing in normally. The attacker captures the authenticated session information and uses it to access the account.
This is why a standard authentication-app approval is not considered completely phishing-resistant.
Session-token theft
After a user signs in, the service may issue a token that allows the session to remain authenticated.
If malware or another attack steals this token, the criminal may be able to replay it without completing the original MFA process again. Microsoft specifically advises organisations to prepare for token-theft attacks even when MFA is deployed.
Social engineering
An attacker may contact the employee, service desk or mobile provider and attempt to manipulate account recovery or authentication settings.
For example, they may try to:
Register a new authentication method
Reset the existing MFA configuration
Move a mobile number to another SIM
Obtain a temporary access credential
Persuade the employee to disclose a verification code
Convince IT support that they are the legitimate user
Unprotected accounts or systems
MFA cannot protect an account if it is not actually required.
Businesses sometimes enable MFA for most users while leaving gaps such as:
Old or forgotten accounts
Service accounts
Legacy applications
Emergency-access accounts
Administrator portals
Third-party cloud services
External supplier accounts
Protocols that do not support modern authentication
Attackers will often look for the route where the strongest controls have not been applied.
Are all types of MFA equally secure?
No.
Different authentication methods provide different levels of protection against phishing, interception and social engineering.
Methods can include:
Codes sent by text message
Codes generated by an authentication application
Push notifications
Number-matching approvals
Hardware security keys
Passkeys
Windows Hello for Business
Certificate-based authentication
Text messages and standard approval notifications still offer valuable protection compared with using a password alone. However, they can be more exposed to phishing, social engineering and user error than phishing-resistant methods.
The NCSC recommends selecting MFA methods according to the organisation’s risk and using stronger methods for access to sensitive information.
Microsoft supports phishing-resistant authentication methods such as passkeys, FIDO2 security keys, Windows Hello for Business and certificate-based authentication in appropriate configurations.
What is phishing-resistant MFA?
Phishing-resistant MFA uses cryptographic methods connected to the legitimate service being accessed.
This makes it much harder for a fraudulent website to capture and reuse the employee’s authentication.
Depending on the business environment, phishing-resistant methods may include:
FIDO2 security keys
Passkeys
Windows Hello for Business
Certificate-based authentication
These methods are especially important for:
Global administrators
Security administrators
Finance users
Senior leaders
Employees with access to sensitive data
IT support personnel
Users regularly targeted by phishing
A business may introduce stronger methods to high-risk users first before expanding them across the organisation.
Does Microsoft Authenticator make an account completely secure?
No authentication application can make an account completely secure.
Microsoft Authenticator can provide strong protection, especially when features such as number matching and additional sign-in context are used. However, users can still be deceived into approving fraudulent requests.
The wider account configuration also matters.
For example:
Is MFA required for every relevant sign-in?
Are legacy authentication methods blocked?
Is the device managed?
Are risky sign-ins monitored?
Can the user register a new authentication method without additional checks?
Are administrator accounts separated from everyday accounts?
Are sign-in sessions reviewed and revoked following suspected compromise?
The application is one component of the identity-security setup.
What should I do if I receive an MFA request I did not initiate?
Deny the request and report it immediately.
An unexpected authentication request may mean that someone already knows the account password and is attempting to complete the login.
The employee should:
Reject the request.
Avoid approving further prompts.
Contact the organisation’s IT support or security team.
Change the password using a trusted device and genuine sign-in page if instructed.
Review recent sign-in activity.
Follow the business’s account-compromise procedure.
Repeated prompts should not be treated as a harmless technical fault until they have been investigated.
Is MFA enough to stop phishing?
MFA does not stop phishing emails from reaching employees.
It can prevent a stolen password from being used successfully, but some phishing attacks are designed to steal the second factor or authenticated session as well.
Businesses should still use:
Email filtering
Anti-phishing protection
Employee awareness training
Safe reporting processes
Domain authentication
Web and link protection
Security monitoring
Incident-response procedures
MFA reduces the consequences of many credential-phishing attacks, but it does not remove the need to detect and block phishing.
For an introduction to how MFA works, read What Is Multi-Factor Authentication?.
What protection should businesses use alongside MFA?
A layered identity-security setup may include:
Conditional access
Conditional Access can apply different requirements based on factors such as the user, device, location, application and detected risk.
For example, the business might block access from an unmanaged device or require stronger authentication for an administrator.
Managed devices
Microsoft Intune or another device-management platform can help ensure that computers and mobile devices meet the organisation’s security requirements before accessing company data.
Endpoint protection
MFA cannot compensate for a device infected with malware. Endpoint detection, antivirus protection, patching and restricted administrative privileges help reduce the risk of session and information theft.
Sign-in monitoring
Unusual locations, devices, authentication registrations and access patterns should be monitored and investigated.
Least-privilege access
Employees should have only the access required for their role. Administrator accounts should not be used for routine email and web browsing.
Employee training
Employees need to recognise fraudulent sign-in pages, unexpected approval requests and attempts to obtain verification codes.
Secure recovery processes
Account-recovery and MFA-reset procedures should verify the user properly. Otherwise, attackers may bypass strong authentication by targeting the recovery process.
Does every employee need MFA?
MFA should be required for everyone accessing business systems where the service supports it.
It is particularly important for:
Microsoft 365
Remote access
Cloud storage
Finance and banking systems
Customer databases
HR platforms
Password managers
Administrative accounts
Backup systems
Supplier and procurement portals
Applying MFA only to senior employees or administrators leaves other accounts available as possible entry points.
Standard users may still have access to email, company documents, customer details and internal conversations that attackers can exploit.
Can MFA prevent a business email compromise attack?
It can prevent many account-takeover attempts, particularly those relying on stolen passwords.
However, business email compromise can still occur through:
Stolen authenticated sessions
Fraudulent approval requests
Compromised supplier accounts
Email spoofing
Manipulation without account access
Weak account-recovery procedures
A compromised employee device
Payment and bank-detail changes should therefore be verified through a trusted second communication method, regardless of whether MFA is enabled.
What should a business check after enabling MFA?
Businesses should confirm:
MFA covers every relevant user and application.
Administrator accounts use appropriately strong authentication.
Legacy authentication is blocked where possible.
Users have more than one secure recovery method.
Old authentication methods are removed.
New authentication registrations generate alerts where appropriate.
Sign-in and risk information is monitored.
Service-desk reset procedures verify identities properly.
Employees know how to report unexpected prompts.
Emergency-access accounts are secured and monitored.
Third-party applications are included in the review.
Simply switching MFA on is not the end of the project. Its coverage, method and supporting controls should be reviewed regularly.
Related Insights
So, why IT Desk?

Proactive & Reactive Support
In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.
Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

Award Winning
Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!
Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

Experienced & Certified
Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.
From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent
Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.
With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.
Innovative Solutions for Businesses
20+
Years of Experience
A legacy of excellence in digital solutions.
100%
Zero Carbon
Doing our part for the environment.
Certified by British Gas.
99.9%
Client Satisfaction Rate
Trusted by businesses across all sectors for superior service.
1200+
Projects Completed
Delivering cutting-edge solutions for a seamless digital future.












