What Multi-Factor Authentication (MFA) means in practice
Multi-factor authentication is the single highest-value security control available to most businesses, because the overwhelming majority of account compromises begin with a password rather than a software exploit. Passwords are phished, reused across services, and exposed in breaches of unrelated sites. A second factor breaks that chain.
Not all factors are equal. SMS codes are better than nothing but vulnerable to SIM swapping and interception, and Australian telecommunications providers have seen enough SIM porting fraud that regulated organisations should avoid relying on them. Authenticator app push notifications are stronger, particularly with number matching enabled, which forces the user to type a number shown on the sign-in screen and defeats the fatigue attacks where an attacker spams approvals until somebody taps accept. Hardware security keys and Windows Hello for Business are stronger again and resist phishing outright.
Coverage is where most implementations fall short. MFA applied to email but not to VPN, or enforced for staff but not for administrators, contractors or service accounts, leaves the door it was meant to close. Legacy authentication protocols such as IMAP, POP and older Exchange clients bypass modern authentication entirely, which is why disabling them is part of any credible rollout.
Rollout is a change management exercise as much as a technical one. Enrolment should be staged, with a clear window, a communication that explains why, and a support path for staff whose phones cannot run the app. Shared devices, front-of-house terminals and field workers without reliable mobile coverage all need a designed answer before enforcement, not after.
For Australian organisations, MFA appears explicitly in the Essential Eight, in APRA expectations for regulated entities, and in nearly every cyber insurance questionnaire. Insurers increasingly ask not whether MFA exists but whether it covers all remote access and all privileged accounts, and they expect evidence rather than assurance.
How we help with this
Related terms
- Conditional AccessConditional Access is the policy engine in Microsoft Entra ID that decides what happens after a sign-in is authenticated.
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
