Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Identity and access

    Multi-Factor Authentication (MFA)

    Multi-factor authentication requires two or more independent proofs of identity before granting access: something you know, something you have, or something you are. In Microsoft 365 it is enforced through Microsoft Entra ID, most commonly with the Microsoft Authenticator app rather than SMS codes.

    What Multi-Factor Authentication (MFA) means in practice

    Multi-factor authentication is the single highest-value security control available to most businesses, because the overwhelming majority of account compromises begin with a password rather than a software exploit. Passwords are phished, reused across services, and exposed in breaches of unrelated sites. A second factor breaks that chain.

    Not all factors are equal. SMS codes are better than nothing but vulnerable to SIM swapping and interception, and Australian telecommunications providers have seen enough SIM porting fraud that regulated organisations should avoid relying on them. Authenticator app push notifications are stronger, particularly with number matching enabled, which forces the user to type a number shown on the sign-in screen and defeats the fatigue attacks where an attacker spams approvals until somebody taps accept. Hardware security keys and Windows Hello for Business are stronger again and resist phishing outright.

    Coverage is where most implementations fall short. MFA applied to email but not to VPN, or enforced for staff but not for administrators, contractors or service accounts, leaves the door it was meant to close. Legacy authentication protocols such as IMAP, POP and older Exchange clients bypass modern authentication entirely, which is why disabling them is part of any credible rollout.

    Rollout is a change management exercise as much as a technical one. Enrolment should be staged, with a clear window, a communication that explains why, and a support path for staff whose phones cannot run the app. Shared devices, front-of-house terminals and field workers without reliable mobile coverage all need a designed answer before enforcement, not after.

    For Australian organisations, MFA appears explicitly in the Essential Eight, in APRA expectations for regulated entities, and in nearly every cyber insurance questionnaire. Insurers increasingly ask not whether MFA exists but whether it covers all remote access and all privileged accounts, and they expect evidence rather than assurance.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.