Skip to main content
Service

MFA, deployed properly — the highest-return security control there is

A stolen password stops being enough. Rolled out across Microsoft 365, VPN and admin accounts with conditional access, so it protects you without punishing your staff daily.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Multi-factor authentication rolled out across Microsoft 365, VPN and administrative accounts, with conditional access tuned so security does not become a daily tax.

Why this one first

If a business asks where to start with security and can only do one thing, the answer is multi-factor authentication on Microsoft 365 and remote access. Nothing else available at comparable cost blocks as large a share of real attacks.

The reason is structural. The dominant attack against Australian businesses of 10 to 200 staff is not sophisticated malware. It is someone logging in with a valid password — obtained from a phishing page, reused from an unrelated breach, or guessed. Every one of those paths ends at the same wall when a second factor is required.

The gap between having MFA and being protected

Most environments we audit report that MFA is enabled. A meaningful share of them are not actually protected, for one of three reasons.

Legacy authentication is still permitted. Older mail protocols cannot present an MFA challenge, so an attacker with a valid password connects through one and bypasses the control entirely. The MFA is real; it just is not in the path.

Exemptions were never removed. A policy exclusion added for one person, or one application, during rollout two years ago. Still live. Usually on an account with elevated rights, because that was the person who found it inconvenient.

Administrators are not covered. General staff enrolled, global administrators exempted so automation would not break. Which inverts the priority exactly — the privileged accounts are the ones an attacker is trying to reach.

Auditing for these three is quick and it is the first thing we do.

Conditional access is what makes it liveable

Blanket MFA on every sign-in generates fatigue, and fatigued users approve prompts without reading them — which is its own attack vector, and a successful one.

Conditional access sets policy by context. A managed, compliant device on a known network signs in without challenge. An unfamiliar device, an unusual location, or an impossible-travel pattern gets challenged or blocked. Administrative actions always require a fresh factor.

The result is that prompts become rare and therefore meaningful. When one appears unexpectedly, it is genuinely worth reading.

Not all second factors are equal

In rough order of strength: hardware security keys, then authenticator apps with number matching, then authenticator push without number matching, then SMS.

Number matching matters more than it sounds. Plain push approval is vulnerable to MFA fatigue attacks — an attacker with your password triggers prompts repeatedly until someone taps approve to stop the noise. Number matching requires reading a code from the login screen, which makes blind approval impossible.

For global administrators and finance staff, hardware keys are worth the cost.

Getting it deployed

MFA rollouts fail on change management, not technology. Staff told a week in advance what is changing and why, with a short enrolment guide and a window to do it, will enrol. Staff who discover it on a Monday morning when they cannot read their email will generate a support queue and a grievance.

We stage it: privileged accounts, then a pilot group, then the organisation, then legacy authentication disabled once nothing is left depending on it.

What you get with JTIT

Concrete deliverables, not vague promises.

A stolen password becomes insufficient

Credential stuffing, phishing and password reuse all end at the same wall. This single control blocks the large majority of opportunistic account attacks.

Conditional access, not constant prompting

Trusted device on the office network: sign in normally. Unfamiliar location or unmanaged device: challenge. Security that adapts is security staff do not work around.

Admin accounts treated differently

Privileged accounts get stricter policy than general users, because those are the credentials that turn an incident into a catastrophe.

Legacy authentication closed

Old protocols bypass MFA entirely. Leaving them enabled means the control is present but not actually enforced — a very common gap.

Phishing-resistant options where they matter

Number matching and authenticator apps over SMS, and hardware keys for the highest-risk accounts. Not all second factors are equal.

Satisfies the insurance question honestly

Cyber policies now commonly require MFA on email and remote access. Answering yes accurately, with evidence, is a condition of cover you can prove.

How it works

A predictable, no-surprises process.

  1. 01

    Audit current coverage

    Who has MFA, who does not, which accounts are exempt, and whether legacy authentication is still permitted anywhere. Exemptions from years ago are usually still live.

  2. 02

    Secure privileged accounts first

    Global administrators and anyone with elevated rights, before general staff. These are the accounts an attacker actually wants.

  3. 03

    Roll out with communication

    Staff told what is changing, why, and how to enrol, in advance. MFA rollouts fail on change management far more often than on technology.

  4. 04

    Tune with conditional access

    Policies adjusted so trusted contexts are frictionless and risky ones are challenged, then legacy authentication disabled once nothing depends on it.

Frequently asked questions

Our staff will complain. How disruptive is this really?

Handled badly, very. Handled properly, most staff notice it for about a week and then stop thinking about it. The difference is conditional access: if a policy is written so that signing in on a managed device from the office is not challenged every time, the prompts only appear in genuinely unusual situations. The rollouts that generate revolt are the ones deployed with a blanket policy and no communication.

Is SMS good enough as a second factor?

It is far better than nothing and considerably worse than the alternatives. SMS is vulnerable to SIM swapping and interception, and phishing kits routinely relay SMS codes in real time. An authenticator app with number matching is the practical standard, and hardware security keys are worth it for global administrators and finance staff. We will deploy SMS where a person genuinely cannot use an app, rather than leaving them unprotected.

What is legacy authentication and why does it matter?

Older mail protocols that predate modern authentication and cannot present an MFA challenge. If they remain enabled on your tenant, an attacker with a valid password can simply connect using one of them and bypass MFA entirely. This is the single most common reason an organisation that believes it has MFA turns out not to be protected. Disabling it requires checking that no old device or application depends on it, which is a real task but a finite one.

Do we need MFA if we are a small business?

Especially then. The attacks that reach small businesses are automated and password-driven — credential stuffing against Microsoft 365 using passwords leaked from unrelated breaches, at enormous volume. They do not care who you are. MFA is what turns a valid stolen password into a failed login, and it is the cheapest meaningful security control available to you.

Will our cyber insurance require it?

Almost certainly, and increasingly as a precondition rather than a discount. Policies commonly require MFA on email, remote access and privileged accounts. It is worth noting that misstating this on an application has caused claims to be reduced or declined, so the answer needs to be true rather than aspirational — which means knowing your actual coverage, including exemptions.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote