Multi-factor authentication rolled out across Microsoft 365, VPN and administrative accounts, with conditional access tuned so security does not become a daily tax.
Why this one first
If a business asks where to start with security and can only do one thing, the answer is multi-factor authentication on Microsoft 365 and remote access. Nothing else available at comparable cost blocks as large a share of real attacks.
The reason is structural. The dominant attack against Australian businesses of 10 to 200 staff is not sophisticated malware. It is someone logging in with a valid password — obtained from a phishing page, reused from an unrelated breach, or guessed. Every one of those paths ends at the same wall when a second factor is required.
The gap between having MFA and being protected
Most environments we audit report that MFA is enabled. A meaningful share of them are not actually protected, for one of three reasons.
Legacy authentication is still permitted. Older mail protocols cannot present an MFA challenge, so an attacker with a valid password connects through one and bypasses the control entirely. The MFA is real; it just is not in the path.
Exemptions were never removed. A policy exclusion added for one person, or one application, during rollout two years ago. Still live. Usually on an account with elevated rights, because that was the person who found it inconvenient.
Administrators are not covered. General staff enrolled, global administrators exempted so automation would not break. Which inverts the priority exactly — the privileged accounts are the ones an attacker is trying to reach.
Auditing for these three is quick and it is the first thing we do.
Conditional access is what makes it liveable
Blanket MFA on every sign-in generates fatigue, and fatigued users approve prompts without reading them — which is its own attack vector, and a successful one.
Conditional access sets policy by context. A managed, compliant device on a known network signs in without challenge. An unfamiliar device, an unusual location, or an impossible-travel pattern gets challenged or blocked. Administrative actions always require a fresh factor.
The result is that prompts become rare and therefore meaningful. When one appears unexpectedly, it is genuinely worth reading.
Not all second factors are equal
In rough order of strength: hardware security keys, then authenticator apps with number matching, then authenticator push without number matching, then SMS.
Number matching matters more than it sounds. Plain push approval is vulnerable to MFA fatigue attacks — an attacker with your password triggers prompts repeatedly until someone taps approve to stop the noise. Number matching requires reading a code from the login screen, which makes blind approval impossible.
For global administrators and finance staff, hardware keys are worth the cost.
Getting it deployed
MFA rollouts fail on change management, not technology. Staff told a week in advance what is changing and why, with a short enrolment guide and a window to do it, will enrol. Staff who discover it on a Monday morning when they cannot read their email will generate a support queue and a grievance.
We stage it: privileged accounts, then a pilot group, then the organisation, then legacy authentication disabled once nothing is left depending on it.