MFA

Authenticator apps and MFA for UK SME staff accounts (2026)

A practical checklist for UK owner-managers. Turn on authenticator-app MFA for named staff accounts, covering Microsoft 365, Google Workspace, and the company password manager.

A password on its own is a single point of failure. Multi-factor authentication (MFA) adds a second check. For a small UK firm, that second check should be an authenticator app, not a habit of texting codes around the office.

This guide is for owner-managers with roughly 2 to 50 staff and no IT department. It is a checklist, not a product manual. Admin menus move. If a button name has changed, use the vendor's current help and keep the same outcome.

If you only need Microsoft 365 steps, use OwnerSec's MFA for Microsoft 365 beginners guide. This page sits beside it. It covers staff phones, Google Workspace, and how MFA fits a password manager.

What an authenticator app actually does

You sign in with the password. The service then asks for a short code, or a prompt on a phone you have already unlocked. The app creates that code on the phone. It does not need a text message.

SMS is better than nothing. It is weaker than an app. Text messages can be redirected. An app code is harder to steal at a distance. It is still not magic. If someone types the code into a fake login page, the code works for a short time.

A security key (a small hardware token) is stronger again, especially for admin accounts. Most small firms should start with an authenticator app this week. Add a key for the owner and the admin later if you want to.

Named staff accounts come first

MFA on a shared login is a muddle. You cannot tell who approved a prompt. You cannot remove one leaver without locking everyone else out.

  • Each person gets their own work account for email and for the password manager.
  • Use a shared mailbox for accounts@ or info@. Do not share the founder's password.
  • Contractors get a named account with an end date, not the owner's login.
  • Write down who can pay suppliers, change DNS, and reset other people's passwords. Those people enrol first.

Shared Gmail and shared Outlook passwords cause the same problem. See OwnerSec's shared-login guide.

Turn MFA on in this order

  1. Email (Microsoft 365 or Google Workspace). Mail is how people reset everything else.
  2. The company password manager. The vault is where the other passwords live.
  3. Banking, payroll, and accounting (your bank, Xero, FreeAgent, Sage, and HMRC where a second factor is offered).
  4. Domain, website, and ad accounts that can send mail or spend money as the business.

Leave the printer portal and the coffee-supplier login until the list above is done.

Microsoft 365, in brief

Do this if work email is Outlook or Microsoft 365. Skip to the next section if you are on Google Workspace only.

  • The owner and any admin enrol first, using an authenticator app.
  • Microsoft Authenticator is the usual choice. Another reputable authenticator app is fine if it scans a QR code.
  • Require MFA for the whole tenant. Security defaults, or the MFA setting already in your admin centre, both aim at that outcome. Follow Microsoft's current labels if the screen has moved.
  • Keep backup codes, and a note of any emergency admin account, in the company password manager. Not in a personal notes app. Not in WhatsApp.
  • A shared mailbox is fine. A shared password for the founder's mailbox is not.

Step-by-step owner notes, including lost phones and legacy mail apps, are in the Microsoft 365 MFA beginners guide.

Google Workspace, in brief

Do this if work email is Google Workspace. If you use both Google and Microsoft, protect both. Attackers use whichever inbox can reset the other.

  • Sign in to the Admin console as a super admin who already has MFA, or turn yours on before you enforce it for everyone else.
  • Open Security, then the 2-step verification settings. Google renames these menus. If you cannot see them, search the admin help for "2-step verification".
  • Allow authenticator apps. A Google prompt on a phone the user has unlocked is acceptable for many small teams. Keep SMS as a short bridge, not the long-term standard.
  • Each person scans the QR code in their own app and saves backup codes.
  • Turn enforcement on after the owner is enrolled. Give people a few days to finish setup. Do not leave it optional for months.
  • Super admin accounts need MFA too. Do not keep a password-only recovery admin "just in case" with the password in a drawer.

If other tools use "Sign in with Google", Workspace MFA covers that Google sign-in. Still check any tool that has its own admin password outside Google.

Password manager plus MFA

MFA without unique passwords still hurts. People reuse one password on email, the bank, and a random portal. MFA on email helps. It does not fix the reused password on the portal.

Unique passwords without MFA on the vault also hurt. The vault becomes the new single point of failure.

Use both. Put a company password manager in place. Turn MFA on for that vault. Store email backup codes in the vault, with access limited to the owner and one deputy.

NordPass Business is a sensible option for a small UK team that wants shared folders and a cash-priced plan you can check on the vendor site. OwnerSec has a live affiliate link. Commission does not change the order of this checklist. Named accounts and MFA come first. The vault is how you keep them tidy.

  • Shared folders let you remove a leaver from supplier and tool logins without emailing a spreadsheet.
  • You can require an authenticator app, or a security key, on the NordPass account itself. Do that for admins at minimum.
  • NordPass can also show one-time codes for other websites, including some shared items. That is useful when a supplier portal really is one shared login. It is better than sending codes on WhatsApp. It is weaker than giving each person their own account.
  • Do not store the NordPass sign-in code inside NordPass. NordPass warns that this can lock the team out of the apps. Keep that factor in a separate authenticator app. Keep backup codes with two named people.
  • If staff already sign in with company single sign-on, and that sign-on already asks for MFA every time, do not stack a second NordPass prompt on top. NordPass's own admin guidance says the identity provider's MFA is enough in that case.

1Password and Bitwarden remain reasonable alternatives. See best password manager for small UK businesses and 1Password vs Bitwarden. The rollout habit is the same either way: stop staff reusing passwords, then keep MFA on the vault.

Personal phones, lost phones, and leavers

Most firms this size will not buy a second phone for MFA. Say that clearly. A personal phone with a work account in an authenticator app is normal.

  • Work identity, personal handset: acceptable.
  • The company still owns the access. On the last day, remove that person's sign-in methods, sign them out of email and the vault, and rotate any shared items they could open.
  • Backup codes live in the company vault, not in one person's camera roll.
  • If a phone is lost or stolen, use the backup code the same day. Do not wait for a replacement handset.
  • Tell people to deny unexpected approval prompts. A prompt you did not just trigger is a reason to stop and tell the owner. Tapping Yes out of habit is a common way MFA fails.

One-week checklist

Copy this into a note the owner can see. Short is the point.

Day 1

  • Owner and admins enrol authenticator-app MFA on work email
  • Password-manager admin account has MFA on, in a separate app from any codes stored in the vault
  • Backup codes saved in the company vault, limited to two named people

Day 2

  • One short note to staff: what will change, which app to install, who to ask
  • Finance and anyone who can pay a supplier enrol the same day

Days 3 to 4

  • Enforcement turned on for Microsoft 365 or Google Workspace (or both)
  • SMS left only where an app really is not available yet
  • Old shared founder passwords removed; shared mailboxes used instead

Day 5 and the same week

  • MFA turned on for bank, payroll, and accounting admin users where the product offers it
  • Leaver step written down: remove MFA methods, sign them out, rotate shared logins
  • Staff told to deny prompts they did not just request

If someone has already clicked a bad link, do not wait for this rollout to finish. Use the first-hour phishing checklist, then come back to MFA.

What this does not stop

  • Invoice fraud and "new bank details" emails. MFA protects sign-in. It does not check a sort code. Use a call-back on a known number. See the invoice fraud checklist.
  • A one-time code typed into a lookalike page.
  • Malware already on the laptop. MFA is not endpoint protection and it is not a backup.
  • Someone approving a prompt because it appeared. Teach a deny-and-report habit.

Cyber Essentials expects MFA where it is available. You do not need the certificate before you turn MFA on. The Cyber Essentials beginners guide explains what the scheme is, and what it is not.

FAQ

Is SMS good enough?
It is better than a password alone. Prefer an authenticator app this month. Keep SMS only as a bridge for someone who cannot scan a QR code yet.
Can we use personal phones?
Yes. Use named work accounts, store backup codes in the company vault, and remove the person's methods on their last day.
We have both Microsoft 365 and Google Workspace. Which one?
Protect the system that holds staff email first. If both send or receive work mail, protect both. Email is the reset path.
Does a password manager replace MFA?
No. The vault stores unique passwords. MFA is the second check on email, on the vault, and on finance tools.
Is NordPass required?
No. It is one business password manager with a live OwnerSec affiliate link. 1Password and Bitwarden are fair alternatives. Check current pricing yourself.

Bottom line

Give people named accounts. Put an authenticator app on email and on the password manager. Enforce it within the week. Keep backup codes with two named people. Remove leavers the day they leave. That will not make the firm fully secure. It closes the sign-in gap most small UK companies still leave open.

Written for UK SME owners. More guides · How we make money · Pages-ready draft only (held)