Identity · Draft held

MFA for Microsoft 365 beginners: a UK SME owner guide (2026)

Plain-English MFA for UK SME owners on Microsoft 365: what it is, authenticator vs SMS vs keys, turn it on for yourself then the team, and the gotchas that break small firms.

Most UK firms with 2 to 50 people live in Microsoft 365: Outlook, Teams, OneDrive, SharePoint. If someone steals a password for those accounts, they can read customer email, reset other tools, and quietly change invoice details. Multi-factor authentication (MFA) is the single cheapest control that makes stolen passwords much less useful.

This guide is for owner-managers who are not IT people. It explains what MFA is, how to turn it on for yourself first, then for the team, and the traps small firms hit (shared logins, SMS, legacy apps). It will not turn you into an Entra ID specialist. It will get the basics done without fear theatre.

What MFA is (and what it is not)

MFA means signing in needs more than the password. Usually that is something you have: a code from an authenticator app on your phone, a tap on a push notification, or a hardware security key. Sometimes it is a text message. The point is simple: a leaked or guessed password alone should not open the door.

MFA is not:

  • A full security programme. You still need unique passwords, patching, backups, and payment discipline.
  • Antivirus. It does not scan files or stop ransomware by itself.
  • A guarantee. Skilled attackers and social engineering still exist. MFA raises the cost of a common attack; it does not invent a force field.
  • The same as a password manager. They work together. The vault stops reuse; MFA stops a stolen password from being enough.

Why Microsoft 365 MFA matters more than most other tools

For a typical UK SME, email is the nerve centre. Payroll notices, supplier invoices, board packs, and password-reset links all land there. If an attacker sits in your mailbox, they can:

  • Reset other services that email a reset link
  • Set quiet forwarding rules so you never see the fraud thread
  • Impersonate you to customers with "new bank details"
  • Pull files from OneDrive and SharePoint that sit behind the same login

That is why MFA on Microsoft 365 usually beats buying another shiny product first. Cyber Essentials also expects multi-factor authentication on internet-facing and cloud services where available. See OwnerSec's Cyber Essentials beginner guide if you are heading that way. Finish MFA before you collect certificates.

Authenticator app vs SMS vs security keys

You will see three common second factors. Prefer the stronger ones when the product allows it. Be honest about what "better" means: fewer easy attack paths, not perfection.

  • Authenticator app (Microsoft Authenticator, or another TOTP app): recommended default for most SMEs. Codes or push approvals live on a device you control. Works offline for code-based apps. Store backup/recovery codes in the company password manager, not in WhatsApp.
  • Security keys (FIDO2 / hardware keys): excellent for admins and high-risk roles when you can buy and label a few keys. Harder for remote phishing to copy than a typed code. Overkill as day-one for every warehouse phone, fine for the people who can empty the bank.
  • SMS text codes: better than password-only. Still weaker than apps or keys. SIM-swap and SMS interception are real for some high-value targets; they are uncommon for a quiet 12-person firm, but SMS remains the fall-back, not the goal. Use SMS if it is the only option someone will accept this week, then migrate to an app.

No method is "unhackable". Choose authenticator or keys where you can. Treat SMS as a temporary bridge.

Turn it on for yourself first

Do you before you preach. Owner-managers who skip their own MFA become the softest admin account in the tenant.

  • Sign into Microsoft 365 / Outlook on the web with your normal work account.
  • Open your Microsoft account security / additional security verification settings (wording moves in the portal; search "security info" or "My Account" if the menu has moved).
  • Add Microsoft Authenticator (or another supported authenticator). Scan the QR code with the phone app. Complete one test sign-in.
  • Add a second method if offered (backup phone or a second authenticator). Print or copy recovery codes into the company password manager vault item for your account.
  • Sign out and sign back in once on laptop and phone so you know the prompt works before you enforce it on staff.

If you cannot find the self-service page, your tenant may already require admin-led enrolment. That is fine: use the admin steps below on your own account first.

Then turn it on for the team (high-level admin steps)

Exact clicks change as Microsoft renames admin centres. The intent stays the same. You need Global Admin or an equivalent security role. If an MSP runs your tenant, ask them to enable MFA for all users and to confirm legacy authentication is off. You still own the outcome.

  • Open the Microsoft 365 admin centre, then the identity / Entra security settings for multifactor authentication or Conditional Access (licence-dependent).
  • Prefer a policy that requires MFA for all users on Microsoft 365 apps, not a voluntary "please enrol when you fancy it" poster.
  • Roll out in waves if you have more than a handful of people: leadership and finance first, then everyone else. Give 48 hours' notice and a one-page how-to with screenshots.
  • Block or disable legacy authentication where your plan allows it. Old mail apps that only understand username + password will keep failing MFA and tempting people to carve exceptions.
  • Confirm every human mailbox has enrolled. Shared mailboxes should not be signed into with a shared password; people open them from their own MFA-protected account.

You do not need a 40-page Conditional Access design on day one. Require MFA for interactive sign-ins. Close the obvious holes. Revisit advanced policies when the basics are boring and reliable.

Common gotchas in small firms

These trip UK SMEs more often than exotic zero-days.

  • Shared accounts: "everyone uses the founder Outlook login" defeats MFA discipline and makes leavers a nightmare. Give people named accounts. Use shared mailboxes for info@ / accounts@ without sharing a password. See OwnerSec's shared-login guide.
  • Legacy auth and old phone mail apps: they may ignore modern MFA. Update to Outlook mobile / current Outlook, or move the account into a modern client.
  • Contractors on the founder login: never. Guest or named accounts with time limits; remove access the day the project ends.
  • Break-glass admin: keep one emergency admin account with a long unique password in the vault, MFA registered to a hardware key or a controlled second factor, and two named people who know it exists. Do not use it for daily email.
  • Lost phone: rehearse recovery. Backup codes in the vault and a second factor beat "we are locked out until Monday".
  • Personal Microsoft accounts mixed with work: staff should sign into work M365 with the work identity.

Tie MFA to a password manager

MFA without unique passwords still hurts. People reuse the same password across Xero, the bank, and a random shipping portal. When one site leaks, attackers try that password on Microsoft 365. MFA helps; unique passwords help more together.

  • Roll out a company vault (1Password Business or Bitwarden Teams / Business are common SME choices).
  • Store Microsoft recovery codes and break-glass details as vault items with restricted access.
  • Stop sending temporary passwords in WhatsApp or SMS group chats.
  • Kill the spreadsheet of shared logins as part of the same project, not "later".

Microsoft 365 licences themselves are usually bought direct or via a partner. OwnerSec does not pretend there is an affiliate link for M365 when there is not. Pay for the plan you need; finish MFA on it.

What MFA does not stop

Keep expectations honest so staff trust the guidance.

  • Invoice fraud and change-of-bank-details social engineering: someone phones or emails pretending to be a supplier. MFA on email does not verify a new sort code. Use a call-back on a known number.
  • Already-stolen sessions: if malware or a phishing page already grabbed an open session, turning MFA on afterwards helps the next login, not the current thief. Revoke sessions and follow the phishing first-hour checklist.
  • Malware on the device: MFA does not replace endpoint protection or backups.
  • Someone approving a push by habit ("MFA fatigue"): teach people to deny unexpected prompts and report them.

Copy-paste checklist for owner-managers

Drop this into onboarding or a Teams note.

  • Owner and admins enrol MFA on their own Microsoft 365 accounts today
  • Authenticator app (or security key for admins) preferred; SMS only as bridge
  • Recovery codes stored in the company password manager
  • Company-wide MFA required for Microsoft 365 sign-in (admin policy, not a poster)
  • Legacy authentication reviewed and turned off where possible
  • No shared founder login; shared mailboxes instead of shared passwords
  • Contractors on named, time-limited accounts
  • Break-glass admin documented with two named holders
  • Staff told: deny unexpected MFA prompts; report them
  • Sessions revoked for anyone who may already be phished

What this guide is not

  • Not a full Microsoft Entra / Conditional Access training course.
  • Not Cyber Essentials certification. MFA helps that journey; assessment has its own rules.
  • Not a promise that MFA stops ransomware, invoice fraud, or every account takeover.
  • Not legal, NCSC, insurance, or consultancy advice.
  • Not a reason to delay MFA until you buy five other products.

A sensible order if you are starting cold

Day 1: enrol yourself and any Global Admins on authenticator apps; store recovery codes in a vault. Day 2–3: announce MFA to the team with a one-pager; enforce for finance and leadership. Day 4–5: enforce for everyone; fix legacy mail clients; kill shared passwords. Same week: confirm leavers lose access and contractors are named. Next: remote-work checklist items (device encryption, payment rules) and a backup restore test.

FAQ

Is SMS MFA good enough for a small UK firm?
SMS is better than password-only. Prefer an authenticator app or security key where the product allows it. Use SMS as a temporary bridge if that is all someone will accept this week.
Does MFA stop invoice fraud?
No. MFA protects sign-in. Change-of-bank-details fraud still needs a call-back on a known number and a written payment rule.
Do we need Cyber Essentials before turning MFA on?
No. Turn MFA on first. Cyber Essentials is a separate assessment path that also expects MFA where available.
Is Microsoft 365 itself an OwnerSec affiliate product?
Usually not. Buy Microsoft 365 direct or via your partner. Affiliate placeholders here are for password managers.

Bottom line

For a UK SME on Microsoft 365, MFA is boring on purpose. Turn it on for yourself, enforce it for the team, prefer authenticator apps or keys over SMS, pair it with a company password manager, and fix shared logins. That will not make you fully secure. It will close the hole attackers use most often against firms your size.

Written for UK SME owners. More guides · How we make money · Pages-ready draft only (held)