Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security.
|

Setting Up MFA the Right Way

Setting Up MFA the Right Way: Why SMS Isn’t Enough Anymore

Most businesses know they should have multi-factor authentication (MFA) turned on. Fewer realize that the type of MFA they’re using actually matters. If your team’s second factor is a text message code, you have some protection, but less than you probably think.

Why SMS Codes Aren’t Enough Anymore

SMS-based MFA was a meaningful step forward when it became common, but attackers have caught up. The biggest problem is SIM swapping, where an attacker convinces a mobile carrier to transfer a victim’s phone number to a SIM card the attacker controls. Once that happens, every SMS code meant for you goes straight to them instead. Text messages can also be intercepted through vulnerabilities in the cellular network itself, and phishing kits now exist specifically designed to capture SMS codes in real time as a victim types them into a fake login page.

None of this means SMS-based MFA is worthless, it’s still far better than no MFA at all. But if you’re setting up MFA for the first time, or upgrading what you already have, there are stronger options that aren’t meaningfully harder to use.

The Better Options

Authenticator Apps

Apps like Microsoft Authenticator, Google Authenticator, or Authy generate a rotating six-digit code directly on your phone, no cell network or text message involved at all. Because the code is generated locally on the device rather than transmitted, there’s nothing for an attacker to intercept. This is the most common upgrade path, and most services that support MFA already support authenticator apps.

Hardware Security Keys

Physical keys like a YubiKey plug into a USB port or tap via NFC to approve a login. These are built on a standard called FIDO2/WebAuthn, which is specifically designed to resist phishing, the key checks that it’s talking to the real website before it approves anything, so even a perfect fake login page can’t trick it. This is the strongest option available, and the standard recommendation for anyone handling particularly sensitive data or accounts (like IT admins, finance, or executives).

Rolling This Out Across Your Team in an Afternoon

1. Start With Your Highest-Risk Accounts

Email and your identity provider (Microsoft 365 or Google Workspace) come first, since compromising either one usually gives an attacker a path into everything else. Admin accounts should be the very first ones upgraded.

2. Pick One Authenticator App as the Standard

Just like with password managers, standardizing avoids a mess of different apps and different recovery processes. Microsoft Authenticator is a reasonable default if your team is already in the Microsoft 365 ecosystem.

3. Walk Through Setup Together

For each person: open the security settings for the account being protected, choose “authenticator app” as the MFA method, scan the QR code with the app, and confirm with the generated code. This takes about two minutes per account once someone’s done it once.

4. Save Backup Codes Somewhere Safe

Every MFA setup process offers one-time backup codes for account recovery if a device is lost. These should go into the team’s password manager, not a sticky note or an unencrypted document.

5. Turn Off SMS as a Fallback Where You Can

Many services keep SMS available as a backup option even after you set up an authenticator app. Where possible, remove SMS entirely rather than leaving it as a weaker fallback an attacker could exploit.

6. Roll Out Hardware Keys for High-Risk Roles

Once the team is comfortable with authenticator apps, consider hardware keys specifically for admin accounts, finance, and anyone with access to sensitive client data.

The Bottom Line

Upgrading from SMS to an authenticator app is a small change with a real security payoff, and most teams can get through it in a single afternoon. If you’re not sure which of your accounts still rely on SMS-only MFA, that’s worth a quick audit, and it’s exactly the kind of thing we can help you sort out.

Leave a Reply

Your email address will not be published. Required fields are marked *