Call Us : 01636 34 33 32

MFA Requirements for UK SMEs Made Practical

Blog
Categories

Interested in discussing this further?

Give us a call, drop us a text or chat with us now

MFA Requirements for UK SMEs Made Practical

A stolen password should not be enough to give somebody access to your email, customer records or finance systems. That is the practical point behind MFA requirements. For most UK SMEs, multi-factor authentication is one of the quickest and most effective ways to reduce the risk of an account takeover, particularly in Microsoft 365.

It is also an area where businesses can make avoidable mistakes. Turning on MFA is not the same as having a workable security policy. Staff need a clear enrolment process, critical accounts need appropriate protection, and exceptions must be tightly controlled. Get it right and MFA adds a valuable barrier without making daily work harder than it needs to be.

What are MFA requirements?

Multi-factor authentication, often shortened to MFA or two-factor authentication, asks a user to prove who they are with more than just a password. They may enter a code from an authenticator app, approve a sign-in on their mobile phone, use a security key, or use biometric verification such as a fingerprint.

The aim is straightforward. If a criminal obtains a password through phishing, a data breach or password reuse, they should still be unable to sign in without the second factor.

There is no single UK law stating that every business must use MFA for every system. However, MFA requirements increasingly come from several directions: cyber insurance conditions, client contracts, industry standards, data protection responsibilities and the security controls built into cloud platforms. Microsoft, for example, has continued to strengthen default MFA expectations for administrative access and many business tenants.

For an SME handling client information, payment details or confidential documents, the question is usually not whether MFA is worthwhile. It is where it should be applied first, which method is suitable, and how to keep the process manageable.

Where should your MFA policy apply?

Start with accounts that could cause the greatest disruption if compromised. Email is the obvious priority. A compromised mailbox can be used to reset passwords elsewhere, send convincing fraudulent invoices, intercept conversations and access years of sensitive correspondence.

Microsoft 365 accounts should therefore be protected with MFA, including Outlook, Teams, SharePoint, OneDrive and the Microsoft administration portal. The same applies to any cloud accounting platform, payroll system, CRM, remote access service, document management platform and password manager.

Administrative accounts deserve additional attention. Global administrators, Azure administrators, backup administrators and users able to create accounts or change security settings are high-value targets. These accounts should not be used for routine email and office work. Give authorised IT staff a separate, named admin account with stronger controls and only use it when administrative work is required.

Remote access is another common weakness. If staff can connect to company systems from home or while travelling, MFA should protect that access. A VPN protected by a password alone is no longer a sensible position for most businesses.

A practical policy normally includes the following controls:

  • MFA for every user accessing Microsoft 365 and other business-critical cloud services.
  • Stronger methods, such as authenticator app approval or security keys, for administrators and finance users.
  • MFA for remote access, privileged systems and external support tools.
  • A documented process for joiners, leavers, lost devices and emergency account recovery.
  • Regular reviews of accounts, MFA registrations and exceptions.

The exact scope depends on your systems and risk profile. A small charity using Microsoft 365 and cloud bookkeeping has different needs from a solicitors’ practice managing highly sensitive case files. Both, however, need to protect the accounts that could expose data or stop the organisation operating.

Choosing the right MFA method

Not all MFA methods offer the same level of protection. Text-message codes are better than a password alone, but they can be vulnerable to SIM-swapping and social engineering. They are best treated as a fallback rather than the preferred method.

Authenticator apps are usually the sensible starting point for SMEs. They are widely supported, straightforward for staff to use and do not rely on mobile signal. Number matching, where the user enters a number shown on the sign-in screen into their app, provides a useful defence against accidental approval of fraudulent prompts.

For users with privileged access, security keys can provide a higher level of assurance. These small physical devices are particularly useful for administrators, finance teams and senior staff who may be targeted by phishing attacks. They carry a cost and need a process for replacement, but that trade-off is often justified for the most sensitive accounts.

Biometric sign-in and passkeys are also becoming more common. They can improve both security and convenience because users do not have to type passwords or receive codes. Whether they are appropriate depends on the applications you use and the devices your staff have available.

The best method is one that is secure enough for the account, supported by your systems and practical for your people. A policy that staff repeatedly work around is not a security control.

Making MFA work for staff

The technical setup is only part of the job. MFA changes a familiar sign-in process, and people need to understand why they are being asked to use it. A short, plain-English briefing is more effective than sending a policy document and hoping for the best.

Explain that no legitimate colleague, IT provider or bank will ask them to approve an unexpected sign-in request. If a notification appears when they are not logging in, they should reject it and report it. This is vital because criminals increasingly use MFA fatigue attacks, repeatedly sending prompts in the hope that somebody approves one just to make them stop.

Plan enrolment carefully. Staff need enough notice to install an authenticator app, register a second method and ask for help if their mobile phone is unsuitable. Not every employee has a company mobile, and a business should not assume that using a personal device is acceptable without considering its own policies and workforce circumstances.

Where personal mobile phones are not appropriate, alternatives may include a company device, a hardware security key or another approved authentication method. The right answer is not always identical for every role.

Avoid the common gaps

Many businesses enable MFA and assume the work is complete. The gaps tend to appear later, often when someone leaves, changes phone or needs urgent access during an incident.

Avoid shared logins wherever possible. A shared account means no clear audit trail and creates problems when one person leaves or loses a device. Use named accounts, then provide access through suitable permissions or delegated mailboxes.

Keep at least two carefully controlled emergency access accounts for Microsoft 365 and similar critical platforms. These are not everyday accounts. They should have very long, unique passwords, be monitored closely, and only be used if the normal MFA process or identity service is unavailable. Without this planning, an MFA issue can leave everyone locked out, including the people trying to fix it.

Also review legacy applications and devices. Older email clients, multifunction printers and line-of-business systems may not support modern authentication. Do not leave them using weak sign-in methods indefinitely because replacing them feels inconvenient. Assess whether they can be updated, reconfigured or replaced, and limit their permissions while that work is underway.

MFA requirements and compliance

For organisations subject to compliance expectations, MFA supports more than cyber security. It helps demonstrate that access to personal and confidential data is controlled. That matters to accountants, solicitors, charities, healthcare-related organisations and any business asked security questions by larger customers.

MFA alone will not make an organisation compliant with GDPR, Cyber Essentials or a client security standard. You also need sensible access controls, patching, backups, staff awareness, incident procedures and evidence that controls are being maintained. But password-only access to important systems is increasingly difficult to defend if an incident occurs.

Cyber insurers may specify MFA as a condition of cover, particularly for email, remote access and administrator accounts. Read the wording rather than relying on assumptions. Some policies expect MFA across all remote access; others require particular controls for privileged users. If a requirement is unclear, clarify it before a claim situation arises.

A practical rollout plan

A good MFA rollout should reduce risk without creating an unnecessary Monday-morning support queue. Begin with an audit of users, applications, administrator accounts and current sign-in methods. Identify high-risk services first, especially Microsoft 365, remote access and finance platforms.

Next, choose approved authentication methods and document any legitimate exceptions. Set a timetable for staff enrolment, communicate it clearly and make support available during the change. After rollout, review sign-in logs, unsuccessful attempts and accounts that have not registered a second factor.

Finally, test the less obvious scenarios: a lost phone, a new starter on their first day, an employee leaving unexpectedly, a director travelling abroad, and an emergency administrator needing access. Those tests reveal whether the process works in real life rather than just in a settings screen.

At Keyhole IT Solutions, we help businesses put practical Microsoft 365 security controls in place without burying people in jargon. The goal is simple: protect the accounts your business depends on while keeping staff productive and supported.

MFA is most effective when it is treated as part of everyday IT housekeeping, not a one-off compliance exercise. Review it as your people, devices and systems change, and it will continue to do the job it was designed for: stopping one stolen password from becoming a business-wide problem.

Tags :
Share :