How to Set Up Multi-factor Authentication for Your Business
In our last post, we explained what multi-factor authentication (MFA) is. Essentially, MFA refers to multiple checkpoints that users must get through when logging into a system. We dug into the four types of factors there are as well as the benefits of using MFA within your business.
Now it’s time to talk about the practical applications of MFA.
First, we’re going to look at examples of where and when you can implement MFA. Then, we’ll discuss how to set it up as well as the best multi-factor authenticator apps you and your team can use to secure access from inside or outside the office.
Where and When Should You Use MFA in Your Business?
As a business owner or IT manager, you ultimately get the last say when it comes to where you require MFA. Here are some places where businesses have data and communications that need securing:
- Company email
- Slack or whatever private messaging app you use
- Cloud storage
- Website hosting and management
- Company intranet
- Employee records and management systems
- Customer relationship management (CRM) apps
- Company apps (like for scheduling appointments and messaging customers)
- Anything financial (e.g. payment processing apps or invoicing systems)
- Customer support portals
This list isn’t exhaustive by any means. In heavily regulated environments and niche industries, there will be other types of software you use that are chock-full of data. So add to this list as needed.
How to Set Up MFA to Protect Your Business
According to the Cybersecurity & Infrastructure Security Agency (CISA), MFA significantly improves your odds. Those that use it are 99% less likely to experience a security breach.
Here is what you need to do to set up MFA in your business:
1. Take an Inventory of Your Systems
To start, take an inventory of all the systems you use that require a login.
For each, decide if MFA is necessary. For those where it is, choose the types of methods (Knowledge, Possession, Inherence, or Contextual) that will be most suitable for securing them.
Next, rate how sensitive the data is that sits behind each system. Using these ratings, rank your systems in terms of highest and lowest risk.
2. Take an Inventory of Your Devices
Next, take an inventory of all company-owned devices that you and your team members use. If employees are allowed to access the network through their own remote desktops or phones, make note of them as well.
Any device that connects to your business and data should be secured. While two factors might seem excessive for opening a computer or phone, requiring a stronger authentication layer is a good idea. For instance, you might require users to input a lengthy PIN access code or do a biometric scan to open their devices.
3. Set User Requirements Based on Access/Role
Multi-factor authentication isn’t always necessary for every user. At the same time, some users should be required to input more than two factors of authentication.
So, before you begin implementing your MFA plans, come up with a set of rules.
For each system/application, list all the types of user roles (e.g. Administrator, Editor, Customer, etc.). Note which level of authentication is required for each role for each system (e.g. password only, 2FA, MFA).
Administrators and other users with deep access to your most sensitive data should have the strictest MFA rules enforced.
4. Decide Which Multi-factor Authentication Solutions You’ll Use
You have a couple options here.
You could go through each application your company uses and enforce MFA and whatever other security settings are available on a case-by-case basis.
This process may get tedious to set up depending on how many sensitive applications you and your employees use. What’s more, it can lead to a lot of friction for your team if they end up having to employ different types of MFA as they move from app to app.
Another option is to find an MFA solution that provides more robust and consistent coverage for your organization. For this, you’ll need a solution that adds MFA at the device and/or desktop level. Here are some of the best authenticator apps for this:
These authenticator apps are great for enterprise-grade security at the highest level. If you’re looking for free authenticator apps you can use to secure individual applications and accounts, then look at Google Authenticator and Microsoft Authenticator.
5. Schedule a Time to Roll Out the New MFA Setup
If you’re going to take the piecemeal approach to implementing MFA, use the info you gathered in the earlier steps to schedule the MFA setup for your more critical applications and users first.
Your team is likely going to need some time to adjust to these changes, so it’s best to roll out your MFA setup bit by bit. This will ensure that the new security checkpoints work as they should and aren’t creating undue friction for your team.
Now, if you’re planning to set up MFA at a device or desktop level, you might not have much else to roll out. However, you should start with the following people:
- Administrators who oversee user access
- Other users who handle sensitive and mission-critical data
- Any executives who are likely to be targeted by hackers
Essentially, the rollout should prioritize the areas and users most in need of MFA first. You can then complete the process once things are moving along smoothly with the priority areas.
6. Train Your Team
Although multi-factor authentication is relatively common these days, your team members should still be onboarded to the new process.
The training should explain what MFA is and why it’s mandatory for certain users, applications, and scenarios (like remote work setups). The session should also offer a step-by-step explanation of how the new authenticator solutions work.
Your IT staff should be available for hands-on or remote assistance to ensure everyone gets the hang of the new process. They should also make self-help resources available for employees if they encounter issues and aren’t able to get in touch with IT support right away.
It’s also not a bad idea to record this initial training session, so employees can watch the replay if they get stuck during setup. You can also share it with new employees during onboarding.
7. Schedule Regular MFA Updates (As Needed)
Some MFA methods won’t need updating, like authenticator apps and biometric scans. However, employees should be required to regularly update other factors like:
- Passwords
- PINs
- Security question answers
In many applications and multi-factor authentication solutions, your administrator can manage this. They can either set an automatic reminder for employees to make these updates (every three to six months is best) or they can enforce the change the next time anyone tries to log in.
If you find that this process frustrates employees, consider changing your factors to stronger ones that don’t require updates (like biometric scans and security keys).
8. Monitor Your Process
Every six months or so, evaluate how things are going.
For starters, have your employees adjusted well to the process? IT should be able to give you some insights into what’s changed. For instance, if they notice more tech support requests related to login failures, this could be a sign that your staff needs more training or that the MFA methods need to be reevaluated.
Also, check with IT to see if there have been any changes regarding security threats. It’s not just the number of security breaches that should have gone down. Also look for a decline in failed authentication requests. If hackers have a harder time breaking through the initial layers of security, then that means your MFA setup is working.
Reinforce MFA with a Strong Security Policy
Multi-factor authentication will help lock down your login checkpoints. However, that’s not the only way in which hackers are able to break into a system.
Make sure that cybersecurity is a top priority across your organization. If you haven’t yet, download this free 58-point cybersecurity checklist and make sure your business is covered.
Recent Posts
Subscribe for More Content
Are you a business owner or IT manager looking to optimize your company’s IT systems? Subscribe for more useful tips and insights.