Boost Microsoft 365 Security: Turn on Multi-Factor Authentication

▶ Watch the short explainer for this tip
Every Australian small business owner running Microsoft 365 needs to consider multi-factor authentication (MFA). It's one of the most effective ways to protect your accounts from unauthorised access. This simple security setting adds a vital layer of protection beyond just a password, making it much harder for cyber criminals to compromise your business's data.
What is Multi-Factor Authentication (MFA)?
Multi-factor authentication (MFA) requires users to provide at least two pieces of evidence to verify their identity before gaining access to an account or application. This usually means something you know (like a password) and something you have (like a phone or hardware token).
Why is MFA Critical for Email Security?
MFA is critical because it dramatically reduces the risk of unauthorised account access, even if your password is stolen or guessed. Most cyber attacks, especially business email compromise (BEC) scams, rely on gaining access to user accounts. By implementing MFA, you make it significantly harder for attackers to log in, protecting your emails and sensitive information.
What Happens if You Don't Enable MFA?
Leaving MFA disabled exposes your business to a higher risk of account compromise, leading to potential financial losses, data breaches, and reputational damage. Without MFA, a simple password leak could result in an attacker gaining full access to your Microsoft 365 environment, potentially leading to notifiable data breaches (NDBs) under Australian privacy law, costly downtime, and even impacting your cyber insurance coverage.
How to Turn on MFA for Your Microsoft 365 Users
You can enable multi-factor authentication for all your Microsoft 365 users through the Microsoft Entra admin centre. Here are the steps: 1. Sign in to entra.microsoft.com as a Global Administrator. 2. Go to Protection > Conditional Access > Policies and select New policy (or enable Security defaults under Entra ID > Overview > Properties for the simple option). 3. Under Users select All users and exclude one break-glass admin account; under Target resources select All cloud apps. 4. Under Grant select Require multifactor authentication, set Enable policy to Report-only first, review sign-in logs, then switch it to On.
Confirming MFA is Active and What to Watch For
After implementing, you can check that it worked by going to Protection > Authentication methods > User registration details and confirming every active user is MFA-capable. Be aware that shared mailboxes, service accounts, and unattended scripts need review before enforcement, as they might break. Always ensure you have a documented break-glass account excluded from MFA for emergency access, and warn staff about the upcoming change.
Important Disclaimer
These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement. If you'd like an expert to assess your Microsoft 365 security, you can book a complimentary 15-minute chat with Neil about an audit to help secure your business.
Enabling multi-factor authentication for all Microsoft 365 users is a non-negotiable security measure for any Australian small business. It's a foundational step that protects your email, data, and reputation from common cyber threats. For a thorough review of your current setup, book a complimentary 15-minute chat with Neil about a Microsoft 365 security audit.
Disclaimer: These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Frequently asked questions
- What is multi-factor authentication (MFA) and why do I need it for my Microsoft 365?
- Multi-factor authentication (MFA) adds an extra layer of security beyond just a password, typically requiring something you know and something you have. You need it for Microsoft 365 to significantly reduce the risk of unauthorised access to your business emails and data, even if passwords are stolen.
- Will enabling MFA disrupt my business operations in Australia?
- Enabling MFA may cause minor initial disruption as users adapt to the new login process, but the security benefits far outweigh these. It's crucial to plan, warn staff, and address specific accounts like shared mailboxes and service accounts to minimise issues.
- Is MFA required by Australian cyber security regulations for small businesses?
- While not always explicitly mandated by law for all small businesses, MFA is a core recommendation from the Australian Cyber Security Centre (ACSC) for robust cyber security. It helps businesses meet their obligations under privacy laws to protect personal information and is often a requirement for cyber insurance policies.
- What is a 'break-glass' account and why do I need one for my Microsoft 365 MFA policy?
- A 'break-glass' account is a highly privileged administrative account specifically excluded from MFA policies and other conditional access rules. You need one as an emergency backup to regain access to your Microsoft 365 environment if your primary administrator accounts become locked out or MFA systems fail, ensuring you're never completely locked out.
- How can I check if all my active Microsoft 365 users are MFA-capable after implementing the policy?
- You can check by going to the Microsoft Entra admin centre (entra.microsoft.com), then navigating to Protection > Authentication methods > User registration details. This report will show if every active user has successfully registered for multi-factor authentication.
Sources
Every reference below was link-checked when this article was published.
- 1.What is Conditional Access?Microsoft Learn
- 2.Security defaults in Microsoft Entra IDMicrosoft Learn
- 3.Microsoft Defender for Office 365 security recommendationsMicrosoft Learn
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


