Article

MFA Your Staff Will Not Try to Dodge

·By Mathew Chewing

Strong authentication fails when it is annoying enough to route around. Here is how to get phishing-resistant MFA across your business without a helpdesk revolt.

5 Ways to Balance User Productivity with Solid Authentication Protocols

Every security control has a hidden failure mode: staff working around it. Not out of malice, out of friction. If signing in costs ninety seconds and eleven taps, someone will find the shortcut — and the shortcut is always less secure than the thing you installed.

So the goal is not maximum authentication. It is the strongest control people will tolerate without inventing a bypass. Those are different targets, and only one of them is achievable.

First: not all MFA is equal

The phrase "we have MFA" hides an enormous range of actual protection. Ranked weakest to strongest:

  • SMS codes. Better than nothing, and genuinely vulnerable. In a SIM-swap, an attacker convinces a telco to port your number to their SIM and starts receiving your codes. Australian carriers have tightened the process, but it still happens.
  • App-generated codes (TOTP). The six digits that rotate every 30 seconds. No SIM to steal, but entirely phishable — a fake login page asks for the code and relays it to the real site inside the window.
  • Push notifications. Tap approve on your phone. Convenient, and vulnerable to MFA fatigue: the attacker has your password and sends approval requests at 2am until you tap one to make it stop.
  • Number matching. The screen shows a two-digit number you must type into the app. This kills MFA fatigue outright, because a half-asleep tap no longer works. Low effort, big gain.
  • Phishing-resistant — passkeys, FIDO2 keys, Windows Hello. The credential is cryptographically bound to the real domain, so a fake login page cannot use it. The browser simply will not offer it to the wrong site. This is the only tier that stops a competent phishing attack.

If you do one thing after reading this, turn on number matching. It is a toggle, it takes minutes, and it removes the single most common way real accounts get taken over.

1. Stop challenging people when nothing has changed

The biggest source of authentication resentment is being challenged repeatedly from the same laptop, in the same office, on the same morning. It teaches staff that the prompt is noise, and people click through noise without reading it.

Conditional access makes the challenge proportional to risk. Known device, known location, normal hours: sign in and get on with it. Unfamiliar device, impossible travel, a sign-in from overseas forty minutes after one in Wyong: challenge hard, or block.

The user experience improves and the security improves at the same time, which is rare enough to be worth the configuration effort.

2. Cut the number of sign-ins, not their strength

A business running fifteen separate logins has staff maintaining fifteen passwords, which means they are reusing three of them. Single sign-on through your Microsoft 365 tenant means one strong, well-protected identity — and one place to revoke everything when someone leaves.

That last point matters more than it sounds. Offboarding with SSO is one action. Offboarding fifteen scattered accounts is fifteen actions, and the one everybody forgets is the one still active two years later.

3. Give them a password manager and end the reuse problem

Complexity rules produced a generation of passwords like Winter2026! — which satisfies every policy and is guessed in seconds. Modern guidance, including the ACSC own, favours length over baroque character rules, and long passphrases only work if people do not have to remember thirty of them.

A business password manager solves the underlying problem. Staff remember one strong passphrase; everything else is generated, unique and long. It also kills credential stuffing: when an unrelated site is breached, the leaked password is not also your Microsoft 365 password.

Pair it with user awareness training so the tool gets used rather than installed and ignored.

4. Protect the accounts that can undo everything else

Standard staff accounts and administrator accounts do not deserve the same treatment. An attacker in a normal mailbox is a problem. An attacker with global admin owns the tenant, including your backups.

Three rules that cost nothing:

  • Admin accounts are separate from daily-driver accounts. Nobody reads email as a global admin.
  • Admin access requires phishing-resistant MFA — a passkey or hardware key, not a code.
  • Privileged roles are granted just-in-time and expire, rather than sitting permanently assigned to six people who each needed them once.

5. Watch for the signals that MFA is being bypassed

Attackers who cannot beat MFA go around it. The two common routes leave clear traces.

Token theft. Malware or an adversary-in-the-middle page steals the session cookie issued after successful authentication. The attacker replays it and never faces a prompt. The tell is a session appearing from a new location or device with no matching sign-in event.

Quiet persistence. Having got in once, the attacker enrols their own MFA method, adds an app password, or sets an inbox rule that forwards anything containing "invoice" to an external address and marks it read. Then they leave, and come back when a real payment is in flight.

Neither is visible unless something is watching. That is the job of managed detection and response — alerting on new MFA enrolments, unfamiliar sign-in patterns and forwarding rules, rather than waiting for a client to ask why your bank details changed.

Where to start on Monday

  1. Turn on number matching. Today.
  2. Find the accounts with no MFA at all — usually shared mailboxes, service accounts, and the director who asked to be exempt.
  3. Move admin accounts to passkeys or hardware keys.
  4. Add conditional access so trusted devices stop being challenged needlessly.
  5. Alert on new MFA methods and external forwarding rules.

Those five steps remove the overwhelming majority of real-world account takeovers, and only one of them makes signing in slower — for the handful of people who can do the most damage.

A cyber security assessment will show which accounts are exposed today, and our cyber security team can stage the rollout so it lands without a helpdesk queue.

Local IT and cyber security support across NSW

Chewing IT runs managed IT and cyber security for small and mid-sized businesses from our Wyong and Hornsby offices, covering the Central Coast, Newcastle, Lake Macquarie and Hornsby.

Want to know which of your accounts are one password away from compromise? Ask us for an MFA gap review.

Want this handled for you?

Chewing IT looks after IT, cloud and cyber security for businesses across the Central Coast, Newcastle and Sydney. Free, no-pressure consultation — no contracts, no jargon.