Your Mum Told You to Use Protection, So Why Isn't Your Business?
Every time I sit down with a firm owner and mention multi-factor authentication, I get the same response: “My staff will hate it. They’ll be getting buzzed on their phone every five minutes.”
I get it. That used to be true. Two years ago, MFA meant your phone lighting up constantly. Approve this, approve that, tap here, enter this code. It was annoying. Some of your staff probably turned it off when nobody was looking.
But that world is gone, and the excuse needs to go with it.
The old MFA is dead
Traditional MFA worked like this: every time you opened Outlook, Teams, SharePoint, or anything else, you’d get a push notification. Approve. Open another app. Approve again. Your phone buzzing all day like a needy ex.
Microsoft killed that model. Here’s what replaced it:
Conditional Access with token caching means you authenticate once on a trusted device, and you’re in for the day. No repeated prompts. No buzzing. You open your laptop in the morning, verify once, and get on with your work.
Passwordless authentication takes it further. Windows Hello uses your face or fingerprint. No password to type, no code to enter, no phone to pull out of your pocket. You sit down and you’re in.
Number matching (now mandatory on all Microsoft Authenticator push notifications) eliminated the old “just tap approve” fatigue attacks entirely. If you do get a prompt, you have to type a specific number from your screen, which means you can’t accidentally approve a request you didn’t initiate.
The result: modern MFA is actually less friction than typing a password.
The numbers that should scare you
Microsoft’s own data: 99.9% of compromised accounts had MFA disabled.
Let that sink in. Not 50%. Not 80%. Virtually every single account takeover they see involves an account without MFA.
The WA Auditor General’s review of government entities found 87% had admin accounts without MFA, and 28% of all admin accounts across those organisations were unprotected. The result? Business email compromise cost Australia over $152 million in 2024.
The OAIC’s breach notification statistics tell the same story. In the first half of 2025, 59% of reported breaches were malicious attacks. The top attack vector? Compromised credentials. The kind of attack MFA stops cold.
And here’s one closer to home: an Australian tax agent had their email compromised and a fraudster sent fake data requests to their entire client list. No MFA. No conditional access. Just a password someone guessed or phished.
”But my staff will revolt”
No, they won’t. Because they’re already using MFA everywhere else and they don’t even notice.
Your staff unlock their iPhone with Face ID. That’s biometric MFA. They tap their card at the coffee shop. That’s a hardware token. They log into their banking app with a fingerprint. That’s passwordless auth.
They’re not revolting against MFA. They’re revolting against bad MFA, the kind that interrupts them every twenty minutes. Deploy it properly and they won’t even think about it.
Here’s what “properly” looks like:
- Conditional Access policies that trust compliant, managed devices, so users authenticate once per session, not once per app
- Windows Hello for Business, where face or fingerprint replaces the password entirely
- Microsoft Authenticator with number matching, for the rare occasions a prompt is needed
- Trusted network locations, so your office network doesn’t trigger additional prompts
A user’s typical day: sit down, face scan or fingerprint, work all day without a single authentication prompt. That’s it.
What happens when you don’t
The FIIG Securities case is instructive. No MFA for remote access was one of the findings that led to a $2.5 million Federal Court penalty. The court didn’t buy “we didn’t get around to it” as a defence.
Your professional obligations are explicit:
- Accountants: APES 325 requires risk management covering IT security. The TPB’s Code of Professional Conduct mandates client data protection. MFA is the baseline control every regulator expects.
- Lawyers: Client confidentiality obligations extend to digital systems. Your law society and your PI insurer both expect MFA. Some insurers are now declining coverage for firms without it.
- Everyone: The Cyber Security Act 2024 introduces mandatory ransomware reporting for businesses over $3 million turnover. When you’re reporting an incident, “we didn’t have MFA” is going to be a very uncomfortable sentence.
The real cost of “too annoying”
Here’s the maths for a 15-person accounting firm:
Doing nothing:
- Average data breach cost in Australia: $4.26 million (IBM 2024)
- OAIC maximum civil penalties: $50 million or 30% of adjusted turnover
- Business email compromise: average loss of $39,000 per incident (ACSC)
- Client trust: unquantifiable, unrecoverable
Doing it properly:
- Microsoft 365 Business Premium (includes Conditional Access, Intune, Defender): already included in every Novaguard managed cyber security plan
- Setup time: half a day for a 15-person firm
- Ongoing user friction: effectively zero
One of these numbers is dramatically bigger than the other.
What you should do this week
- Check your current state. Log into your Microsoft 365 admin centre. Go to Azure AD → Security → Authentication methods. See how many users have MFA registered. If it’s not 100%, you have a problem.
- Kill legacy authentication. POP3, IMAP, SMTP. These protocols bypass MFA entirely. They’re the back door most firms forget to lock. Block them in Conditional Access.
- Enable Conditional Access. This requires Microsoft 365 Business Premium or Entra ID P1 licensing. If you’re on Business Basic or Standard, you’re limited to security defaults. Better than nothing, but not enough.
- Deploy Windows Hello. For firms that want zero daily friction, this is the answer. Biometric login, no passwords, no phone prompts.
- Test it. Have someone try to log in from an unmanaged device, from a new location, from a new browser. Make sure the policies work before you assume they do.
Your mum was right. Protection matters. The good news is that modern protection doesn’t interrupt your day. It just quietly keeps your firm, your clients, and your reputation intact.
If you’re not sure where your authentication setup stands, book a free assessment. We’ll check your M365 tenant and tell you exactly what’s exposed. No sales pitch, just a straight answer.
Want to know where you are actually exposed?
A Cyber Business Review tells you what an attacker would find first and what to fix in what order. Independent, and no switch required.
More on this: Cybersecurity articles · Managed Cybersecurity