MFA can block 100% of automated bots, 96% of phishing attacks, and 76% of targeted attacks, according to Get Cyber Safe guidance from the Government of Canada. That makes multi factor authentication setup one of the most practical security improvements available to a household, home office, or small business.
Passwords still matter, but a password alone gives an attacker one barrier to defeat. MFA adds another factor, such as an authenticator app, passkey, security key, or phone verification. The value comes from choosing the right method, applying it consistently, and planning recovery before someone loses a phone or gets locked out.
Table of Contents
- Why Multi Factor Authentication Setup Is Essential
- Choosing the Right Authentication Methods
- Platform-Specific Setup Instructions
- Recovery Planning and Preventing Lockouts
- Developing a Security Policy for Small Business
- Troubleshooting Common MFA Challenges
Why Multi Factor Authentication Setup Is Essential
MFA can block 100% of automated bots, 96% of phishing attacks, and 76% of targeted attacks, according to Canadian public guidance cited earlier. Those results show why multi factor authentication setup belongs near the top of any security plan, especially for email, cloud services, financial systems, and administrator accounts.
A stolen password can give an attacker access to email, cloud storage, financial services, remote access tools, and privileged accounts. Password reuse increases the exposure because criminals may test credentials from one breach against unrelated services. MFA changes the sign-in requirement by asking for proof that the user also controls another device, credential, or physical key.
Federal deployment guidance separately cites a Microsoft study stating that MFA can block 99.9% of account compromises. No MFA configuration provides equal protection, but the finding supports treating MFA as a baseline control rather than an optional feature.

What passwords cannot handle
A password cannot distinguish a legitimate employee from a criminal who has obtained the same credential. If a user enters it on a convincing fake Microsoft 365 or Google sign-in page, the attacker may receive exactly what they need. MFA can interrupt that sequence, particularly when the second factor resists phishing.
Authenticator prompts and one-time codes improve protection over a password alone, but users must still inspect unexpected requests. Repeated fraudulent approval prompts can pressure someone into accepting one. Passkeys and security keys offer stronger protection because they verify the intended website during sign-in.
Practical rule: Turn on MFA first for email, administrator accounts, cloud storage, financial access, remote access, and services containing sensitive information.
For an Edmonton household, the priority list may include personal email, Apple ID, banking access, and cloud backups. A small business should usually start with Microsoft 365 or Google Workspace, accounting software, file-sharing services, remote-management tools, and every administrator identity.
Canada's standard is becoming more specific
Federal cloud-authentication guidance requires strong MFA for privileged or enhanced-access accounts, users accessing systems with an assurance level requirement of 3 or higher, and users of remote access solutions. It also calls for phishing-resistant MFA for cloud solutions, third-party services handling sensitive data, privileged actions, and remote administration. Departments are directed to disable weaker fallback methods such as SMS and email MFA. These requirements appear in the Government of Canada's cloud authentication guideline.
This federal approach gives Canadian businesses a useful benchmark when adopting cloud software, supporting remote work, or handling client information. A proper setup is more than adding a code after the password. It should address phishing resistance, least privilege, secure recovery, and protection of sensitive workloads.
Small businesses should also document who can approve sign-ins, which accounts require stronger factors, and how access will be restored after a lost phone or security key. Recovery planning matters because an account that cannot be recovered can interrupt payroll, customer service, or administration.
For a practical explanation of the model, read what multi-factor authentication means. The decision is no longer whether to use MFA. It is how broadly to deploy it and how carefully to configure its factors and recovery process.
Choosing the Right Authentication Methods
Not every second factor provides the same protection. SMS is familiar and easy to deploy, while authenticator apps are usually a better everyday choice. Passkeys and FIDO2 security keys provide the strongest protection against many phishing techniques, but they require more planning and user support.
| Method | Security Level | Convenience | Best For |
|---|---|---|---|
| SMS verification | Lower, suitable mainly for low-risk access | Familiar and widely available | Temporary fallback or low-risk accounts |
| Authenticator app | Stronger than SMS, but codes and prompts can still be targeted | Convenient on a phone | Most personal accounts and small offices |
| Passkey | Phishing-resistant when supported by the service and device | Fast after initial enrolment | High-value accounts and users with compatible devices |
| FIDO2 security key | Strong phishing resistance and independent physical proof | Requires carrying and protecting the key | Administrators, remote access, and sensitive systems |
| Smartcard or hardware-based MFA | Strong, with more administration involved | Less convenient for casual users | Controlled business and government environments |
Federal guidance says SMS codes should be treated as a weak option and considered only for low-risk logins. For stronger protection, the Canadian Centre for Cyber Security recommends authenticator apps, security keys, or smartcards, and notes that hardware-based MFA should be independent of the device being authenticated. The federal MFA deployment guidance explains that distinction clearly.
SMS is convenient, not ideal
SMS can help a user get started, especially when an account supports few alternatives. It's better than relying on a password alone, but a phone number can be targeted through social engineering or number-transfer fraud. SMS also depends on mobile service, which creates problems during travel, in weak coverage areas, or after a number change.
Don't make SMS the only recovery path for an administrator or a service containing sensitive information. If a provider offers an authenticator app or passkey, choose that as the primary method and keep SMS only as a carefully controlled fallback, if it must remain available.
Apps balance protection and usability
Authenticator apps generate temporary codes or deliver approval prompts. They work well for most home users and small offices because they don't depend entirely on text-message delivery. The weakness is operational. A lost phone, failed migration, or careless approval can still create an access or security problem.
Use number matching or other anti-fatigue controls when a service provides them, and deny unexpected prompts. For critical accounts, enrol a second approved method before removing the first one.
Passkeys and security keys change the threat model
The Canadian Centre for Cyber Security's guidance on social-engineering-enabled compromise recommends phishing-resistant MFA such as FIDO2 security keys or passkeys. These methods are designed to resist adversary-in-the-middle phishing and code-relay attacks that can defeat weaker methods.
A passkey is often the smoothest option for users with modern devices. A FIDO2 key is especially useful for administrators because it provides a physical object that can be kept separate from the computer being used. The trade-off is straightforward: purchase, enrolment, replacement, and spare-key procedures require attention. For a high-value account, that effort is usually justified.
Platform-Specific Setup Instructions
The menu names can change slightly as vendors update their interfaces, but the setup pattern remains consistent. Start with an account you control, confirm that the phone or security key is available, enrol the primary factor, add recovery options, and test a fresh sign-in before closing the settings page.

Microsoft 365
For a business using Microsoft 365, an administrator should begin in the Microsoft Entra admin centre.
- Open Protection or the relevant identity-protection area, then review authentication methods and security defaults or conditional-access policies.
- Confirm that the organisation requires MFA for users, with stronger requirements for administrators and remote access.
- In Users, select an account and review its authentication methods. Add Microsoft Authenticator, a passkey, or a security key according to the organisation's policy.
- Ask the user to complete registration at the Microsoft security-info page during sign-in.
- Test a normal browser sign-in and a remote-access sign-in. Verify that the user can deny an unexpected prompt and report it.
A conditional-access policy can apply stronger requirements based on the application, device, location, or risk. Avoid creating a policy that blocks every user before an administrator has tested an emergency access process. Administrative identities should have separately protected recovery arrangements, not a shared password passed between staff.
For compatible Windows devices, Windows Hello setup can complement the wider identity plan by using device-based sign-in. It shouldn't replace account governance, but it can improve the daily experience when configured properly.
Google Workspace
In the Google Admin console, open Security, then Authentication, and review 2-Step Verification. Set the enforcement scope carefully, starting with a pilot group if the organisation has never required MFA.
- Choose the organisational unit or group that should receive the policy.
- Require 2-Step Verification and set an enrolment period that gives users time to register.
- Encourage Google Authenticator, passkeys, or security keys for higher-risk users.
- Review recovery settings and administrator privileges before enforcement.
- Test sign-in from a normal device and confirm that staff know how to report suspicious prompts.
Google Workspace administrators should also review super-admin accounts separately. A compromised super-admin identity can affect the entire tenant, so those accounts deserve phishing-resistant methods and tightly controlled recovery.
Apple ID
On an iPhone or iPad, open Settings, select your name, then Sign-In & Security, and choose Two-Factor Authentication. On a Mac, open System Settings, select your Apple Account, choose Sign-In & Security, and follow the same option.
Add trusted phone information, verify the prompt, and review the trusted devices shown on the account. Remove devices that no longer belong to you, but don't remove your only working device until another trusted method is ready. Apple ID protection matters because it can control backups, purchases, device access, and personal data.
Before enforcing MFA: Test registration, normal sign-in, recovery, and device replacement with one account. A policy that works only on paper will create pressure for unsafe bypasses.
Recovery Planning and Preventing Lockouts
MFA protects the account only if legitimate users can recover access safely. Phones get lost, numbers change, authenticator apps fail to migrate, and employees leave with enrolled devices. A setup that ignores those events encourages rushed support calls, shared codes, and weak identity checks.
Canadian deployment guidance recommends an easy self-reset path when a primary factor is lost or compromised, while also stressing out-of-band verification for identity-related requests and careful device re-enrolment. The Government of Canada's MFA deployment guidance treats recovery as part of the control, not an afterthought.

Build more than one safe path
Use the service's supported recovery options, then document who can approve a reset and how that person verifies the request. A secondary factor should be controlled by the account owner or an authorised administrator, not left in a shared inbox or written on a monitor.
- Backup codes: Generate one-time codes where available and store them in a password manager or another protected location.
- Secondary device: Enrol an approved authenticator or security key before replacing the primary phone.
- Recovery contact: Use a separate, protected recovery email or trusted phone where the service supports it.
- Device replacement: Transfer or re-enrol the authenticator before wiping the old phone.
The CRA sign-in workflow illustrates why multiple enrolled options matter. CRA's MFA instructions support an authenticator app, passcode grid, and phone-based verification, and prompt users to enrol in two MFA options. The practical lesson applies to other accounts as well: don't wait until a phone is missing to discover that it was the only route back in.
Keep recovery harder than the original attack
A help desk reset can become the easiest way into an account. Require an out-of-band check, use a documented approval process, and record factor changes. Never approve a reset solely because someone knows a name, job title, or password.
Recovery is part of MFA security. If attackers can persuade staff to remove the second factor, the login control has a support loophole.
Developing a Security Policy for Small Business
A small business needs an MFA policy because individual choices don't scale. One employee may use an authenticator app, another may rely on SMS, and an administrator may have no recovery plan at all. Consistent rules reduce those gaps without forcing every user into the same hardware or workflow.
Canadian guidance for small organisations describes MFA as a foundational control for all users, systems, applications, and endpoints, not only administrators. The Canadian Centre for Cyber Security's foundational actions for small organisations also defines MFA around at least two distinct authentication factors.
Write a policy people can follow
A useful policy should answer practical questions in plain language:
- Who must enrol: Include every user with access to company email, cloud files, financial services, remote access, or administration.
- Which methods are preferred: Require phishing-resistant methods for privileged access and sensitive systems. Permit authenticator apps for ordinary accounts where appropriate.
- What happens during onboarding: Enrol the user before granting access, then confirm that recovery works.
- What happens during offboarding: Disable the account, revoke active sessions, remove devices, and transfer business data.
- Who approves resets: Name a responsible person and define the verification steps.
- How exceptions expire: Document the reason, owner, and review point instead of allowing a permanent bypass.
Identity management also covers lifecycle controls, access reviews, and the relationship between authentication and employee changes. For a broader perspective, these DynamicsHub identity management insights provide useful context for connecting MFA with wider account governance.
Apply stronger controls where the risk is higher
Not every account needs identical friction. A staff member reading internal announcements has a different exposure than someone approving payments, exporting customer data, or managing the Microsoft 365 tenant. The policy should reserve the strongest factors and most restrictive recovery procedures for privileged actions, remote administration, and sensitive workloads.
A small business can start with an inventory of accounts and applications, then mark each one as standard, sensitive, or privileged. That classification gives the owner a rational basis for choosing an authenticator app, passkey, or security key rather than making ad hoc decisions.
Ongoing IT support for small businesses can help maintain the practical side of that policy, including account changes, network access, device setup, and monitoring. MFA works best when someone checks that the policy continues to match the business.
Troubleshooting Common MFA Challenges
Most MFA failures are configuration or recovery problems, not mysterious technical faults. Start by identifying which factor failed, then use an approved alternative. Don't repeatedly approve prompts or ask an employee to send a code through chat.
Authenticator app codes fail
Check that the phone's date and time are set automatically. If codes still fail, confirm that the account is using the correct entry in the authenticator app, then use a backup method if one is enrolled. Avoid deleting the account entry until access has been restored or an administrator has confirmed a safe re-enrolment path.
SMS codes don't arrive
Check mobile coverage, confirm that the registered number is current, and wait briefly before requesting another code. Repeated requests can create confusion when delayed messages arrive together. Use an authenticator app or security key instead of making SMS the permanent answer for a high-value account.
Travel or device replacement causes trouble
Before travel, test the authenticator app, carry an enrolled security key where appropriate, and store recovery codes securely. Before wiping or replacing a phone, add the new device and complete a test sign-in. If an account is already locked, contact the authorised administrator through a known channel and follow the documented identity-verification process.
Never bypass MFA under pressure. A rushed reset during a suspicious login attempt is exactly the situation in which social engineering succeeds.
Nerds 2 You Edmonton provides on-site computer repair, device setup, email configuration, network support, and security assistance for homes and small businesses. Visit Nerds 2 You Edmonton to arrange practical help with MFA enrolment, recovery planning, and ongoing support.
Contact Nerds 2 You for quality professional service
Experience the difference with our dedicated team of experts ready to assist you. Whether you need immediate support or have questions about our services, we are here to help. Reach out today and let us provide you with the reliable service you deserve. Your satisfaction is our priority and we guarantee a prompt response to all inquiries.
