Telappliant
Cyber Security Guide · 15 August 2026

Multi-factor authentication: rolling out MFA properly

Which factors to use, which to avoid, how to handle exceptions, and how to roll out without a help desk pile-up.

By the Telappliant team

A security key being inserted into a laptop beside an authentication prompt

Multi-factor authentication is the highest-value control most organisations can deploy, and the one most often left partially finished. Partial MFA is the problem: attackers simply find the account or the protocol that was missed.

Not all factors are equal

  • Phishing-resistant: FIDO2 security keys and passkeys, plus certificate-based authentication
  • Strong: authenticator app with number matching and push fatigue protection
  • Weaker: one-time codes by app without number matching
  • Avoid where possible: SMS and voice codes, which are vulnerable to SIM swap and interception

Close the gaps that make it pointless

  • Block legacy authentication protocols, which bypass MFA completely
  • Cover VPN, remote desktop and any third-party portal, not just email
  • Include administrators, service accounts with interactive logins, and contractors
  • Remove weak fallback methods once stronger ones are enrolled

Roll out without a help desk pile-up

Pilot with IT, then the leadership team, then department by department. Publish a one-page guide with screenshots, run enrolment during a working day rather than a Friday, and staff the help desk for the first two mornings. Enforce with conditional access after the enrolment window, not before.

Handle exceptions honestly

Shared devices, shop floors and clinical areas need a designed answer: shared FIDO2 keys held physically, kiosk sign-in, or device-bound trust. An open-ended exemption list is how MFA quietly stops covering the accounts that matter.

Break-glass accounts

Keep two cloud-only emergency administrator accounts excluded from conditional access, with long unique passwords held in a safe, alerting on any use, and reviewed quarterly. Without them a policy mistake can lock everyone out of the tenant.

What good looks like

  • 100 percent of internet-facing accounts enforced, evidenced by report
  • Legacy authentication blocked tenant-wide
  • Number matching on, SMS retired as a primary method
  • Alerting on MFA method changes and failed challenge storms

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation