Multi-factor authentication: rolling out MFA properly
Which factors to use, which to avoid, how to handle exceptions, and how to roll out without a help desk pile-up.
By the Telappliant team

Multi-factor authentication is the highest-value control most organisations can deploy, and the one most often left partially finished. Partial MFA is the problem: attackers simply find the account or the protocol that was missed.
Not all factors are equal
- Phishing-resistant: FIDO2 security keys and passkeys, plus certificate-based authentication
- Strong: authenticator app with number matching and push fatigue protection
- Weaker: one-time codes by app without number matching
- Avoid where possible: SMS and voice codes, which are vulnerable to SIM swap and interception
Close the gaps that make it pointless
- Block legacy authentication protocols, which bypass MFA completely
- Cover VPN, remote desktop and any third-party portal, not just email
- Include administrators, service accounts with interactive logins, and contractors
- Remove weak fallback methods once stronger ones are enrolled
Roll out without a help desk pile-up
Pilot with IT, then the leadership team, then department by department. Publish a one-page guide with screenshots, run enrolment during a working day rather than a Friday, and staff the help desk for the first two mornings. Enforce with conditional access after the enrolment window, not before.
Handle exceptions honestly
Shared devices, shop floors and clinical areas need a designed answer: shared FIDO2 keys held physically, kiosk sign-in, or device-bound trust. An open-ended exemption list is how MFA quietly stops covering the accounts that matter.
Break-glass accounts
Keep two cloud-only emergency administrator accounts excluded from conditional access, with long unique passwords held in a safe, alerting on any use, and reviewed quarterly. Without them a policy mistake can lock everyone out of the tenant.
What good looks like
- 100 percent of internet-facing accounts enforced, evidenced by report
- Legacy authentication blocked tenant-wide
- Number matching on, SMS retired as a primary method
- Alerting on MFA method changes and failed challenge storms



