← Back to all posts

What Is MFA in Cybersecurity? A Simple Guide for Small Businesses

Multifactor authentication, or MFA, verifies identity using two or more different types of evidence. A familiar example is signing in with a password and then entering a code from an authenticator app. If someone steals the password, they still need the additional factor to complete that sign-in.

For a small business, turning on MFA is only part of the work. You also need to know who has enrolled and whether your policies require it. Blue Lantern Security's daily identity scan helps find users without a registered MFA method in Google Workspace and Microsoft Entra, with missing registration on admin accounts treated as a critical finding.

What counts as an authentication factor?

Factors come from different categories:

Factor Meaning Example
Something you know Information you can supply A password
Something you have A device or authenticator you control An authenticator app or security key
Something you are A biometric characteristic A fingerprint used to unlock an authenticator

Two passwords are still the same kind of factor. MFA combines different kinds of evidence, although the experience does not always require two separate prompts. For example, an appropriately configured passkey can use possession of a device and its local PIN or biometric verification. Microsoft's MFA explanation describes the factors and supported authentication methods.

Is MFA the same as 2FA or SSO?

Two-factor authentication, or 2FA, is MFA using exactly two factors. Google Workspace calls its additional sign-in protection 2-Step Verification.

Single sign-on, or SSO, lets a user sign in through one identity provider to access connected applications. MFA strengthens authentication; SSO connects that sign-in to other services. A business can use both. They sit within the wider discipline of identity and access management.

Which MFA method should a small business use?

Prefer phishing-resistant options such as supported passkeys or security keys where your services and devices allow them. Unlike a one-time code that someone can enter into a fraudulent page, these methods are designed to authenticate to the legitimate service. Google's 2-Step Verification deployment guide explains its passkey and security-key options alongside enrollment and recovery considerations.

An authenticator app can be a practical step where stronger options are not yet available. However, a code can still be phished, and a user can mistakenly approve a sign-in request. Train staff to reject unexpected prompts and report them. For an example of checking a suspicious message before acting, see our email report walkthrough.

Choose a method your team can use reliably and support it with a recovery process. MFA reduces the risk from stolen passwords; it does not replace access review, secure devices, or investigation of suspicious activity.

Registered, enforced, and used: three different questions

A business can have strong-looking enrollment numbers and still need to examine its policies. For example, an employee in Microsoft Entra might have registered an authenticator, but an MFA policy scoped only to administrators would not require that employee to use it. These three checks establish different things:

Question Evidence to review What it does not establish
Has the user registered a method? Registration or enrollment status Whether a policy requires the method for the access you care about
Is MFA required for that access? Applicable sign-in policies, scope, and exceptions Whether a particular sign-in satisfied the requirement
Was MFA satisfied for a particular sign-in? Relevant sign-in or authentication records That every other user, application, or sign-in is covered

Microsoft separates registration and usage in its authentication-method activity reports. Registration should therefore be treated as one piece of the review, alongside policy and sign-in evidence.

Also, a missing fresh prompt does not by itself prove MFA was bypassed. A valid session or supported passwordless method may satisfy the requirement. Check the relevant records rather than judging coverage by how often a user sees a code box.

What does a coverage percentage tell you?

Suppose an illustrative report shows that 19 of 20 directory users have a method registered. That is 95% registration coverage. It tells you to investigate the remaining account, especially if it has admin privileges. It does not mean that 95% of sign-ins were protected or that all 19 registered users fall under the intended enforcement policy.

Keep the denominator and the observation clear: which users were checked, what status was measured, and when the check succeeded.

For the provider-specific steps, use the guide to checking MFA coverage in Google Workspace and Microsoft 365.

How Blue Lantern Security helps find MFA gaps

Blue Lantern Security checks the connected Google Workspace or Microsoft Entra directory once daily when the optional identity posture scan is enabled. It reports users without MFA registration and prioritizes administrators without a registered method.

To start:

  1. Open the settings for your Gmail or Outlook organization integration.
  2. Enable the daily identity posture scan and complete any required permission steps.
  3. Review the latest successful result in the Monitoring Hub under the Identity type.
  4. Use the MFA or administrator filter to focus the review, then assign follow-up to the person who manages those accounts.

The scan examines the connected directory, including users whose mailboxes are not monitored. For Microsoft 365, the optional identity checks require AuditLog.Read.All with admin consent. The Google identity check uses the existing directory scope. See the identity monitoring setup guide for the full integration requirements.

The same scan also reviews dormant accounts; Microsoft's dormancy check has an additional Entra ID P1/P2 requirement. Keep that separate from what an MFA registration finding means.

Blue Lantern Security reports registration gaps. Your administrator manages enrollment and enforcement in Google Workspace or Microsoft Entra. After making a change, review the next successful daily result and its timestamp; available provider data can affect when the update appears.

A manageable MFA rollout

Start with administrator accounts and the services that hold important business information, then expand coverage across the organization. For each group:

  1. Choose supported methods. Prefer phishing-resistant methods and account for the devices people actually use.
  2. Prepare recovery. Give users a way to recover from a lost device without turning recovery into an easy way around the control.
  3. Enroll and test. Confirm people can sign in before changing the policy for the wider group.
  4. Require the protection. Review the policy's users, applications, and exceptions. Give any necessary exception an owner and a review date.
  5. Check coverage again. Review new starters, failed enrollment, policy changes, and unusual sign-ins as part of ongoing administration.

Begin with a question you can act on today: which of your users, particularly administrators, still lack MFA registration? Blue Lantern Security's identity checks help you find those accounts so your administrator can address enrollment and verify the enforcement that should follow it.