22 July 2026

MFA Solutions for Small Business

A blue padlock graphic framed by a yellow target symbol over a hooded hacker silhouette and binary code backdrop

In short: 

  • MFA solutions for small business add a second login step (a code, app approval, or key) on top of a password, closing the gap that password strength alone can’t cover
  • A 12-character password can take 89 million years to brute-force, yet most breaches still happen through stolen or phished credentials, not brute-force guessing
  • From April 2026, Cyber Essentials v3.3 makes MFA mandatory for all in-scope user accounts, with no exemptions — missing even one account is an automatic fail
  • Authenticator apps and hardware keys are the strongest options; SMS codes are accepted but not recommended due to SIM-swap risk
  • The right MFA solution balances security with usability — badly implemented MFA gets bypassed or ignored by staff
  • Microsoft is retiring SMS-based MFA for Microsoft 365 entirely from February 2027. A good moment to move to an authenticator app now rather than later

A password made of numbers, upper and lowercase letters, and symbols would take a hacker roughly 89 million years to crack by brute force in 2026, according to research from cybersecurity firm Hive Systems. That sounds like more than enough protection. It isn’t. Most attackers don’t sit around guessing passwords one character at a time. They buy leaked credentials, run phishing campaigns, or reuse passwords stolen from an unrelated breach. That’s exactly the gap MFA solutions for small businesses are built to close.

At Shropshire Computers, we support small businesses across the region with exactly this kind of decision, and lately, we’ve been fielding a lot more questions about it, because Cyber Essentials has just made MFA a requirement, not a recommendation.

What Are MFA Solutions, and How Do They Work?

Multi-factor authentication (MFA) asks for a second piece of proof before letting someone log in. Something beyond just a password.

MFA typically combines two of the following:

  • Something you know — a password or PIN
  • Something you have — a phone, authenticator app, or hardware key
  • Something you are — a fingerprint or face scan

Even if a hacker has your password, they still can’t get in without that second factor. In our experience supporting local businesses through security reviews, this single change consistently blocks the most common way accounts actually get broken into: someone reusing a password that’s already been leaked elsewhere.

If My Password Is Strong, Do I Still Need MFA?

Yes, an 8-character password with only letters can be cracked in about two weeks. A strong, 12-character password with numbers, symbols, and mixed case takes billions of years. But brute force isn’t how most small businesses get breached. Attackers get in through:

  • Phishing emails that trick someone into typing their password into a fake login page
  • Credential stuffing, where passwords leaked in one breach are tried against other accounts
  • Password reuse, where the same password unlocks multiple accounts

None of those care how complex your password is because the attacker already has it. MFA is what stops them at the door anyway.

Why Has Cyber Essentials Made MFA Mandatory in 2026?

Cyber Essentials v3.3, which took effect from 28 April 2026, requires MFA to be enforced on every in-scope user account accessing cloud services and not just administrator accounts, as under the previous version. There are no exemptions.

What Counts as an Acceptable MFA Method?

Assessors accept:

  • Authenticator apps (e.g. Microsoft Authenticator, Google Authenticator)
  • Hardware security keys
  • Push notifications to a registered device
  • SMS codes are accepted, but not recommended due to SIM-swapping risk

A second password or security question does not count as a second factor.

What Happens If Even One Account Is Missed?

If your business has 12 staff on Microsoft 365 and even one account doesn’t have MFA enforced, that’s an automatic assessment fail. If your Cyber Essentials certification is due for renewal, this is worth checking now rather than at assessment time. See our Cyber Essentials guide for the full certification process.

What Are the Best MFA Solutions for a Small Business?

Authenticator Apps

Free, quick to set up, and widely supported across Microsoft 365, Google Workspace, and most SaaS tools. A solid starting point for most small businesses.

Hardware Security Keys

Physical devices offer the strongest protection against phishing, since they can’t be tricked by a fake login page the way a code can. Better suited to higher-risk roles like finance and admin accounts rather than a full team rollout, given the per-device cost.

SMS and Push Notifications

Simple for staff to use, but Microsoft itself is phasing this out. From February 2027, Microsoft is retiring native SMS and voice codes for Microsoft 365 accounts entirely. Anyone still relying on it will be forced to register a passkey to keep signing in. If you’re on SMS-based MFA today, treat this as your migration deadline rather than waiting to be pushed. Push notifications avoid that specific issue but can still suffer from “MFA fatigue” if staff tap approve on autopilot.

How Do You Roll Out MFA Without Disrupting Your Team?

Badly implemented MFA gets resented and worked around; well-implemented MFA barely gets noticed. A few things that make the difference:

  • Start with high-risk accounts like admin and finance first, then roll out company-wide
  • Give staff a grace period to enrol before enforcement kicks in
  • Provide simple setup guides, especially for less tech-confident staff
  • Have a recovery process in place for lost phones or devices

Conclusion

  • A strong password alone no longer protects your business — most breaches happen through stolen or phished credentials, not brute force
  • MFA closes that gap by requiring a second factor beyond the password
  • Cyber Essentials now requires MFA on every in-scope account, with no exemptions — a single missed account fails the assessment
  • Authenticator apps are the best starting point for most SMBs; hardware keys suit higher-risk accounts

If you’re not sure whether your business is fully covered ahead of your next Cyber Essentials assessment, get in touch with our team for a quick MFA and security review.

FAQ Section

Do I still need MFA if my password is really strong?
Yes. Strong passwords protect against brute-force guessing, but most breaches happen through phishing or leaked credentials, which MFA blocks even when the attacker already has your password.

Is MFA now mandatory for Cyber Essentials?
Yes. Since Cyber Essentials v3.3 took effect on 28 April 2026, MFA is mandatory for every in-scope user account, with no exemptions for standard users.

What counts as an acceptable MFA method for Cyber Essentials?
Authenticator apps, hardware security keys, push notifications, and SMS codes are all accepted, though SMS is discouraged due to SIM-swapping risk. A second password or security question does not count.

What’s the best MFA solution for a small business?
Authenticator apps are usually the best starting point — free, quick to deploy, and widely supported. Hardware keys are worth adding for admin or finance accounts handling higher-risk access.

Will MFA slow my team down?
Not if it’s rolled out properly. A short grace period for enrolment and clear setup guidance usually means staff barely notice it after the first login.

Is SMS-based MFA being phased out?

Yes. Microsoft is retiring native SMS and voice MFA for Microsoft 365 accounts from 1 February 2027. Anyone still using it as their only method will be prompted to register a passkey or authenticator app to keep signing in.

Subscribe to email news

Get occasional news, tips and tricks from us. We won’t use your email address for any other purpose.

More blog posts