Business Multi-Factor Authentication remains essential, but it cannot protect every user, device, application or business process on its own.
MFA blocks many password attacks by requiring an additional identity check. However, cyber criminals now target approvals, active sessions, endpoints, cloud identities and employees.
Therefore, SMEs need layered protection before, during and after every sign-in.
Where Business Multi-Factor Authentication Helps
MFA creates a strong barrier when passwords are stolen, reused or guessed. The National Cyber Security Centre explains that MFA makes unauthorised access more difficult, even after a password becomes compromised.
However, MFA addresses only one part of today’s attack surface. Phishing, malware, vulnerable software and social engineering continue to affect organisations throughout London and the wider UK.
MFA helps protect:
- Microsoft 365 and cloud applications
- Remote access systems
- Administrative and financial accounts
- Employee and customer portals
Still, MFA cannot patch software, remove malware or secure an unmanaged laptop.
It also cannot prevent every employee from approving a convincing fraudulent request.
Why MFA Fatigue Attacks Still Work
An MFA fatigue attack floods an employee with approval requests. Eventually, a distracted person may approve one simply to stop the alerts.
Attackers may also telephone the employee while pretending to represent Microsoft, an internal IT department or the company’s Managed IT Services provider.
This added social pressure can make a fraudulent request appear legitimate.
Furthermore, criminals can steal active session tokens after a successful login. They may then access cloud services without triggering another MFA request.
Therefore, SMEs should replace simple push approvals with stronger authentication methods wherever possible.
The National Cyber Security Centre recommends using stronger authentication methods, including passkeys and FIDO2 security keys.
Meanwhile, number matching provides a useful interim defence against repeated push notification attacks.
Number matching requires the employee to enter a number shown on the login screen. Consequently, blindly approving a notification becomes much more difficult.
Business Multi-Factor Authentication Needs Conditional Access
Conditional Access evaluates more than a password and an approval.
It can review user risk, device health, location, application sensitivity and sign-in behaviour.
For example, a managed laptop in a London office may receive normal access. On the other hand, an overseas login from an unknown device may be blocked.
Conditional Access can also respond differently based on the information being accessed.
A member of staff viewing a general company document may receive standard access. However, someone opening financial records may face additional checks.
A practical Conditional Access policy should:
- Block outdated authentication methods.
- Require compliant devices for sensitive applications.
- Challenge risky or unusual sign-ins.
- Restrict administrator access.
- Test policies before enforcement.
As a result, access decisions reflect actual risk instead of treating every login equally.
Microsoft describes Conditional Access as a policy engine that supports a Zero Trust security model.
However, these policies require careful planning.
Poorly configured rules can block legitimate employees or create unnecessary frustration. Therefore, businesses should test policies with a small user group before wider deployment.
EDR and Identity Protection Close Critical Gaps
Endpoint Detection and Response monitors devices for suspicious behaviour.
It can detect ransomware, malicious scripts, credential theft and unusual system activity.
EDR protects laptops, desktops and servers before and after a user signs in.
This protection matters because a user can complete MFA correctly and still open a malicious attachment moments later.
Identity Protection monitors account behaviour across cloud services.
Additionally, it can flag leaked credentials, unusual token use or rapid changes in login locations.
Together, these controls connect identity risk with device risk.
For example, access can be blocked when EDR identifies a compromised laptop.
A device may also be isolated from the company network while the IT provider investigates the threat.
Consequently, a correct password and an approved MFA request do not guarantee continued access.
This layered approach is especially important for businesses with hybrid teams.
Employees may work from a London office, a home network, a customer location or while travelling. Therefore, security cannot rely only on the company’s physical network.
Business Multi-Factor Authentication and Zero Trust
Technology cannot prevent every rushed click or convincing telephone call.
Therefore, employees need brief and frequent training based on current threats.
Teach employees to deny unexpected prompts and report them immediately.
In addition, require staff to verify unusual payment, password or bank detail requests through another communication channel.
For example, employees should never approve a payment change based only on an email.
Instead, they should telephone a known contact using a trusted number.
Zero Trust follows one central principle: never trust automatically and always verify the context.
The National Cyber Security Centre describes Zero Trust as an approach that removes automatic trust based on network location.
Successful access should depend on the user, device, application and current level of risk.
Businesses should begin with five actions:
- Require phishing-resistant MFA for privileged accounts
- Deploy EDR across supported endpoints
- Apply risk-based Conditional Access
- Monitor identities continuously
- Test employees with realistic exercises
These actions also support broader cyber security programmes, including Cyber Essentials and Cyber Essentials Plus.
However, Cyber Essentials should not become a one-time compliance exercise.
The controls should form part of an ongoing security strategy that includes monitoring, patching, training and access reviews.
Protect Administrator and Financial Accounts First
Not every account creates the same level of risk.
Administrator accounts can change security settings, create users and access sensitive systems.
Finance accounts may approve payments, view banking information or change supplier details.
Therefore, businesses should prioritise these accounts when improving MFA and access controls.
Privileged users should have separate accounts for daily work and administrative tasks.
For example, an IT administrator should not use a highly privileged account for email, web browsing or general office work.
Businesses should also limit the number of Global Administrator accounts within Microsoft 365.
Each administrator should receive only the access required for their role.
This approach follows the principle of least privilege.
Temporary access should also expire automatically when a task ends.
As a result, a compromised account has fewer opportunities to cause widespread damage.
Secure MFA Enrolment and Account Recovery
MFA can become ineffective when enrolment and recovery procedures remain weak.
Attackers may attempt to register their own telephone number, authentication application or security key.
They may also contact an IT help desk while pretending to be an employee who has lost a device.
Therefore, businesses need clear identity verification procedures before resetting MFA.
Staff should never approve a reset based only on information available through social media or a company website.
Instead, the IT provider should use agreed verification steps.
These may include manager approval, a known telephone number, video verification or another trusted method.
Businesses should also review MFA registration activity.
Unexpected changes to authentication methods may indicate that an account has already been compromised.
Monitoring these changes allows the IT team to respond before the attacker gains wider access.
Review Third-Party and Supplier Access
Many London SMEs rely on accountants, software providers, consultants and outsourced support teams.
These relationships improve efficiency, but they also introduce additional access risks.
A supplier account may have access to cloud systems, customer information or financial applications.
Therefore, businesses should review third-party access regularly.
External users should receive only the permissions needed for their work.
Access should also expire when a project or contract ends.
Where possible, suppliers should use their own named accounts rather than shared login details.
Shared accounts make monitoring and investigation more difficult.
Businesses should also confirm that suppliers use MFA on accounts connected to company systems.
However, MFA alone should not automatically make a supplier trustworthy.
Conditional Access, logging and permission reviews should still apply.
Conclusion: MFA Is a Starting Point
Business Multi-Factor Authentication should remain part of every cyber security plan.
However, it should never become the entire plan.
Layered security limits the damage when one control fails.
Therefore, combine MFA, Conditional Access, EDR, identity protection, employee awareness and Zero Trust principles.
Businesses should also protect privileged accounts, secure recovery processes and review supplier access.
MFA answers an important question: can the user provide another authentication factor?
Modern cyber security must ask additional questions.
- Is the device secure?
- Is the location expected?
- Is the application sensitive?
- Does the behaviour appear normal?
- Should this user still have access?
When these controls work together, businesses gain stronger protection without making every sign-in unnecessarily difficult.
Frequently Asked Questions
1. Is Multi-Factor Authentication still worth using?
Yes, MFA remains an effective basic control against account takeover.
It adds another verification step after a user enters a password. Therefore, stolen credentials alone may not provide access to email, remote systems or financial tools.
However, businesses must review which MFA method they use.
Text messages and basic push approvals offer less protection than passkeys or hardware security keys. Attackers can intercept messages, trick users or overwhelm employees with repeated requests.
The National Cyber Security Centre recommends stronger authentication methods wherever possible.
Additionally, number matching can reduce fatigue attacks when organisations still use mobile push notifications.
Administrative, financial and remote access accounts should receive priority.
MFA also needs secure enrolment and recovery procedures.
Otherwise, attackers may register their own devices or abuse weak IT support processes.
Consequently, businesses should verify identity during recovery, limit enrolment locations and monitor authentication changes.
MFA remains necessary.
Nevertheless, it works best with device protection, risk-based access, monitoring and employee education.
2. What is an MFA fatigue attack?
An MFA fatigue attack occurs when a criminal sends many approval requests to a user’s telephone.
The attacker usually already has the password. Therefore, only one mistaken approval may provide access.
The criminal may send requests late at night or during busy working hours.
Additionally, someone may telephone while pretending to represent Microsoft, an IT provider or internal technical support.
That conversation can make the request appear legitimate.
Employees should deny unexpected prompts and report them immediately.
Meanwhile, IT teams should investigate repeated challenges, reset exposed credentials, revoke active sessions and check devices for compromise.
Businesses can reduce this risk through number matching, sign-in context, rate limits and phishing-resistant authentication.
Passkeys and FIDO2 security keys connect authentication to the legitimate service.
Consequently, fake login pages and unsolicited approvals become less effective.
Training also matters.
Staff should recognise repeated prompts as a possible attack, not a technical fault.
Fast reporting gives the IT team time to contain the account and investigate other affected systems.
3. How does Conditional Access improve MFA?
Conditional Access uses context to decide whether a login should proceed.
MFA asks whether someone can provide another authentication factor.
Conditional Access also evaluates the user, device, location, application and behaviour.
For example, an employee may sign in from a managed office laptop during normal working hours.
That request may receive standard access.
However, an unmanaged device in another country may trigger blocking or stronger verification.
Conditional Access can combine risk, device compliance, network location, application sensitivity and authentication strength.
Therefore, businesses can protect important resources without placing identical restrictions on every activity.
Good policies should block legacy authentication, require secure devices and protect administrative accounts.
Additionally, organisations should test policies before enforcement.
This approach reduces unexpected interruptions and helps avoid locking out legitimate users.
Conditional Access also supports productivity.
Employees receive reasonable access during normal work, while risky requests face greater scrutiny.
As a result, the business improves security without turning every login into a frustrating process.
4. Why does a business need EDR when it has MFA?
MFA protects the login process, while EDR protects the endpoint before and after access.
A user can complete MFA correctly and still open a malicious attachment.
Likewise, attackers may exploit vulnerable software without stealing passwords.
EDR watches for suspicious behaviour on laptops, desktops and servers.
It can detect malicious scripts, ransomware, credential theft, persistence and unexpected system changes.
Furthermore, many EDR platforms can isolate an affected device before the threat spreads.
Consider an employee using a legitimate company laptop.
Malware later steals an active browser session.
The attacker may reuse that session without triggering another MFA request.
EDR can identify suspicious endpoint activity, while identity protection detects unusual cloud behaviour.
The strongest approach connects these systems.
Conditional Access can restrict cloud services when an endpoint becomes risky or non-compliant.
Therefore, a valid password and an approved MFA request no longer guarantee continued access.
MFA answers an identity question.
EDR provides another view by asking whether the device remains trustworthy and secure.
5. What does Zero Trust mean for an SME?
Zero Trust does not require an enterprise budget or one specific product.
It means the business grants no permanent trust based only on a network, device or successful login.
Instead, access decisions consider current risks and business need.
An SME can begin with practical steps.
First, identify critical data, applications and administrator accounts.
Next, require strong MFA and separate daily accounts from privileged accounts.
Then, deploy EDR, patch systems, and remove unnecessary access.
Additionally, apply Conditional Access to block risky locations, unmanaged devices and outdated authentication.
Monitor identity alerts and review account permissions regularly.
Employees should also receive frequent training on phishing, payment fraud and unexpected MFA prompts.
The National Cyber Security Centre explains that Zero Trust requires organisations to understand users, devices, services and data.
Therefore, it connects existing controls rather than replacing everything.
The goal remains simple: verify each request, limit access and reduce potential damage.
SMEs can adopt Zero Trust gradually by addressing their highest risks first.






