Why this matters
MFA is one of the most effective Essential Eight strategies. Rolling it out across a business needs a bit of planning so staff are not locked out and no accounts are missed.
What you'll need
- A list of online services and remote access methods
- Admin access to Microsoft 365 or identity provider
- Staff communication plan
Step-by-step instructions
Step 1
List everything that needs MFA
Include Microsoft 365, VPN and remote access, cloud apps, accounting software, banking and any internet-facing service holding sensitive data.
Step 2
Start with admins and remote access
Privileged accounts and remote access are the highest-value targets. Enforce MFA on these first.
Step 3
Choose your methods
Use an authenticator app with number matching at a minimum. Higher maturity levels expect phishing-resistant methods such as passkeys, Windows Hello for Business or FIDO2 security keys.
Step 4
Communicate with staff
Tell staff when MFA is coming, why it matters and how to set it up. Offer help sessions.
Step 5
Enforce with policy
Use Security defaults or Conditional Access in Microsoft 365 to require MFA, rather than relying on individuals to opt in.
Step 6
Handle exceptions carefully
Keep an emergency access account excluded but monitored. Remove legacy authentication that bypasses MFA.
Step 7
Monitor sign-ins
Review sign-in logs for failed MFA attempts or unexpected approvals.
Summary
A planned MFA rollout, enforced by policy and starting with your riskiest accounts, makes a large contribution to Essential Eight maturity.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.