MFA Best Practices: More than just a second factor

    Back to Blog
    Security

    MFA Best Practices: More than just a second factor

    Properly implemented Multi-Factor Authentication. Learn how to introduce MFA in a user-friendly and secure way in your company.

    October 25, 20258 min read
    Luis Castillo

    Luis Castillo

    Solution Engineer

    luis.castillo@cnext.ch
    6+ Jahreexperience·5×Microsoft Applied Skills·Security & Intune
    CNEXT Desk Setup

    Quick Answer

    Properly implemented Multi-Factor Authentication. Learn how to introduce MFA in a user-friendly and secure way in your company.

    MFA is the most important single security measure. When implemented correctly, it stops 99.9% of all credential-based attacks.

    Why MFA is Essential

    Statistics

    • 99.9% of credential attacks are prevented by MFA
    • 80% of all security incidents involve passwords
    • Phishing remains the most common attack vector

    Without MFA

    A password is enough for access – and passwords are:

    • Stolen (Phishing, Breaches)
    • Guessed (Weak Passwords)
    • Reused (Credential Stuffing)

    Comparison of MFA Methods

    Strong (Recommended)

    1. 1FIDO2 Security Keys – Phishing-resistant
    2. 2Windows Hello for Business – Biometric, device-bound
    3. 3Microsoft Authenticator (Passwordless) – With Number Matching

    Medium

    1. 1Microsoft Authenticator (Push) – Convenient, but risk of MFA fatigue
    2. 2TOTP Apps – Google Authenticator, Authy

    Weak (Avoid)

    1. 1SMS – Vulnerable to SIM swapping
    2. 2Phone Call – Social engineering risk
    3. 3Email – Often unprotected itself

    Best Practices

    Enable Number Matching

    Against MFA fatigue attacks:

    • User must enter a number
    • Not just press "Confirm"
    • Makes prompt bombing more difficult

    Display Additional Context

    User sees:

    • Location of the request
    • Application
    • IP address

    This helps to identify suspicious requests.

    Registration Policies

    Secure MFA registration:

    • Temporary Access Pass for onboarding
    • No self-service in high-risk situations
    • Register at least two methods

    Rollout Strategy

    Phase 1: Administrators

    • All admins with strong MFA
    • FIDO2 or Windows Hello
    • No SMS/Phone

    Phase 2: Privileged Users

    • Finance, HR, IT
    • Access to sensitive data
    • Prioritize strong methods

    Phase 3: All Users

    • Gradual rollout
    • Authenticator app as a minimum
    • Security keys where practical

    Phase 4: Enforcement

    • Activate MFA requirement
    • Limit fallback methods
    • Continuous monitoring

    Common Mistakes

    1. 1SMS as primary method – Too weak
    2. 2No emergency processes – What if the phone is lost?
    3. 3Exceptions for VIPs – Increases risk
    4. 4No training – Users do not understand MFA

    Conclusion

    MFA is not optional. With the right methods and processes, it provides maximum protection. CNEXT supports user-friendly implementation.

    IdentitySecurityBest PracticesSchweiz
    Teilen:

    This article was created with the support of AI and reviewed by our team. We use AI tools to produce high-quality content efficiently — the editorial responsibility always lies with our experts.

    Luis Castillo

    Luis Castillo

    Solution Engineer

    Have questions about this topic?

    Our experts are happy to advise you – free and without obligation.