Two-factor authentication: what it is and why every account needs it
Overview
Most break-ins to business accounts do not involve anything clever. Someone gets hold of a password, types it in, and they are in. The password might have been guessed, reused from another site that was breached, or handed over on a fake login page. Two-factor authentication, usually shortened to 2FA, is the one setting that makes a stolen password useless on its own.
If you have ever had your bank send a code to your phone before letting you log in, you have already used it. This article explains what is happening behind that step, why we treat it as a requirement rather than a preference, and what it takes to get it switched on across a whole business.
What 2FA actually is
Logging in normally asks for one thing: something you know, which is your password. Two-factor authentication adds a second thing: something you have, which is usually your phone. To get in, an attacker would need both. Knowing your password is not enough if they do not also have the device sitting in your pocket.
The second factor most people see is a six-digit code from an authenticator app, or a notification on the phone asking "Is this you?" with an Approve button. Text message codes still exist, but they are the weakest option and we move clients away from them where we can.
How it works day to day
In practice it is less disruptive than people expect. You enter your password as usual. On a device you have used before, that is often the end of it. On a new device, a new location or after a set period, you are asked to confirm on your phone. Tap approve, or type in the code, and you are through. The whole thing takes a few seconds and most staff stop noticing it within a week.
Behind the scenes, the app on your phone and the service you are logging into share a secret that was set up when you first enrolled. The code the app shows changes every 30 seconds and is generated from that secret plus the current time. Nobody else can produce the same code without the phone, and a code that has been used or has expired is worthless.
If someone is asking you to read out or type in your 2FA code, that is the attack. The code is for you to enter, never to share.
Why it is not optional any more
Passwords leak constantly. Large breaches at other companies release millions of email and password pairs, and attackers run those lists against Microsoft 365, Google, Xero and every other business service on the assumption that people reuse passwords. Many do. A phishing email that captures one login can be enough to read a mailbox, redirect a supplier payment or reset the passwords on everything else.
With 2FA turned on, those attacks stop at the door. Microsoft's own figures put the reduction in account compromise at over 99 percent for accounts with it enabled. Cyber insurers now ask about it before they will quote, and several will decline cover or a claim without it. Industry and government frameworks in New Zealand list it as a baseline control, not an advanced one.
The other reason it is not optional is that one unprotected account is enough. Security settings that are "mostly on" give a false sense of safety. Attackers do not need the director's login if the accounts inbox or a shared mailbox is still open.
Where businesses fall short
In the accounts we review, the pattern is usually the same. 2FA was recommended to staff but not enforced, so some people set it up and others did not. Shared logins for a generic mailbox or a software subscription were left out because nobody was sure whose phone should get the code. Old accounts for people who have left were never closed. And the systems outside Microsoft or Google, such as accounting, payroll, the website host and the domain registrar, were forgotten entirely.
How New Solutions can help
Turning 2FA on for yourself takes two minutes. Making sure it is on for every account in the business, and stays on, is the part that takes some organisation. This is work we do for clients as part of managed IT support, and it looks like this:
Audit. We list every account and service the business uses, including the ones outside your main email platform, and check which have 2FA enforced, which have it available but unused, and which do not support it.
Enforce rather than encourage. In Microsoft 365 and Google Workspace we set policies that require 2FA for everyone, so a new staff member cannot skip it and an existing one cannot switch it off. Where a service has no way to enforce it, we track it and check it.
Handle the awkward cases. Shared mailboxes, service accounts and logins for the boardroom TV all need a sensible approach. We sort out who holds the second factor and document it, so nobody is locked out when someone is on leave.
Roll it out without a bad day. We schedule the change, tell staff what to expect, help anyone who gets stuck and set up backup methods so a lost phone does not become a lost week.
Keep checking. Accounts get added and people move on. We review regularly so the coverage you had at the start is the coverage you still have a year later.
If you are not sure whether every account in your business has 2FA enforced, that is the answer. Get in touch and we will run through it with you.
What our clients say
“We have found them to be very flexible – they work nights and weekends to fix problems and install upgrades to minimise disruption. They are also proactive and offer solutions to simplify our IT, whilst being mindful of our budget.”
Elaine Hogg, Reproflex3
Looking for an IT partner that just gets it?
No silly questions, just straight up answers.
