IT helpdesk support headset icon
Talk to our experts for fast, reliable IT support.

connectivity

How to Set Up Multi-Factor Authentication in Microsoft 365 for Australian Businesses

Multi-factor authentication is the single most effective security control you can enable to protect your business. Here's a practical, step-by-step guide to setting up MFA in Microsoft 365 — from admin centre to verified protection across your team.
September 17, 2026
Adam Brown, Business Director — Tyto IT
6 min read
Cyber Security
Business professional setting up multi-factor authentication on a smartphone for Microsoft 365 security

Multi-factor authentication (MFA) is one of the most impactful security measures any Australian business can implement. Microsoft data consistently shows that enabling MFA blocks more than 99 per cent of automated account compromise attacks. If your business uses Microsoft 365 — for email, Teams, SharePoint, or any Microsoft app — and you haven't enforced MFA across all your users, that's the single most important security improvement you can make today.

This guide walks you through exactly how to enable and configure MFA in Microsoft 365, from your first login to the admin centre through to verifying that every user is properly protected.

Before You Start

You'll need:

  • Global Administrator or Security Administrator access to your Microsoft 365 tenant
  • A decision made about which MFA enforcement method to use (covered in Step 2)
  • Roughly 30 minutes to complete the setup

Step 1: Sign In to the Microsoft 365 Admin Centre

Open your browser and go to admin.microsoft.com. Sign in with your Global Administrator account. From the left navigation, select SettingsOrg settingsSecurity & privacy.

If you see a prompt about Security Defaults, note it — this is relevant to Step 2.

Step 2: Choose Your MFA Enforcement Method

Microsoft 365 offers two main ways to enforce MFA. Choose the one appropriate for your business:

Option A: Security Defaults (Recommended for most small businesses)

Security Defaults is Microsoft's pre-configured baseline that enforces MFA for all users, blocks legacy authentication, and protects privileged actions. It's free, requires no additional licensing, and takes about two minutes to enable.

To enable Security Defaults:

  1. Go to the Azure Portal → Microsoft Entra IDProperties
  2. Click Manage Security Defaults at the bottom of the page
  3. Set the toggle to Enabled and click Save

All users will be prompted to register an MFA method at their next sign-in.

Option B: Conditional Access (Recommended for businesses with Microsoft 365 Business Premium or higher)

Conditional Access gives you fine-grained control — requiring MFA only under certain conditions (for example, sign-in from outside Australia or access to sensitive apps) while allowing trusted networks to bypass the prompt. This requires Microsoft Entra ID P1 licensing or above.

To create a Conditional Access policy:

  1. Go to Microsoft Entra IDSecurityConditional Access
  2. Click + New policy and give it a name (for example, "Require MFA — All Users")
  3. Under Users, select All users (exclude your break-glass admin account)
  4. Under Cloud apps, select All cloud apps
  5. Under Grant, choose Grant accessRequire multi-factor authentication
  6. Set the policy to On and click Create

Step 3: Configure Approved MFA Methods

By default, Microsoft allows multiple MFA methods including SMS, phone call, and the Microsoft Authenticator app. For better security, restrict users to the Authenticator app and remove SMS as an option.

  1. In the Azure Portal, navigate to Microsoft Entra IDSecurityAuthentication methods
  2. Enable Microsoft Authenticator and disable SMS and Voice call where possible
  3. Under Authenticator settings, enable Number matching — this prevents MFA fatigue attacks where an attacker triggers push notifications hoping the user approves without noticing

Step 4: Roll Out to Your Team

Before users are prompted at sign-in, give them advance notice. A brief email or Teams message explaining what MFA is, why it's being enabled, and how to set it up with the Authenticator app significantly reduces friction and helpdesk calls.

Key setup instructions for users:

  1. Download the Microsoft Authenticator app from the App Store or Google Play
  2. At their next sign-in, follow the on-screen prompts to register their device
  3. When signing in, the Authenticator app will display a two-digit number to enter — approve it in the app
  4. Registration takes under two minutes per person

For team members who are not tech-confident, have your IT contact or Tyto's helpdesk assist them through the process in person or via remote session. Getting everyone registered in the first 48 hours prevents stragglers from delaying your organisation's protection.

Step 5: Verify That Every Account Is Protected

Once MFA has been rolled out, confirm every account is covered:

  1. Go to Microsoft Entra IDUsersAll users
  2. Open the Authentication methods report (under Security) or use the Per-user MFA view
  3. Review which accounts show as Enabled or Enforced
  4. Any account showing Disabled needs follow-up — confirm whether it's a service account requiring a different approach

Service accounts — accounts used by automated systems rather than people — should not use MFA in the same way as user accounts. They should instead use certificate-based authentication or Managed Identities. Contact your IT provider to handle these appropriately rather than simply disabling MFA for them.

Frequently Asked Questions

Does enabling MFA affect all users immediately?

With Security Defaults, users are prompted to register MFA at their next sign-in, but they have a 14-day grace period before it's required. With Conditional Access, MFA is enforced immediately on the next sign-in matching your policy conditions. Plan your rollout window accordingly and communicate with your team in advance.

What happens if a user loses their phone and can't access the Authenticator app?

This is why every Microsoft 365 tenant should have at least two Global Administrator accounts — a primary and a break-glass account — each with their own separate MFA methods registered. For regular users who lose access, a Global or Authentication Administrator can reset their MFA methods from the Entra ID admin centre, allowing them to register a new device. Without this in place, recovering a locked-out account becomes significantly more complex.

Is the Microsoft Authenticator app the only option?

Microsoft Authenticator is the recommended option because it supports number matching — which significantly reduces MFA fatigue attacks — and works seamlessly with Microsoft 365. However, any TOTP-compatible authenticator app such as Google Authenticator or Authy can be used as an alternative. Where possible, standardising on Microsoft Authenticator across your team simplifies support and ensures you have access to the most advanced security features.

Enabling MFA is the most impactful security step your business can take today, and for most Microsoft 365 configurations it costs nothing extra. If you need help rolling out MFA or want Tyto to review your current security posture, call us on 1300 070 565 or visit tyto.net.au.

Need support now?

Having an IT issue right now? Call our helpdesk on 1300 070 565 — you’ll speak to a real engineer who already knows IT, not a call centre script.
Support Portal
Circular dark gray button with a white arrow pointing diagonally up and right.Black arrow pointing diagonally upward and to the right on white background.

empowering businesses with tailored IT solutions

Contact Us Now
©2026 Tyto. All rights reserved.