
Multi-factor authentication (MFA) is one of the most impactful security measures any Australian business can implement. Microsoft data consistently shows that enabling MFA blocks more than 99 per cent of automated account compromise attacks. If your business uses Microsoft 365 — for email, Teams, SharePoint, or any Microsoft app — and you haven't enforced MFA across all your users, that's the single most important security improvement you can make today.
This guide walks you through exactly how to enable and configure MFA in Microsoft 365, from your first login to the admin centre through to verifying that every user is properly protected.
You'll need:
Open your browser and go to admin.microsoft.com. Sign in with your Global Administrator account. From the left navigation, select Settings → Org settings → Security & privacy.
If you see a prompt about Security Defaults, note it — this is relevant to Step 2.
Microsoft 365 offers two main ways to enforce MFA. Choose the one appropriate for your business:
Security Defaults is Microsoft's pre-configured baseline that enforces MFA for all users, blocks legacy authentication, and protects privileged actions. It's free, requires no additional licensing, and takes about two minutes to enable.
To enable Security Defaults:
All users will be prompted to register an MFA method at their next sign-in.
Conditional Access gives you fine-grained control — requiring MFA only under certain conditions (for example, sign-in from outside Australia or access to sensitive apps) while allowing trusted networks to bypass the prompt. This requires Microsoft Entra ID P1 licensing or above.
To create a Conditional Access policy:
By default, Microsoft allows multiple MFA methods including SMS, phone call, and the Microsoft Authenticator app. For better security, restrict users to the Authenticator app and remove SMS as an option.
Before users are prompted at sign-in, give them advance notice. A brief email or Teams message explaining what MFA is, why it's being enabled, and how to set it up with the Authenticator app significantly reduces friction and helpdesk calls.
Key setup instructions for users:
For team members who are not tech-confident, have your IT contact or Tyto's helpdesk assist them through the process in person or via remote session. Getting everyone registered in the first 48 hours prevents stragglers from delaying your organisation's protection.
Once MFA has been rolled out, confirm every account is covered:
Service accounts — accounts used by automated systems rather than people — should not use MFA in the same way as user accounts. They should instead use certificate-based authentication or Managed Identities. Contact your IT provider to handle these appropriately rather than simply disabling MFA for them.
With Security Defaults, users are prompted to register MFA at their next sign-in, but they have a 14-day grace period before it's required. With Conditional Access, MFA is enforced immediately on the next sign-in matching your policy conditions. Plan your rollout window accordingly and communicate with your team in advance.
This is why every Microsoft 365 tenant should have at least two Global Administrator accounts — a primary and a break-glass account — each with their own separate MFA methods registered. For regular users who lose access, a Global or Authentication Administrator can reset their MFA methods from the Entra ID admin centre, allowing them to register a new device. Without this in place, recovering a locked-out account becomes significantly more complex.
Microsoft Authenticator is the recommended option because it supports number matching — which significantly reduces MFA fatigue attacks — and works seamlessly with Microsoft 365. However, any TOTP-compatible authenticator app such as Google Authenticator or Authy can be used as an alternative. Where possible, standardising on Microsoft Authenticator across your team simplifies support and ensures you have access to the most advanced security features.
Enabling MFA is the most impactful security step your business can take today, and for most Microsoft 365 configurations it costs nothing extra. If you need help rolling out MFA or want Tyto to review your current security posture, call us on 1300 070 565 or visit tyto.net.au.