Elecrics logoElecricsManaged IT Services
ServicesIndustriesHow It WorksAboutClient Support
(617) 982-2325Book an IT Fit CallSign in
Elecrics logoElecrics

The complete outsourced IT department for growing Massachusetts businesses.

530 West St, Braintree, MA 02184

Mon–Fri, 10 AM–6 PM ET

(617) 982-2325support@elecrics.com

Services

Complete Managed ITHelpdesk & Employee SupportMicrosoft 365 & Google WorkspaceCybersecurity & Data ProtectionDevice & Endpoint ManagementNetworks & Workplace TechnologyDevice Procurement & LifecycleIT Projects & Deployments

Company

How It WorksIndustriesProperty Management ITIT Insights (Blog)About ElecricsContactClient Support

Get Started

A free 20-minute call to see whether Elecrics is the right IT department for your team.

Book an IT Fit Call

Windows · Mac · Chromebook · Microsoft 365 · Google Workspace

© 2026 Elecrics LLC. All rights reserved.

Terms of ServicePrivacy PolicyCCPA/CPRA
    All articles

    MFA for Small Business: Roll It Out Without a Revolt

    September 9, 2026 · Elecrics Team

    What multi-factor authentication actually is

    Multi-factor authentication (MFA) means proving who you are with more than one thing before you get into an account. A password is one factor: something you know. MFA adds a second factor, usually something you have — like a code from an app on your phone, or a tap to approve a login.

    The reason it matters is simple. Passwords get stolen, guessed, and reused all the time. If someone in your Weymouth office uses the same password for email as they do for a shopping site, and that shopping site gets breached, an attacker now has a working key to your business email. MFA slams that door. Even with the right password, an attacker can't log in without the second factor sitting in your employee's pocket.

    For a 5–50 person company with no IT department, MFA is the single highest-impact security step you can take for the money. It's often free or nearly free — it just requires a rollout that people cooperate with.

    Why small businesses get targeted

    A common myth: "We're too small for hackers to care about us." The opposite is true. Attackers use automated tools that don't care whether you're a 12-person accounting firm in Quincy or a Fortune 500. They look for weak logins at scale. Small businesses are attractive precisely because they usually have fewer defenses.

    The most common attack we see isn't dramatic. It's email account takeover. Someone gets into a mailbox, watches quietly for a week, then sends a fake invoice or wire-transfer request to your customers or your bookkeeper. MFA on email alone prevents the large majority of these.

    The types of second factor, ranked

    Not all MFA is equal. From most to least secure:

    • App-based approval or passkeys — An authenticator app (like Microsoft Authenticator or Google Authenticator) shows a code or a "Yes, it's me" prompt. Passkeys use your phone's fingerprint or face. This is the sweet spot: strong and easy.
    • Hardware security keys — A small USB or tap device. Very secure, great for owners and finance staff, but more to manage.
    • Text-message codes (SMS) — Better than nothing, and fine as a fallback, but codes can be intercepted or redirected. Don't make it your only method.

    Our general advice: standardize on an authenticator app for the whole team, with SMS as a backup only.

    Where to turn MFA on first

    You don't have to do everything at once. Protect the accounts that would hurt most if lost, in this order:

    1. Email and Microsoft 365 / Google Workspace — the master key to almost everything.
    2. Banking, payroll, and accounting (QuickBooks, your bank portal, payroll provider).
    3. Admin accounts — anyone who can add users, reset passwords, or change settings.
    4. Remote access tools and VPNs.
    5. Everything else — CRM, file storage, e-commerce, social media.

    Most of these platforms have MFA built in and free. You're switching on a feature you already own.

    The rollout plan that avoids a revolt

    MFA fails not because of technology but because of communication. People hate surprises that make their workday harder. Here's how to roll it out so your team comes along willingly.

    1. Tell people why, in human terms

    A week before, send a short message: "To protect our email and our clients from fraud, we're adding a quick phone approval when you log in. It takes about 10 minutes to set up and adds a couple of seconds to logins." Frame it as protecting their paycheck and your customers, not as a hoop to jump through.

    2. Pilot with a small group

    Start with yourself and one or two willing people. Work out the wrinkles before the whole office is involved. You'll learn what questions come up.

    3. Set up in a hands-on session

    Block 30 minutes. Walk everyone through installing the authenticator app and connecting it. Doing it together beats emailing instructions and hoping. Have a plan for the person whose phone is old, or who doesn't want a work app on a personal device.

    4. Plan for the phone question up front

    Some employees push back on using a personal phone. Reasonable options:

    • The authenticator app is tiny and doesn't track them — explain that.
    • Offer a hardware key as an alternative for anyone who prefers it.
    • For shared or front-desk roles, use a security key kept at the desk.

    5. Handle backup and recovery

    What happens when someone gets a new phone or loses one? Decide before launch:

    • Set up backup codes and store them safely.
    • Make sure an admin can reset a locked-out employee.
    • Never let people share codes or passwords to "get around" it — that defeats the purpose.

    6. Make it stick with a policy

    Write one paragraph: MFA is required on all work accounts, no exceptions, and here's who to call if you're stuck. Add it to onboarding so new hires set it up on day one.

    Common objections and honest answers

    • "It slows us down." After setup, most logins are a single tap, and many tools remember trusted devices for weeks, so you're not prompted constantly.
    • "I don't have my phone at my desk." That's what backup codes and hardware keys are for.
    • "We've never been hacked." The goal is to keep it that way — and account takeover often goes unnoticed until money moves.

    A realistic timeline

    For a 15-person office, a sensible pace looks like:

    • Week 1: Turn on MFA for email/admin accounts, pilot with leadership.
    • Week 2: Company-wide setup session; enable MFA on banking and payroll.
    • Week 3: Extend to remaining apps; confirm everyone has backup codes.
    • Ongoing: New hires set up MFA on day one; review who has admin access quarterly.

    Where a managed IT provider fits in

    You can absolutely do this yourself with the steps above. Where an IT partner helps is enforcing MFA consistently across every account, setting up recovery so no one gets permanently locked out, and layering it with related protections like conditional access (rules that, for example, block logins from outside the country). A managed IT provider like Elecrics handles the setup, the exceptions, and the "what if" cases so you don't have to become the office's tech-support hotline.

    If you'd like a second set of eyes on your setup — or you're not sure which accounts are still unprotected — you're welcome to book a free 20-minute IT Fit Call at https://elecrics.com/book. No pressure, just a straight answer about where you stand.

    Questions about your own IT?

    Book a free 20-minute IT Fit Call — a no-pressure conversation about your team, your technology, and what would actually help.

    Book a Free IT Fit Call

    Elecrics LLC

    530 West St, Braintree, MA 02184

    (617) 982-2325 · support@elecrics.com

    Monday–Friday, 10:00 AM–6:00 PM ET