We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Cybersecurity
  2. MFA Solutions
MFA solutions for US businesses

If you only fix one thing this quarter, make it how people sign in.

Stolen credentials are behind most of the intrusions American companies actually suffer, and a second factor on every account remains the cheapest way to break that chain. The catch is that not every second factor still works. We build on Entra ID with FIDO2 keys, Windows Hello for Business, and certificate-based sign-in, because text messages and simple approval prompts are routinely defeated by the phishing kits sold today. The goal is authentication that survives an attacker sitting in the middle of the session, not a checkbox that satisfies a questionnaire.

Book an MFA scoping callSee MFA methods
MFA prompt on a mobile device
  • Phishing-resistantFIDO2 + Hello
  • Entra IDMicrosoft identity platform
  • ConditionalRisk-based access
  • 99.9%Microsoft-reported compromise block rate
MFA methods and scope

Six dimensions of a production-grade MFA deployment.

Turning on Microsoft Authenticator is the first ten percent of this work. Attackers do not attack the part you switched on. They find the service account someone exempted, the old application still using basic authentication, and the text message fallback nobody removed. All six areas below get addressed, because the gaps are the whole story.

Phishing-resistant authentication

Hardware keys, Windows Hello for Business, and certificates deployed through Intune. These are the methods that hold when an attacker proxies the login page in real time, which is exactly where codes and approval taps fail.

Microsoft Authenticator + passkeys

Number matching in Microsoft Authenticator so a prompt cannot be approved by reflex. Passkeys where we can remove the password entirely. Text or voice kept only as a last resort for the handful of people without a company smartphone.

Conditional Access policy stack

Enforcement applies to everyone, with the emergency accounts held in a documented break-glass process rather than as everyday exceptions. Sensitive applications get their own policies, unusual sign-ins get challenged on risk, and location conditions apply where the business genuinely operates.

Privileged Identity Management (PIM)

Administrative rights stop being permanent. An engineer requests the role, it is approved, and it expires on a timer. If one account is ever taken, the attacker inherits an ordinary user rather than the keys to the tenant.

Identity Protection monitoring

Entra ID Protection surfaces the sign-ins worth looking at: travel that is not physically possible, anonymized IP addresses, behavior that does not match the user, and credentials that have turned up in a public dump. Those get triaged around the clock, and for managed clients a critical finding has an engineer on it inside five minutes.

Service account hardening

The accounts nobody wanted to break are now the softest target in most tenants. We move them onto managed identities where the workload runs in Azure, onto certificates where it does not, and onto tightly scoped credentials wrapped in conditional access where neither is possible.

Why US businesses route MFA through us

Four reasons clients pick our MFA work.

Phishing-resistant by default

Six-digit codes and text messages no longer stop a real-time proxy attack. Hardware keys and Windows Hello become the default, starting with the people whose accounts move money or sign contracts.

Rollout designed for adoption

These projects die from friction, not from technology. The sequence matters: a pilot, then education, then a period where enforcement is soft, then the hard cutover. Communication, training, and a fallback for the people who lose a phone on day one. Enabled and enforced are two very different states.

Conditional Access policy library

Microsoft-recommended Conditional Access baseline plus US-market extensions: policies tuned to what cyber insurance carriers, SOC 2 auditors and the FTC Safeguards Rule actually ask about, BYOD versus corporate device policies, and finance / HR sensitivity tiers.

Service-account migration done thoroughly

Behind most breaches at companies that believed they had this covered sits an account exempted for two weeks in 2022. Every service account is inventoried and hardened as part of the project, and no exemption survives without an expiry date attached.

Who needs MFA now

Six profiles where MFA is non-negotiable.

Financial services

NYDFS Part 500 and the FTC Safeguards Rule expect MFA; phishing-resistant methods for privileged access.

Healthcare

HIPAA covered entities and business associates; access controls on ePHI make MFA the baseline.

Retail and e-commerce

Point-of-sale, payment processing, and store admin logins are prime credential-theft targets under PCI DSS scrutiny.

Professional services

Client files, wire instructions, and trust accounts make these firms the classic business email compromise target.

Manufacturing

OT-IT convergence creates new MFA scope; production system access and CMMC-driven requirements need hardening.

Education

Education records protected by FERPA, plus financial aid systems, across faculty and administrative accounts alike.

MFA methods compared

Four MFA approaches with security and usability trade-offs.

Resists adversary-in-the-middle
FIDO2 + Windows Hello (phishing-resistant)
Microsoft Authenticator (TOTP)Partially
SMS / voice call
Password-only (no MFA)
Resists SIM-swap attack
FIDO2 + Windows Hello (phishing-resistant)
Microsoft Authenticator (TOTP)
SMS / voice call
Password-only (no MFA)
Resists phishing reuse
FIDO2 + Windows Hello (phishing-resistant)
Microsoft Authenticator (TOTP)Vulnerable to AiTM
SMS / voice call
Password-only (no MFA)
User experience
FIDO2 + Windows Hello (phishing-resistant)Tap key or biometric
Microsoft Authenticator (TOTP)Open app, type code
SMS / voice callReceive SMS
Password-only (no MFA)Easiest, weakest
What it takes to run
FIDO2 + Windows Hello (phishing-resistant)Hardware keys plus Entra ID
Microsoft Authenticator (TOTP)Entra ID license
SMS / voice callCarrier delivery dependency
Password-only (no MFA)Nothing, until the incident
Suitable for executives, finance, admins
FIDO2 + Windows Hello (phishing-resistant)
Microsoft Authenticator (TOTP)Acceptable
SMS / voice callNot recommended
Password-only (no MFA)Not acceptable
Suitable for general users
FIDO2 + Windows Hello (phishing-resistant)Increasingly default
Microsoft Authenticator (TOTP)
SMS / voice callFallback only
Password-only (no MFA)Not acceptable anymore
Insurer and auditor expectation
FIDO2 + Windows Hello (phishing-resistant)Increasingly required for privileged access
Microsoft Authenticator (TOTP)
SMS / voice callNo longer sufficient
Password-only (no MFA)Below minimum
Feature
FIDO2 + Windows Hello (phishing-resistant)
Microsoft Authenticator (TOTP)
SMS / voice call
Password-only (no MFA)
Resists adversary-in-the-middle
Partially
Resists SIM-swap attack
Resists phishing reuse
Vulnerable to AiTM
User experience
Tap key or biometricOpen app, type codeReceive SMSEasiest, weakest
What it takes to run
Hardware keys plus Entra IDEntra ID licenseCarrier delivery dependencyNothing, until the incident
Suitable for executives, finance, admins
AcceptableNot recommendedNot acceptable
Suitable for general users
Increasingly defaultFallback onlyNot acceptable anymore
Insurer and auditor expectation
Increasingly required for privileged accessNo longer sufficientBelow minimum
How an MFA engagement runs

Six to ten weeks, in four deliberate phases.

What separates a rollout that lands from one that stalls is order. Inventory first, then a pilot, then soft enforcement, then the real cutover. Every phase carries its own communication and training. The finish line is full enforcement, and a tenant where the feature is switched on is not the same tenant as one where nobody can get past it.
  1. 1

    Identity inventory and policy design

    1-2 weeks

    We inventory human accounts, service accounts, and every privileged role, design the conditional access policies, and choose which method suits each population. You receive the program design in writing before anything is switched on.

  2. 2

    Pilot rollout

    2-3 weeks

    A pilot group goes first, usually IT, security, and the leadership team. General staff enroll with number matching, privileged users get hardware keys. Every complaint and stumble is recorded, because that is what the wider rollout is built from.

  3. 3

    Soft enforcement

    2-3 weeks

    MFA required for all users with grace period for first-time enrollment. Communication to all staff. Service desk briefed for enrollment support. PIM enabled for admin roles.

  4. 4

    Hard enforcement and ongoing

    1-2 weeks plus continuous

    Enforcement goes hard with no carve-outs left standing. Service accounts are hardened, Identity Protection watches sign-ins continuously, and every quarter we revisit exemptions, enrollment gaps, and the alerts that fired.

MFA FAQ

What buyers ask before adopting.

For ordinary staff with number matching turned on, it is adequate today. For your executives, your finance team, your administrators, and anything holding elevated rights, it is not. Phishing kits sold as a service now defeat both one-time codes and approval prompts as a matter of routine. Those accounts belong on hardware keys, Windows Hello, or certificates.

Text messages are materially weaker than an app or a key. SIM swap attacks against American carriers are documented, prosecuted, and still happening. Keep text as a fallback for the few people who need it, never as the default method.

Entra ID P1 includes MFA and Conditional Access. Entra ID P2 adds Identity Protection risk policies, PIM, Access Reviews. Microsoft 365 E5, or E3 plus the security add-on, includes both. We confirm what your subscription already covers during scoping rather than assuming you need to buy more.

Far less than the pushback you are anticipating. Number matching adds two seconds over a blind approval tap. Passkeys remove the password altogether, which staff generally prefer to what they had before. A hardware key is one touch. Most of the remaining friction is solved by telling people what is coming and why, a week before it happens.

FIDO2 hardware keys for users who refuse or cannot use a smartphone. Hardware OATH tokens as a second fallback. In a typical workforce this is a small minority; we handle exceptions case-by-case.

An account that genuinely cannot present a second factor belongs on a managed identity if the workload runs in Azure, or on a certificate with tight conditional access if it does not. What must not survive is the long-lived password with a permanent exemption beside it, which is where most of these breaches now start. Hardening them is part of the project, not a later phase.

Under a hundred staff, four to six weeks. Between one and five hundred, six to ten. Above that, ten to sixteen. The human side moves quickly. What stretches the timeline is service accounts, because each one means touching an application and testing it properly.

Anything speaking OAuth or SAML handles this natively. The problem children are applications still using basic authentication, which we block with a conditional access policy first and then either migrate to modern authentication or replace. Exchange Online retired basic authentication some time ago, but on-premises software and a surprising number of smaller SaaS products still accept it.
Related identity services

Services that pair with MFA.

Phishing-resistant MFA

What actually qualifies, and how to get there without a lockout.

Learn more

Microsoft Entra

Microsoft identity platform overview.

Learn more

Passwordless authentication

Passkeys and the rollout that removes the password from the equation.

Learn more
MFA, ready when you are

Book an MFA scoping call and get a written program proposal.

Half an hour covering where authentication stands today, which groups of users you have, what service accounts exist, and when you need enforcement complete. You get back a written program with the phases mapped and the right method chosen for each population.

Book an MFA scoping callSee Entra ID

Related Services

Explore more solutions that work great with this service

Passwordless Authentication and Passkeys

Passwordless authentication rollouts for US organizations using

Learn more

Phishing-Resistant MFA

Phishing-resistant multifactor authentication for US organizations:

Learn more

Microsoft Entra Conditional Access Design

Conditional Access design and review for US organizations:

Learn more

Microsoft Entra ID Protection

Entra ID Protection deployment for US organizations: establishing

Learn more

Microsoft Entra

Identity and access management solutions

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA