If you only fix one thing this quarter, make it how people sign in.
Stolen credentials are behind most of the intrusions American companies actually suffer, and a second factor on every account remains the cheapest way to break that chain. The catch is that not every second factor still works. We build on Entra ID with FIDO2 keys, Windows Hello for Business, and certificate-based sign-in, because text messages and simple approval prompts are routinely defeated by the phishing kits sold today. The goal is authentication that survives an attacker sitting in the middle of the session, not a checkbox that satisfies a questionnaire.

- Phishing-resistantFIDO2 + Hello
- Entra IDMicrosoft identity platform
- ConditionalRisk-based access
- 99.9%Microsoft-reported compromise block rate
Six dimensions of a production-grade MFA deployment.
Phishing-resistant authentication
Hardware keys, Windows Hello for Business, and certificates deployed through Intune. These are the methods that hold when an attacker proxies the login page in real time, which is exactly where codes and approval taps fail.
Microsoft Authenticator + passkeys
Number matching in Microsoft Authenticator so a prompt cannot be approved by reflex. Passkeys where we can remove the password entirely. Text or voice kept only as a last resort for the handful of people without a company smartphone.
Conditional Access policy stack
Enforcement applies to everyone, with the emergency accounts held in a documented break-glass process rather than as everyday exceptions. Sensitive applications get their own policies, unusual sign-ins get challenged on risk, and location conditions apply where the business genuinely operates.
Privileged Identity Management (PIM)
Administrative rights stop being permanent. An engineer requests the role, it is approved, and it expires on a timer. If one account is ever taken, the attacker inherits an ordinary user rather than the keys to the tenant.
Identity Protection monitoring
Entra ID Protection surfaces the sign-ins worth looking at: travel that is not physically possible, anonymized IP addresses, behavior that does not match the user, and credentials that have turned up in a public dump. Those get triaged around the clock, and for managed clients a critical finding has an engineer on it inside five minutes.
Service account hardening
The accounts nobody wanted to break are now the softest target in most tenants. We move them onto managed identities where the workload runs in Azure, onto certificates where it does not, and onto tightly scoped credentials wrapped in conditional access where neither is possible.
Four reasons clients pick our MFA work.
Phishing-resistant by default
Six-digit codes and text messages no longer stop a real-time proxy attack. Hardware keys and Windows Hello become the default, starting with the people whose accounts move money or sign contracts.
Rollout designed for adoption
These projects die from friction, not from technology. The sequence matters: a pilot, then education, then a period where enforcement is soft, then the hard cutover. Communication, training, and a fallback for the people who lose a phone on day one. Enabled and enforced are two very different states.
Conditional Access policy library
Microsoft-recommended Conditional Access baseline plus US-market extensions: policies tuned to what cyber insurance carriers, SOC 2 auditors and the FTC Safeguards Rule actually ask about, BYOD versus corporate device policies, and finance / HR sensitivity tiers.
Service-account migration done thoroughly
Behind most breaches at companies that believed they had this covered sits an account exempted for two weeks in 2022. Every service account is inventoried and hardened as part of the project, and no exemption survives without an expiry date attached.
Six profiles where MFA is non-negotiable.
Financial services
NYDFS Part 500 and the FTC Safeguards Rule expect MFA; phishing-resistant methods for privileged access.
Healthcare
HIPAA covered entities and business associates; access controls on ePHI make MFA the baseline.
Retail and e-commerce
Point-of-sale, payment processing, and store admin logins are prime credential-theft targets under PCI DSS scrutiny.
Professional services
Client files, wire instructions, and trust accounts make these firms the classic business email compromise target.
Manufacturing
OT-IT convergence creates new MFA scope; production system access and CMMC-driven requirements need hardening.
Education
Education records protected by FERPA, plus financial aid systems, across faculty and administrative accounts alike.
Four MFA approaches with security and usability trade-offs.
| Feature | FIDO2 + Windows Hello (phishing-resistant) | Microsoft Authenticator (TOTP) | SMS / voice call | Password-only (no MFA) |
|---|---|---|---|---|
Resists adversary-in-the-middle | Partially | |||
Resists SIM-swap attack | ||||
Resists phishing reuse | Vulnerable to AiTM | |||
User experience | Tap key or biometric | Open app, type code | Receive SMS | Easiest, weakest |
What it takes to run | Hardware keys plus Entra ID | Entra ID license | Carrier delivery dependency | Nothing, until the incident |
Suitable for executives, finance, admins | Acceptable | Not recommended | Not acceptable | |
Suitable for general users | Increasingly default | Fallback only | Not acceptable anymore | |
Insurer and auditor expectation | Increasingly required for privileged access | No longer sufficient | Below minimum |
Six to ten weeks, in four deliberate phases.
- 1
Identity inventory and policy design
1-2 weeks
We inventory human accounts, service accounts, and every privileged role, design the conditional access policies, and choose which method suits each population. You receive the program design in writing before anything is switched on.
- 2
Pilot rollout
2-3 weeks
A pilot group goes first, usually IT, security, and the leadership team. General staff enroll with number matching, privileged users get hardware keys. Every complaint and stumble is recorded, because that is what the wider rollout is built from.
- 3
Soft enforcement
2-3 weeks
MFA required for all users with grace period for first-time enrollment. Communication to all staff. Service desk briefed for enrollment support. PIM enabled for admin roles.
- 4
Hard enforcement and ongoing
1-2 weeks plus continuous
Enforcement goes hard with no carve-outs left standing. Service accounts are hardened, Identity Protection watches sign-ins continuously, and every quarter we revisit exemptions, enrollment gaps, and the alerts that fired.
What buyers ask before adopting.
Book an MFA scoping call and get a written program proposal.
Half an hour covering where authentication stands today, which groups of users you have, what service accounts exist, and when you need enforcement complete. You get back a written program with the phases mapped and the right method chosen for each population.
Related Services
Explore more solutions that work great with this service
Passwordless Authentication and Passkeys
Passwordless authentication rollouts for US organizations using
Learn morePhishing-Resistant MFA
Phishing-resistant multifactor authentication for US organizations:
Learn moreMicrosoft Entra Conditional Access Design
Conditional Access design and review for US organizations:
Learn moreMicrosoft Entra ID Protection
Entra ID Protection deployment for US organizations: establishing
Learn moreMicrosoft Entra
Identity and access management solutions
Learn more