We completed our MFA rollout last week. 100% of users now use multi-factor authentication for Microsoft 365 and VPN access. Here's what we learned.
Why MFA Matters
Compromised credentials are the leading cause of breaches. Passwords get phished, reused, or guessed. MFA blocks the vast majority of credential-based attacks. It's not optional anymore - it's baseline security hygiene.
The Technical Approach
We used Microsoft Entra ID (Azure AD) Conditional Access policies with Microsoft Authenticator as the primary method. Users can choose push notifications or time-based codes. FIDO2 security keys available for users who prefer hardware tokens.
Phased rollout: IT first (pilot), then office staff, then warehouse staff. Each phase included training, support, and feedback collection before moving to the next.
Change Management
Technical implementation is 20% of the work. Change management is 80%. Users resist new friction. Leadership support was essential - the CEO enrolled first and championed the initiative.
We communicated the "why" repeatedly: protecting the company, protecting customer data, protecting jobs. Fear works less than purpose.
Challenges
Legacy applications: Some apps don't support modern authentication. Required workarounds with app passwords or conditional access exclusions. Documented each exception for future remediation.
Shared workstations: Warehouse computers used by multiple people. Solved with shorter session timeouts and clear sign-out procedures.
Phone resistance: Some users didn't want apps on personal phones. Offered company-provided hardware tokens as alternative.
Results
Zero security incidents related to compromised credentials since rollout. User complaints dropped after the first week - people adapted. Cyber insurance renewal went smoother with MFA documentation.
Planning an ERP modernization?
6 SAP-to-Dynamics conversions with zero business disruption. Let's discuss your project.
ERP Services Book a Call