Administrator enrolling a Microsoft 365 MFA method

Enable multi-factor authentication now. Every Microsoft 365 user or admin delaying this setup is leaving the front door unlocked. Use an authenticator app or a passkey as your primary method, save your backup codes the moment they’re generated, and register at least two verification methods before you close the setup screen. If you’re an administrator, remember that Microsoft Entra ID has to have MFA enabled at the organization level before any of your users can register a method at all.


TL;DR:

  • Microsoft Entra ID must have MFA enabled at the organization level before users can register methods, which can delay rollout if not configured correctly.
  • Using an authenticator app like Microsoft Authenticator offers offline, secure, and phishing-resistant authentication, while SMS is less secure and should be a backup only.
  • Enrolling at least two verification methods, including a hardware security key or passkey, and storing backup codes offline are essential to prevent lockouts.
  • Admins should create emergency access accounts before organization-wide MFA deployment and follow a staged rollout process to avoid disruptions.
  • Managing MFA methods over time requires regular device updates, rotating retired devices, and setting reminders to verify active registered methods.

Mavericks Office Solutions
Strengthen Your Microsoft 365 Security
Mavericks provides managed IT services, cybersecurity, and proactive support to help small and medium-sized businesses secure their technology.

Explore IT security support

Table of Contents

Getting Your Multi Factor Authentication Setup Ready: What to Prepare First

Before you touch a single settings screen, get your ducks in a row. A rushed MFA configuration is how people end up locked out of their own inbox at 7 a.m. on a Monday.

Start by confirming your organization’s policy stance. If you’re an individual user, check with your IT department to see whether Microsoft Entra ID has security defaults or Conditional Access already turned on. If you’re the admin, that decision is yours to make before anyone else can register a method.

Here’s your preflight checklist:

  • Confirm your organization has MFA enabled through security defaults or Conditional Access, or verify you have permission to register methods on your own account.
  • Have your primary email, an alternate email, a working phone number, and either a laptop or desktop within reach during setup.
  • Decide in advance which verification methods your organization allows. Some SMBs block SMS entirely for security reasons.
  • If you’re an admin, create emergency access accounts (sometimes called break-glass accounts) before you roll anything out organization-wide.

Skipping that last step is one of the more common regrets IT administrators mention after a rollout goes sideways.

How Do You Set Up Multi Factor Authentication Step by Step?

Once your prerequisites are handled, the actual two factor authentication setup takes less time than making coffee. Here’s the order that works best for most Microsoft 365 users, whether you’re doing this for the first time or adding a new device.

  1. Start at the sign-in prompt or go directly to account.microsoft.com/security or aka.ms/mfasetup. Your organization may automatically prompt you the next time you sign in if MFA has just been turned on.
  2. Install Microsoft Authenticator on your phone from the App Store or Google Play. This is the method Microsoft recommends first, and for good reason: authenticator apps generating time-based one-time passwords are free, work offline, and don’t depend on cell signal the way SMS does, according to SUNY Niagara’s IT guidance.
  3. Scan the QR code shown on your screen with the app, then approve the test prompt it sends. If your account setup offers cloud backup for the app, turn it on. It saves you from re-registering every account if your phone breaks or gets replaced.
  4. Register a passkey or Windows Hello for Business if your organization offers it. Passkeys and Windows Hello let you sign in with your face, fingerprint, or device PIN instead of typing anything, and they’re built directly into Windows. Test the biometric prompt once to confirm it recognizes you reliably.
  5. Add SMS or voice as a fallback only if your policy allows it. Text-message codes are convenient, but they’re also the weakest link in the chain. SIM-swapping attacks have made SMS one of the more vulnerable verification methods, according to StaySafeOnline’s guidance on MFA. Treat it as a backup, not your primary method.
  6. Register a FIDO2 hardware security key if you handle sensitive data or hold an admin role. Plug the key into a compatible browser, follow the registration prompt, and test it once before you close the window. Hardware keys and passkeys are considered the most phishing-resistant options available, which is why Microsoft and security agencies alike push them for high-risk accounts.
  7. Save your backup codes immediately. Print them, store them in a password manager, or lock them on an encrypted USB drive. Then enroll one more method beyond your first. Two working methods beat one perfect one every time.

Pro Tip: If your authenticator app displays a setup key (a string of letters and numbers) during registration, write it down somewhere secure before you scan the QR code. That backup secret lets you re-provision the same account on a new phone without waiting on account recovery.

How Do You Manage and Update Your MFA Methods Over Time?

Setup day isn’t the end of the job. Phones get lost, upgraded, or dropped in a lake, and your verification methods need to keep pace.

Method management for Microsoft 365 lives under My Profile > Security info or Additional security options, depending on your account type. From there you can add a second authenticator, register a new phone number, or enroll a spare hardware key without waiting on IT.

A few habits keep this system healthy:

  • Store backup codes offline, either printed or on a secure USB drive, never in an unencrypted note on your phone.
  • Rotate out old devices from your registered methods as soon as you retire them.
  • Keep at least two non-SMS methods enrolled at all times, plus your backup codes as a third layer.

Nair’s writing on backup MFA methods](https://www.anoopcnair.com/why-setting-up-backup-mfa-methods-is-important/).

Pro Tip: Set a recurring calendar reminder every six months to check which devices are still registered to your account. It takes two minutes and it’s the easiest way to catch an old phone still sitting in your security info.

Security Defaults or Conditional Access: Which Should Admins Choose?

Administrators rolling out multi factor authentication across an organization have two paths, and picking the wrong one wastes time.

Security defaults is the fast option. It’s available at no extra cost in Entra ID Free and enforces a sensible baseline: MFA for all users, blocked legacy authentication, and protection for privileged roles. If you’re a small business with straightforward needs, this is often enough on its own.

Conditional Access is the granular option, available with Entra ID P1 or P2 licensing. It lets you build policies based on user role, location, device compliance, or risk level, but it requires turning off security defaults first, according to Microsoft’s admin guidance.

Before enforcing anything organization-wide, follow this sequence:

  • Build a baseline Conditional Access policy that mirrors what security defaults already does, then test it in report-only mode.
  • Create two emergency access accounts (break-glass accounts) with strong, non-expiring credentials stored somewhere physically secure.
  • Require phishing-resistant methods, meaning hardware keys or passkeys, for every admin and privileged role.
  • Roll enforcement out in stages rather than flipping the switch for all users at once.

Our companion guide on MFA implementation for growing businesses walks through this rollout sequence in more depth if you’re managing this for the first time.

What Should You Do If You Lose Access or Get Locked Out?

Losing your phone doesn’t have to mean losing your account, but only if you set things up correctly beforehand.

If your device is gone, use your backup codes or an already-enrolled alternate method, such as a second phone number or a spare hardware key, to sign back in. From there, remove the lost device and register a replacement immediately.

If you start seeing repeated approval prompts you didn’t trigger, that’s MFA fatigue, a tactic attackers use hoping you’ll approve out of annoyance. Never approve a prompt you didn’t request. Deny it and change your password right away.

For legacy applications that can’t handle modern verification, Microsoft 365 supports app passwords, generated from your security info page specifically for that one program.

  • Use backup codes or an enrolled alternate method the moment you lose a device.
  • Deny any unexpected approval prompt and change your password immediately.
  • Generate an app password only for legacy software that can’t support modern MFA.
  • When contacting IT, provide your last successful sign-in time and device ID to speed up recovery.

Roughly one in three IT help-desk tickets tied to authentication comes down to a single missing backup method, which is exactly why CISA recommends enrolling more than one factor from the start.

Mavericks Office Solutions’ Field-Tested MFA Checklist

Small business owners rarely have a dedicated security team walking them through every edge case, which is where a short, practical checklist earns its keep.

Enroll multiple methods at setup, not just one. Keep backup codes offline, in a drawer or a locked file, not a phone note. Register a spare hardware key for every admin account and store it somewhere separate from the primary user’s desk. Run a recovery drill twice a year so nobody discovers a gap in emergency access during an actual emergency.

When clients using managed IT support run into an MFA issue anyway, our help desk answers in under 12 minutes on average, so a lockout costs minutes, not a morning.

Convenience Costs Time. Lockouts Cost More.

Convenience Costs Time. Lockouts Cost More. — overview diagram

Every added verification step costs a few seconds of a user’s day, and that’s the honest trade nobody likes to say out loud. But weigh that against the alternative: a compromised admin account, a ransomware entry point, or a locked-out employee who can’t process payroll. The math isn’t close.

My take, after looking at how these rollouts actually play out: most small businesses over-invest in convenience and under-invest in phishing-resistant methods for the accounts that matter most. Authenticator apps are the right default for everyday staff. Hardware keys belong on every admin and finance account, full stop, no exceptions for “we’ll get to it later.”

— Jeffrey

Let Mavericks Office Solutions Handle Your MFA Rollout

Setting up multi factor authentication for one account takes ten minutes. Rolling it out correctly across thirty employees, four admin roles, and a mix of legacy software takes considerably longer, and one missed emergency access account can turn into a very bad Tuesday.

Mavericks Office Solutions

Mavericks Office Solutions builds the organization-wide policy, decides between security defaults and Conditional Access based on what your business actually needs, and enforces phishing-resistant methods for every privileged role, all without you having to become a part-time identity administrator. Our managed IT services include ongoing monitoring and a USA-based help desk that answers fast when something goes wrong, not three days later through an offshore ticket queue. Pair that with our cybersecurity services for broader policy enforcement and risk review. If your business is ready to stop managing MFA as an afterthought, reach out to Mavericks Office Solutions and get a rollout plan built around how your team actually works.

Where to Verify These MFA Setup Steps Yourself

For the exact click-by-click screens, Microsoft’s own support pages stay current with interface changes better than any third-party guide. Start with Microsoft’s user setup instructions and the admin configuration guide for policy decisions. CISA’s MFA resource covers the security fundamentals behind why this matters at all, and our own password policy checklist pairs well as a next read.

Sources