BUSINESS SECURITY
Why the MFA method and coverage both matter
A password is no longer enough. Many Microsoft 365 and Google Workspace plans include a basic MFA capability, and turning it on is better than relying on passwords alone. The next question is whether the setup protects every important sign-in and uses an authentication method that matches the risk.
MFA platforms take different approaches. Microsoft and Google provide strong controls inside their own ecosystems. Independent platforms can cover a wider mix of cloud applications, VPNs, remote access and administrator portals. Milnsbridge supplies and manages Cisco Duo MFA, but the right choice still depends on the applications, identity platform, account risk and compliance requirements of each business.
The authentication method matters as much as the product name. SMS codes can be exposed through SIM swapping. Basic push approvals can be abused through notification fatigue. Passkeys and properly verified FIDO2 security keys provide stronger protection against phishing when the application supports them.
This guide explains what effective multi-factor authentication Sydney businesses should look like, compares five widely used platforms and covers the rollout controls that prevent gaps. Microsoft 365 controls such as Conditional Access remain important in a Microsoft environment, and Milnsbridge manages those through our Microsoft 365 service.
The goal is consistent protection. Every important access path needs an owner, an appropriate authentication method and a controlled process for enrolment, recovery and exceptions.
WHERE MFA GOES WRONG
Four MFA problems Sydney businesses run into
SMS becomes the permanent default
SMS codes are easy to deploy, which is why they often remain in place long after a rollout. They are vulnerable to phone number porting and SIM swapping. A sound MFA design treats SMS as a limited fallback where necessary, not the preferred method for administrator, finance or other high-risk access.
Push approvals are configured without safeguards
Attackers can trigger repeated approval requests and wait for a tired or distracted person to accept one. Number matching or verified push requires the user to enter information shown by the login prompt, which reduces blind approvals. It is stronger than a simple approve button, although it is not the same as a phishing-resistant passkey or security key.
Old access methods sit outside the control
MFA can be enabled for normal sign-ins while an older protocol, application, or remote access path still accepts only a password. Microsoft 365 legacy authentication is one example. VPNs, administrator portals, and third-party cloud applications also need to be checked. The rollout is incomplete until every access path is either protected, restricted, replaced, or documented as an approved exception.
Exceptions and enrolment are not managed
Temporary bypasses are often created when someone changes a phone or cannot complete enrolment. Without ownership and reporting, those exceptions can remain open. The rollout needs secure recovery procedures, controlled exceptions, onboarding and offboarding, and a way to verify which users and applications are covered.
PLATFORM COMPARISON
Five MFA platforms businesses often compare
These products do not all solve the same problem. Microsoft and Google provide native protection inside their ecosystems. Independent platforms can cover a broader identity or application environment. For businesses comparing multi-factor authentication Sydney services, the table shows practical fit rather than declaring one universal winner.
| Solution | Best suited to | Stronger authentication options | Main consideration |
|---|---|---|---|
| Cisco Duo | Businesses needing a dedicated MFA platform across supported applications and private resources. | Phishing-resistant MFA, FIDO2 passwordless authentication and trusted endpoint controls. Availability varies by edition. | A dedicated identity security platform with broad integrations. Policy, device and risk features depend on the edition. |
| Microsoft Entra ID MFA | Microsoft 365 and Azure-centred environments. | FIDO2 security keys, Windows Hello for Business and certificate-based authentication. Conditional Access can require specific authentication strengths. | Deep Microsoft integration. Conditional Access requires Microsoft Entra ID P1 or a licence that includes it. |
| Okta Adaptive MFA | Organisations with a large or mixed SaaS environment. | Okta FastPass, FIDO2 WebAuthn authenticators and supported smart cards, with device and contextual policies. | Strong independent identity and application coverage. It may introduce more complexity than a smaller Microsoft-only business needs. |
| JumpCloud MFA | Cloud-first businesses combining identity, device and application access. | JumpCloud Protect, TOTP, hardware keys, biometrics and certificates, plus contextual access policies. | Most useful when the business also wants JumpCloud directory or device management capabilities. |
| Google Workspace 2-Step Verification | Google Workspace-centred businesses. | Passkeys, hardware or phone-based security keys, Google Prompt and authenticator codes. | Strong native protection for Google accounts, but it is not a like-for-like replacement for a cross-platform MFA service. |
Comparison basis. This is not a market-share ranking. It uses public vendor documentation verified in August 2026. Features vary by edition, licensing and integration. Milnsbridge supplies and manages Cisco Duo, but the appropriate platform depends on the applications, identity environment, risk profile and compliance requirements of each business.
STANDARDS AND ASSURANCE
How MFA supports Australian cyber security standards
MFA is not a universal legal requirement for every Australian business. It becomes a defined obligation when a cyber security framework, government program, customer contract or target maturity level requires it. The implementation then has to match the required account coverage, authentication strength, monitoring and evidence.
Essential Eight
MFA is one of the eight mitigation strategies in ASD's Essential Eight. At Maturity Level One, its requirements cover a defined set of organisational and third-party online services, including services handling sensitive information, applicable online customer services, and third-party services handling non-sensitive data where MFA is available. It also defines permitted factor combinations. Maturity Level Two extends coverage to privileged and unprivileged users of systems, requires phishing-resistant MFA for online services and systems, and requires successful and unsuccessful MFA events to be centrally logged.
ASD recommends organisations reach the same maturity level across all eight strategies. The Essential Eight remains the current baseline while ASD develops the broader Essentials series. Read the official maturity model.
DISP
Defence states that all Defence Industry Security Program members are required to achieve and maintain the full Essential Eight at Maturity Level Two. Its Cyber Security Questionnaire covers 107 Essential Eight controls and supports ongoing assurance activities.
For a DISP member, enabling MFA only for email does not address the full requirement. Relevant online services, privileged and unprivileged system access, phishing-resistant methods, event logging and documented exceptions all need to be considered across the applicable corporate ICT environment. Review Defence cyber assurance guidance.
SMB1001
SMB1001:2026 is a five-level cyber security certification standard for small and medium-sized businesses. Dynamic Standards International identifies MFA as part of access management, alongside strong password policies and user-activity monitoring.
The controls increase by level, so MFA requirements should be mapped to the selected certification level and current edition rather than treated as identical for every SMB1001 business. The implementation record should show which accounts and services are covered, how enforcement works and how exceptions are managed. Review the official SMB1001 overview.
Evidence assessors can verify
A licence invoice or screenshot showing that MFA is available does not prove that the control is complete. Useful evidence includes:
- Defined account, application and access-path scope
- Enrolment, coverage and authentication-method reports
- Policies for privileged access and stronger factors
- Successful and unsuccessful authentication logs
- Exception, recovery and emergency-access records
- Review dates and evidence that gaps were remediated
Milnsbridge supports Essential Eight uplift, SMB1001 readiness and Defence industry IT. The target standard and required evidence should be agreed before choosing the MFA platform and rollout design.
IMPLEMENTATION GUIDE
How to roll out MFA across a business
Map the access paths
Start with the systems people use to reach business data. That commonly includes cloud applications, VPN and remote access, administrator portals and user accounts. Record the existing identity platform, privileged access, recovery requirements and any service or emergency accounts that need separate treatment. The result is a defined scope rather than an assumption that one switch protects everything.
Choose methods by account risk
Routine user access and privileged access should not inherit the same policy by default. Compatible applications can use phishing-resistant passkeys or security keys with required user verification such as a PIN or biometric. Where those methods are not practical, number matching or verified push can reduce approval fatigue. SMS should be limited to cases where stronger methods are unavailable.
Pilot enrolment before wider deployment
Start with a small group. Confirm the sign-in experience, supported applications, device enrolment, recovery process and help instructions before the wider rollout. Users need to recognise a genuine prompt and know what to do when a request appears unexpectedly. For privileged access, apply the stronger methods required by the risk and relevant Essential Eight guidance.
Manage changes after go-live
MFA needs ongoing ownership. New employees require enrolment. Departing staff must be removed. Lost or replaced phones need a secure recovery process. New applications and access paths need policy decisions. Review exceptions, adoption and policy coverage so the control does not decay after launch.
THE NUMBERS
Why MFA matters for Sydney businesses
More than 99.9% of compromised Microsoft accounts did not have MFA, according to Microsoft security guidance.
Cybercrime reports received by ASD's ACSC in 2024-25, according to its business fact sheet.
Share of January to June 2025 notified data breaches caused by malicious or criminal attacks, reported by the OAIC.
Average self-reported cost per cybercrime report for Australian businesses in 2024-25, according to ASD's ACSC.
MFA is one of the strongest controls against password-based account takeover, but the percentage is not the whole story. Protection depends on coverage, factor strength, user behaviour and the way exceptions are managed. The platform must fit the applications and identity environment rather than forcing every business into the same design.
COMMON QUESTIONS
MFA questions Sydney businesses ask
Is the MFA included with Microsoft 365 enough?
It can be enough for Microsoft-focused sign-ins when it is properly configured, legacy authentication is disabled and the required policy features are licensed. It does not automatically protect every VPN, remote access system, administrator portal or non-Microsoft application. Businesses with a mixed environment may need a broader identity platform.
Which MFA methods resist phishing?
Passkeys, Windows Hello for Business and FIDO2 security keys can provide phishing resistance when the sign-in uses a compatible integration and requires user verification. SMS, one-time codes and ordinary push approvals do not provide the same protection. Verified push or number matching reduces fatigue attacks but should not be described as equivalent to a phishing-resistant passkey.
Which MFA platform is best for a small business?
Microsoft Entra ID is often the practical choice for a Microsoft-centred environment. Google Workspace 2-Step Verification fits Google accounts. Duo suits businesses that need managed coverage across supported cloud applications, VPN and remote access. Okta is strong in larger mixed SaaS environments, while JumpCloud combines MFA with directory and device management. The application scope and identity environment should decide the platform.
Will MFA slow down the team?
A poorly planned rollout creates frustration. A staged rollout reduces that risk through pilot users, clear instructions, supported enrolment and a documented recovery process. Policies can vary by group and application so higher-risk access receives stronger controls. Staff still need to deny any prompt they did not initiate and report unexpected requests.
EXPLORE MORE
Related Milnsbridge guides
Duo MFA rollout and management
See how Milnsbridge scopes, deploys, supports and manages Duo across the business access paths included in the rollout.
Read moreSMB1001 readiness
Plan a staged certification pathway with documented controls, evidence and review activities matched to the target level.
Read moreEssential Eight guidance
Understand current MFA expectations, stronger factors for privileged access, and how the control supports an Essential Eight uplift.
Read moreDefence industry IT
Review IT support for Defence suppliers working toward DISP cyber security and Essential Eight requirements.
Read moreNEXT STEP
Ready to improve your MFA coverage?
Milnsbridge supports Sydney businesses from our Sydney CBD and Penrith offices, with a 20-second average answer time and 87% first-call resolution. We can review the applications and accounts that need protection, assess the current setup and recommend whether native controls or a managed MFA platform is the better fit.
Talk to a SpecialistAbout the Author
Adrian Weir
Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.
Meet the Milnsbridge Team
