Cyber Security

MFA Guide for Sydney Businesses – What Works and What Fails

in 𝕏
By Adrian Weir | Published 6 August 2026

BUSINESS SECURITY

Why the MFA method and coverage both matter

A password is no longer enough. Many Microsoft 365 and Google Workspace plans include a basic MFA capability, and turning it on is better than relying on passwords alone. The next question is whether the setup protects every important sign-in and uses an authentication method that matches the risk.

MFA platforms take different approaches. Microsoft and Google provide strong controls inside their own ecosystems. Independent platforms can cover a wider mix of cloud applications, VPNs, remote access and administrator portals. Milnsbridge supplies and manages Cisco Duo MFA, but the right choice still depends on the applications, identity platform, account risk and compliance requirements of each business.

The authentication method matters as much as the product name. SMS codes can be exposed through SIM swapping. Basic push approvals can be abused through notification fatigue. Passkeys and properly verified FIDO2 security keys provide stronger protection against phishing when the application supports them.

This guide explains what effective multi-factor authentication Sydney businesses should look like, compares five widely used platforms and covers the rollout controls that prevent gaps. Microsoft 365 controls such as Conditional Access remain important in a Microsoft environment, and Milnsbridge manages those through our Microsoft 365 service.

The goal is consistent protection. Every important access path needs an owner, an appropriate authentication method and a controlled process for enrolment, recovery and exceptions.

WHERE MFA GOES WRONG

Four MFA problems Sydney businesses run into

SMS becomes the permanent default

SMS codes are easy to deploy, which is why they often remain in place long after a rollout. They are vulnerable to phone number porting and SIM swapping. A sound MFA design treats SMS as a limited fallback where necessary, not the preferred method for administrator, finance or other high-risk access.

Push approvals are configured without safeguards

Attackers can trigger repeated approval requests and wait for a tired or distracted person to accept one. Number matching or verified push requires the user to enter information shown by the login prompt, which reduces blind approvals. It is stronger than a simple approve button, although it is not the same as a phishing-resistant passkey or security key.

Old access methods sit outside the control

MFA can be enabled for normal sign-ins while an older protocol, application, or remote access path still accepts only a password. Microsoft 365 legacy authentication is one example. VPNs, administrator portals, and third-party cloud applications also need to be checked. The rollout is incomplete until every access path is either protected, restricted, replaced, or documented as an approved exception.

Exceptions and enrolment are not managed

Temporary bypasses are often created when someone changes a phone or cannot complete enrolment. Without ownership and reporting, those exceptions can remain open. The rollout needs secure recovery procedures, controlled exceptions, onboarding and offboarding, and a way to verify which users and applications are covered.

PLATFORM COMPARISON

Five MFA platforms businesses often compare

These products do not all solve the same problem. Microsoft and Google provide native protection inside their ecosystems. Independent platforms can cover a broader identity or application environment. For businesses comparing multi-factor authentication Sydney services, the table shows practical fit rather than declaring one universal winner.

Solution Best suited to Stronger authentication options Main consideration
Cisco Duo Businesses needing a dedicated MFA platform across supported applications and private resources. Phishing-resistant MFA, FIDO2 passwordless authentication and trusted endpoint controls. Availability varies by edition. A dedicated identity security platform with broad integrations. Policy, device and risk features depend on the edition.
Microsoft Entra ID MFA Microsoft 365 and Azure-centred environments. FIDO2 security keys, Windows Hello for Business and certificate-based authentication. Conditional Access can require specific authentication strengths. Deep Microsoft integration. Conditional Access requires Microsoft Entra ID P1 or a licence that includes it.
Okta Adaptive MFA Organisations with a large or mixed SaaS environment. Okta FastPass, FIDO2 WebAuthn authenticators and supported smart cards, with device and contextual policies. Strong independent identity and application coverage. It may introduce more complexity than a smaller Microsoft-only business needs.
JumpCloud MFA Cloud-first businesses combining identity, device and application access. JumpCloud Protect, TOTP, hardware keys, biometrics and certificates, plus contextual access policies. Most useful when the business also wants JumpCloud directory or device management capabilities.
Google Workspace 2-Step Verification Google Workspace-centred businesses. Passkeys, hardware or phone-based security keys, Google Prompt and authenticator codes. Strong native protection for Google accounts, but it is not a like-for-like replacement for a cross-platform MFA service.

Comparison basis. This is not a market-share ranking. It uses public vendor documentation verified in August 2026. Features vary by edition, licensing and integration. Milnsbridge supplies and manages Cisco Duo, but the appropriate platform depends on the applications, identity environment, risk profile and compliance requirements of each business.

STANDARDS AND ASSURANCE

How MFA supports Australian cyber security standards

MFA is not a universal legal requirement for every Australian business. It becomes a defined obligation when a cyber security framework, government program, customer contract or target maturity level requires it. The implementation then has to match the required account coverage, authentication strength, monitoring and evidence.

Essential Eight

MFA is one of the eight mitigation strategies in ASD's Essential Eight. At Maturity Level One, its requirements cover a defined set of organisational and third-party online services, including services handling sensitive information, applicable online customer services, and third-party services handling non-sensitive data where MFA is available. It also defines permitted factor combinations. Maturity Level Two extends coverage to privileged and unprivileged users of systems, requires phishing-resistant MFA for online services and systems, and requires successful and unsuccessful MFA events to be centrally logged.

ASD recommends organisations reach the same maturity level across all eight strategies. The Essential Eight remains the current baseline while ASD develops the broader Essentials series. Read the official maturity model.

DISP

Defence states that all Defence Industry Security Program members are required to achieve and maintain the full Essential Eight at Maturity Level Two. Its Cyber Security Questionnaire covers 107 Essential Eight controls and supports ongoing assurance activities.

For a DISP member, enabling MFA only for email does not address the full requirement. Relevant online services, privileged and unprivileged system access, phishing-resistant methods, event logging and documented exceptions all need to be considered across the applicable corporate ICT environment. Review Defence cyber assurance guidance.

SMB1001

SMB1001:2026 is a five-level cyber security certification standard for small and medium-sized businesses. Dynamic Standards International identifies MFA as part of access management, alongside strong password policies and user-activity monitoring.

The controls increase by level, so MFA requirements should be mapped to the selected certification level and current edition rather than treated as identical for every SMB1001 business. The implementation record should show which accounts and services are covered, how enforcement works and how exceptions are managed. Review the official SMB1001 overview.

Evidence assessors can verify

A licence invoice or screenshot showing that MFA is available does not prove that the control is complete. Useful evidence includes:

  • Defined account, application and access-path scope
  • Enrolment, coverage and authentication-method reports
  • Policies for privileged access and stronger factors
  • Successful and unsuccessful authentication logs
  • Exception, recovery and emergency-access records
  • Review dates and evidence that gaps were remediated

Milnsbridge supports Essential Eight uplift, SMB1001 readiness and Defence industry IT. The target standard and required evidence should be agreed before choosing the MFA platform and rollout design.

IMPLEMENTATION GUIDE

How to roll out MFA across a business

Map the access paths

Start with the systems people use to reach business data. That commonly includes cloud applications, VPN and remote access, administrator portals and user accounts. Record the existing identity platform, privileged access, recovery requirements and any service or emergency accounts that need separate treatment. The result is a defined scope rather than an assumption that one switch protects everything.

Choose methods by account risk

Routine user access and privileged access should not inherit the same policy by default. Compatible applications can use phishing-resistant passkeys or security keys with required user verification such as a PIN or biometric. Where those methods are not practical, number matching or verified push can reduce approval fatigue. SMS should be limited to cases where stronger methods are unavailable.

Pilot enrolment before wider deployment

Start with a small group. Confirm the sign-in experience, supported applications, device enrolment, recovery process and help instructions before the wider rollout. Users need to recognise a genuine prompt and know what to do when a request appears unexpectedly. For privileged access, apply the stronger methods required by the risk and relevant Essential Eight guidance.

Manage changes after go-live

MFA needs ongoing ownership. New employees require enrolment. Departing staff must be removed. Lost or replaced phones need a secure recovery process. New applications and access paths need policy decisions. Review exceptions, adoption and policy coverage so the control does not decay after launch.

THE NUMBERS

Why MFA matters for Sydney businesses

99.9%

More than 99.9% of compromised Microsoft accounts did not have MFA, according to Microsoft security guidance.

84,700+

Cybercrime reports received by ASD's ACSC in 2024-25, according to its business fact sheet.

59%

Share of January to June 2025 notified data breaches caused by malicious or criminal attacks, reported by the OAIC.

$80,850

Average self-reported cost per cybercrime report for Australian businesses in 2024-25, according to ASD's ACSC.

MFA is one of the strongest controls against password-based account takeover, but the percentage is not the whole story. Protection depends on coverage, factor strength, user behaviour and the way exceptions are managed. The platform must fit the applications and identity environment rather than forcing every business into the same design.

COMMON QUESTIONS

MFA questions Sydney businesses ask

Is the MFA included with Microsoft 365 enough?

It can be enough for Microsoft-focused sign-ins when it is properly configured, legacy authentication is disabled and the required policy features are licensed. It does not automatically protect every VPN, remote access system, administrator portal or non-Microsoft application. Businesses with a mixed environment may need a broader identity platform.

Which MFA methods resist phishing?

Passkeys, Windows Hello for Business and FIDO2 security keys can provide phishing resistance when the sign-in uses a compatible integration and requires user verification. SMS, one-time codes and ordinary push approvals do not provide the same protection. Verified push or number matching reduces fatigue attacks but should not be described as equivalent to a phishing-resistant passkey.

Which MFA platform is best for a small business?

Microsoft Entra ID is often the practical choice for a Microsoft-centred environment. Google Workspace 2-Step Verification fits Google accounts. Duo suits businesses that need managed coverage across supported cloud applications, VPN and remote access. Okta is strong in larger mixed SaaS environments, while JumpCloud combines MFA with directory and device management. The application scope and identity environment should decide the platform.

Will MFA slow down the team?

A poorly planned rollout creates frustration. A staged rollout reduces that risk through pilot users, clear instructions, supported enrolment and a documented recovery process. Policies can vary by group and application so higher-risk access receives stronger controls. Staff still need to deny any prompt they did not initiate and report unexpected requests.

EXPLORE MORE

Related Milnsbridge guides

Duo MFA rollout and management

See how Milnsbridge scopes, deploys, supports and manages Duo across the business access paths included in the rollout.

Read more

SMB1001 readiness

Plan a staged certification pathway with documented controls, evidence and review activities matched to the target level.

Read more

Essential Eight guidance

Understand current MFA expectations, stronger factors for privileged access, and how the control supports an Essential Eight uplift.

Read more

Defence industry IT

Review IT support for Defence suppliers working toward DISP cyber security and Essential Eight requirements.

Read more

NEXT STEP

Ready to improve your MFA coverage?

Milnsbridge supports Sydney businesses from our Sydney CBD and Penrith offices, with a 20-second average answer time and 87% first-call resolution. We can review the applications and accounts that need protection, assess the current setup and recommend whether native controls or a managed MFA platform is the better fit.

Talk to a Specialist

About the Author

Adrian Weir

Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.

Meet the Milnsbridge Team
← Back to Tech News

Need IT Support for Your Business?

Managed IT services for Sydney businesses with 10–200 seats. Unlimited support from $119/seat/month, 20-second average response time.

Talk to a Specialist Book a 30-Minute Call