A password on its own is no longer enough. Multi-factor auth adds a second door: even if someone knows your password, they stay locked out.

You type your password, and the site also asks for a code sent to your phone. That's MFA. A short second check that changes a lot.

Good news: turning it on for an account takes about five minutes.

What you actually gain

Passwords leak. It happens every month: a site breach, phishing, an infected machine, a reused password from years ago.

With MFA on, someone trying your password gets stuck on the second screen. They don't have your phone, and the code changes every 30 seconds.

Microsoft reports that MFA blocks more than 99% of automated account-compromise attempts, and cuts overall compromise risk by roughly 99% across its user base (2019 and 2023 studies on Azure AD accounts, see Sources). Those numbers come from Microsoft's own data; they don't cover the most sophisticated targeted attacks (real-time phishing, session hijacking). But for anything aimed at your password, MFA is the highest-return step you can take.

Which kind of MFA to pick

TypeSecurityConvenience
Authenticator app (TOTP code)Very goodGood
Push notification (Microsoft, Google)Very goodExcellent
Hardware key (YubiKey, Titan)ExcellentGood
SMS codeFairExcellent

Apps beat SMS: an SMS can be intercepted through SIM swap. An app generates the code offline on your phone.

If you don't use an authenticator app yet, start there: Microsoft Authenticator, Google Authenticator, or the one built into your password manager (1Password, Bitwarden). All free.

One case where MFA isn't enough

Modern phishing can relay a TOTP or SMS code in real time. It's rare, but it happens. The truly robust protections are passkeys or a FIDO2 hardware key. For a critical account (main email, bank, business admin), a hardware key remains the best choice.

For everything else, app-based MFA already does 95% of the work.

Tonight, one account: your main email

The main email is the key to every other account, because that's where password resets and security alerts land. Start there.

  1. Install an authenticator app (2 min)
  2. Open the security settings of Gmail, Outlook or iCloud
  3. Turn on two-factor authentication, scan the QR code
  4. Save the backup codes in your password manager (not in a text to yourself)

This week, do the same for your bank, Apple or Google, your password manager, government portals and social media. Five to ten minutes per account. In one evening, your critical accounts are double-locked.

Related

MFA works better with a password manager: a unique password per site plus a second factor. Two doors beat one. See also six cybersecurity habits for everyone.

Rolling MFA out across a team without breaking Outlook on mobile, without stranding people on the road, and without losing backup codes when employees leave, is a different job. Book thirty minutes and we'll frame it.

Sources