Turning On Two-Factor Authentication Everywhere
By CodexierPublished 5 min read
Most break-ins at small companies start with a password that leaked somewhere else and was reused. Two-factor authentication makes that password useless on its own, which is why it is the single most effective security measure a company can adopt in an afternoon. The work is not technical; it is deciding the order, choosing a method the team will actually use, and setting up recovery so nobody is locked out.
Which accounts first
Order by blast radius. Company email comes first because password resets for every other service land there; whoever controls the mailbox controls everything. The domain registrar and DNS come next, since they can redirect your website and your email. Then the password manager, the bank and payment services, the accounting system, and the administrator logins for the website, hosting and cloud providers. After that come advertising and social accounts, which attackers target for the payment card attached, and finally the everyday tools.
Authenticator apps, keys and SMS
Not all second factors are equal. The differences matter most for the accounts at the top of your list.
| Method | Strength | Best for |
|---|---|---|
| Hardware security key or passkey | Strongest; resists phishing because it checks the site's identity | Email, domain, password manager, admin accounts |
| Authenticator app with time-based codes | Strong; a phished code is usable only for seconds | Everything that supports it |
| Push approval in an app | Strong if staff are trained to deny unexpected prompts | Microsoft 365 and Google Workspace |
| SMS codes | Weakest; SIM swapping and forwarding attacks exist | Only where no other option is offered |
BankID already provides strong authentication for Swedish banks and Fortnox-style systems. Use it where offered; it is not a substitute for two-factor on email and domain accounts.
Passkeys are becoming the default on major platforms and combine convenience with phishing resistance. Where a service offers them, enable them alongside an authenticator app as the backup.
Rolling it out to staff
Adoption fails when it is announced by email and left to individuals. It succeeds when it is done together, with a deadline and a person to ask.
- Enable enforcement at the platform level in Microsoft 365 or Google Workspace, with a grace period of two weeks, so the requirement is technical rather than a request.
- Hold a thirty-minute session where everyone installs the authenticator app and enrols the first account with someone watching.
- Give each person a written one-page guide covering setup, what a suspicious prompt looks like, and whom to call when a phone is lost.
- After the grace period, check the admin report and follow up individually with anyone not enrolled.
Tell staff the one rule that matters most: never approve a login prompt you did not just cause, and report it if you get one. That instruction defeats the most common way two-factor is bypassed.
Recovery codes and lockouts
The fear that stops companies enabling two-factor is being locked out, and it is a fair fear if recovery is not planned. Every service issues recovery codes at enrolment; most people click past them. Save them in the company password manager under the account's entry, so that whoever needs them can find them without the phone. Enrol a second factor on every critical account, such as a hardware key kept in the office safe, and make sure at least two people hold administrator rights on email, domain and cloud. When a phone is lost, the routine is: revoke the old device, log in with a recovery code, enrol the new device, generate fresh codes. Write that routine down before you need it.
Frequently asked questions
Is SMS two-factor better than nothing?
Yes, considerably. It stops the common attack of reusing a leaked password. It is weaker than an app or a key against a targeted attacker who can redirect your phone number, so use it only where the service offers nothing else, and upgrade when it does.
What if an employee refuses to install a work app on a private phone?
Offer a hardware key instead; it costs little, needs no app and is stronger. For roles with broad access, a company phone is reasonable. The requirement to use two-factor stands; the method can accommodate the person.
Do we need two-factor on the website itself, for customers?
For the admin login, always. For customer accounts it depends on what they hold: payment details, personal data or the ability to order on account justify it, ideally via BankID or passkeys. A simple newsletter preference page does not.
Not sure which admin accounts your company actually has?
Bring a list of your services, even an incomplete one. In fifteen minutes we can rank them by risk, tell you which second factor each supports, and outline the rollout in the right order.
Book a free 15-minute call