codexier.

Maintenance & Security

Turning On Two-Factor Authentication Everywhere

By CodexierPublished 5 min read

Most break-ins at small companies start with a password that leaked somewhere else and was reused. Two-factor authentication makes that password useless on its own, which is why it is the single most effective security measure a company can adopt in an afternoon. The work is not technical; it is deciding the order, choosing a method the team will actually use, and setting up recovery so nobody is locked out.

Which accounts first

Order by blast radius. Company email comes first because password resets for every other service land there; whoever controls the mailbox controls everything. The domain registrar and DNS come next, since they can redirect your website and your email. Then the password manager, the bank and payment services, the accounting system, and the administrator logins for the website, hosting and cloud providers. After that come advertising and social accounts, which attackers target for the payment card attached, and finally the everyday tools.

Authenticator apps, keys and SMS

Not all second factors are equal. The differences matter most for the accounts at the top of your list.

MethodStrengthBest for
Hardware security key or passkeyStrongest; resists phishing because it checks the site's identityEmail, domain, password manager, admin accounts
Authenticator app with time-based codesStrong; a phished code is usable only for secondsEverything that supports it
Push approval in an appStrong if staff are trained to deny unexpected promptsMicrosoft 365 and Google Workspace
SMS codesWeakest; SIM swapping and forwarding attacks existOnly where no other option is offered

BankID already provides strong authentication for Swedish banks and Fortnox-style systems. Use it where offered; it is not a substitute for two-factor on email and domain accounts.

Passkeys are becoming the default on major platforms and combine convenience with phishing resistance. Where a service offers them, enable them alongside an authenticator app as the backup.

Rolling it out to staff

Adoption fails when it is announced by email and left to individuals. It succeeds when it is done together, with a deadline and a person to ask.

  1. Enable enforcement at the platform level in Microsoft 365 or Google Workspace, with a grace period of two weeks, so the requirement is technical rather than a request.
  2. Hold a thirty-minute session where everyone installs the authenticator app and enrols the first account with someone watching.
  3. Give each person a written one-page guide covering setup, what a suspicious prompt looks like, and whom to call when a phone is lost.
  4. After the grace period, check the admin report and follow up individually with anyone not enrolled.

Tell staff the one rule that matters most: never approve a login prompt you did not just cause, and report it if you get one. That instruction defeats the most common way two-factor is bypassed.

Recovery codes and lockouts

The fear that stops companies enabling two-factor is being locked out, and it is a fair fear if recovery is not planned. Every service issues recovery codes at enrolment; most people click past them. Save them in the company password manager under the account's entry, so that whoever needs them can find them without the phone. Enrol a second factor on every critical account, such as a hardware key kept in the office safe, and make sure at least two people hold administrator rights on email, domain and cloud. When a phone is lost, the routine is: revoke the old device, log in with a recovery code, enrol the new device, generate fresh codes. Write that routine down before you need it.

Shared accounts

Shared logins, such as a company social media account or a supplier portal used by three people, break the two-factor model because the code goes to one phone. The right fix is to stop sharing: most services let you add individual users with roles. Where a shared login is unavoidable, keep the account in the company password manager with its time-based secret stored there too, so the manager generates the code for whoever is authorised, and rotate the password when someone leaves. Never let a shared account be protected by a single employee's private phone number.

When you do not need help with this: a small team can complete the rollout above on its own with a password manager and a free afternoon. Help is worth buying when you have many services, external contractors with access, or a website and infrastructure whose admin accounts you are not sure of. That is part of what a performance and security optimisation covers, and a free call will tell you whether your setup needs it. Pricing is on the pricing page.

Frequently asked questions

Is SMS two-factor better than nothing?

Yes, considerably. It stops the common attack of reusing a leaked password. It is weaker than an app or a key against a targeted attacker who can redirect your phone number, so use it only where the service offers nothing else, and upgrade when it does.

What if an employee refuses to install a work app on a private phone?

Offer a hardware key instead; it costs little, needs no app and is stronger. For roles with broad access, a company phone is reasonable. The requirement to use two-factor stands; the method can accommodate the person.

Do we need two-factor on the website itself, for customers?

For the admin login, always. For customer accounts it depends on what they hold: payment details, personal data or the ability to order on account justify it, ideally via BankID or passkeys. A simple newsletter preference page does not.

Not sure which admin accounts your company actually has?

Bring a list of your services, even an incomplete one. In fifteen minutes we can rank them by risk, tell you which second factor each supports, and outline the rollout in the right order.

Book a free 15-minute call