The first thing most small businesses put in place after a password breach is multi-factor authentication. You may have rolled it out across email, your accounting system, your cloud file storage, and maybe your remote-access tools. That was the right call. The problem is that somewhere in the last twelve months, the assumption that “we have MFA, so we are fine” stopped being accurate. Attackers have adapted, and the gap between an MFA setup that actually stops them and one that just slows them down has gotten wider.

Text-message codes are no longer considered safe enough on their own for the accounts that matter. Push notifications can be defeated by a tactic called MFA fatigue. Even traditional authenticator app codes can be intercepted by a phishing site that proxies the login in real time. Whether your current setup falls into the “actually stops them” category or the “looks secure on paper” category depends on which method you chose, how you configured it, and which accounts you protected first.

Here is what to look at, in plain terms, before your next insurance renewal or security review.

How Do Attackers Get Past MFA?

The shift in attacker behavior over the last two years has been less about new exploits and more about new workflows. Once everyone turned MFA on, the cheapest way around it stopped being a clever technical bypass and started being a few well-known patterns that exploit how the codes get delivered, how people approve them, and how the help desk recovers a locked account. The four patterns below cover the vast majority of business email and Microsoft 365 takeovers we are seeing on the Treasure Coast.

MFA Fatigue And Push Bombing

The attacker already has the password. They enter it on the real login page, which triggers a real push notification to your phone. They wait a few seconds and try again. And again. And again, sometimes thirty or forty times in an hour, often at three in the morning. Eventually a tired or distracted employee taps Approve to make the notifications stop. The attacker is now signed in with a fully valid session. The 2022 Uber breach started this way, and the same pattern has shown up in dozens of small-business email compromises since.

Adversary-In-The-Middle Phishing Proxies

This is the technique that defeats most authenticator app codes. The employee clicks a link that looks like a normal Microsoft 365 sign-in page, but is actually a proxy running on the attacker’s server. They type their password into the proxy, the proxy forwards it to the real Microsoft, Microsoft sends the six-digit code, the employee types the code into the proxy, the proxy forwards that too, and Microsoft returns a session cookie. The proxy keeps the cookie, the employee gets logged in to a real Microsoft page so nothing looks off, and the attacker walks in with a fully authenticated session for the next 24 to 90 days. If your team trains for “watch the URL bar,” this is the attack they need to be ready for. Knowing what to do after a phishing click matters because the session cookie is what gets stolen, and rotating the password alone does not invalidate it.

SIM Swap And Carrier Social Engineering

If your MFA codes are delivered by text message, the attacker has another path. They call the cellular carrier, claim to be the employee, claim to have lost the phone, and ask for the number to be ported to a new SIM card the attacker controls. The text-message code now lands on the attacker’s phone instead of the employee’s. The financial industry has been dealing with this for years, and the technique has moved downstream into small-business attacks. Carriers have improved their verification, but a determined caller still gets through often enough that any account protected only by SMS codes should be treated as one social-engineering call away from compromise.

Help-Desk And Reset-Flow Abuse

The attacker does not need to defeat your MFA if they can convince someone to turn it off. This sometimes looks like a phone call to your internal IT contact pretending to be an executive locked out before a meeting. It sometimes looks like an email to the cellular carrier or to Microsoft support asking for a reset. The defense is procedural, not technical: a written rule that nobody resets MFA without a callback to a known number, regardless of how urgent the request sounds. This is the same logic behind requiring a callback on spoofed requests that look like the CEO, and it applies just as cleanly to MFA reset traffic.

Which Types Of MFA Are Easier To Defeat?

Not all MFA methods are equal. Government guidance has been increasingly explicit about this, and the federal Cybersecurity and Infrastructure Security Agency now recommends a ranked tier system. From weakest to strongest, the practical methods a small business will encounter are: text-message codes, voice-call codes, basic push approvals, authenticator app codes with number matching, hardware security keys, and passkeys. Each step up the ladder closes a specific attack the step below it allowed.

Text-message and voice codes are the bottom of the stack because they can be intercepted at the carrier (SIM swap), at the phishing proxy (the AiTM attack above), or by someone shoulder-surfing a buzzing phone on a desk. They are still better than nothing. They are not adequate for email, banking, or any account that holds customer data. The fastest, lowest-friction upgrade for an office still on SMS codes is moving everyone to an authenticator app, which gets you out of the carrier risk and most of the shoulder-surfing risk in one step.

Basic push approvals (a notification with an Approve and a Deny button) are vulnerable to the fatigue attack above. Number matching is the configuration change that fixes this. With number matching turned on, the sign-in screen shows a two-digit number that the employee has to type into the authenticator app, rather than just tapping Approve. The fatigue attack stops working because the attacker has no way to know which number to send the employee. Microsoft turned number matching on by default for all tenants in early 2023; if your tenant predates that change and was never reviewed, the setting may still be off. This is worth a five-minute check.

Authenticator app codes with number matching are good enough for almost every small-business workload, with one large exception: they do not stop the AiTM phishing proxy attack. To close that last gap, you need phishing-resistant MFA. That is the next section.

What Is Phishing-Resistant MFA And Why Does It Matter?

Phishing-resistant MFA is a category of authentication methods built around a cryptographic guarantee rather than a shared code. The two methods small businesses will actually encounter are hardware security keys (the USB or NFC dongles made by Yubico, Feitian, and a few others) and passkeys (the newer software equivalent that lives in the device’s secure enclave). Both are based on the same FIDO2 and WebAuthn standards, and both share one property that the SMS code and the authenticator app code do not: the credential is bound to the specific website it was registered with, and the browser refuses to release it to any other domain.

What this means in practice: if an employee clicks a phishing link and lands on an attacker’s proxy that pretends to be Microsoft 365, the security key or passkey simply refuses to authenticate. The employee does not have to notice anything is wrong. The credential will not work on the wrong domain, period. This is the only currently-available defense against the AiTM proxy attack that does not depend on the employee spotting a subtle URL difference under pressure.

For a small office, the practical rollout is usually a mix. Hardware keys (around 25 to 70 dollars each) go to the people whose accounts would do the most damage if breached: the owner, the controller or bookkeeper, anyone with administrative access to Microsoft 365 or the accounting system, and anyone whose email is used to authorize payments. Passkeys, which are free and work from a phone or laptop the employee already owns, go to the rest of the team. The CISA fact sheet on this topic, Implementing Phishing-Resistant MFA, is the authoritative reference if you want the formal version of the same recommendation.

How Do You Upgrade MFA Without Disrupting Your Team?

The reason most MFA upgrades stall is not the technology, it is the rollout. Going from SMS codes to authenticator apps, or from authenticator apps to passkeys, touches every employee. Done poorly, you create a week of lockouts and a stack of help-desk tickets. Done well, the change is invisible to most users after the first day.

The rollout pattern that works for a 10-to-100-person office breaks into three phases. First, identify the high-risk accounts: anyone who can move money, anyone who can send mail from a shared inbox, anyone with admin rights in Microsoft 365 or the line-of-business app, and the owner. These accounts get hardware security keys and a written policy that says any sign-in attempt without the key is denied, no matter how convenient the exception would be. Second, move the rest of the team off SMS codes and onto an authenticator app with number matching. The same password vault the team already shares can store backup codes for users whose phones break or get replaced.

Third, plan for the lost-phone and new-employee cases ahead of time. The single biggest reason MFA rollouts get rolled back is that the first time someone breaks their phone, IT cannot get them back in fast enough and leadership decides MFA is too painful. Pre-staged backup codes printed and stored in a safe, a written reset procedure that requires identity verification by callback, and at least two administrators who can perform the reset all need to be in place before the upgrade goes out. These same callback rules also stop the help-desk attack from earlier in the article.

Training is the smallest piece by volume but the most important by impact. The single concept most employees do not know is that a legitimate sign-in never asks for an MFA code on a website they were not actively signing into. If a code arrives unprompted, that is the attack pattern, and the only correct response is to ignore the code and report it. This is the same principle that drives the response to text-message scams aimed at your team, and it generalizes cleanly across SMS, push, and email-based verification.

Frequently Asked Questions

Is text-message MFA actually unsafe, or is the risk overblown?

SMS codes are dramatically better than no MFA at all. They are not adequate for accounts that move money, hold customer data, or have administrative access. The realistic risk is not that every business gets SIM-swapped, but that any employee who is specifically targeted, especially someone visible on a company website or LinkedIn, can be SIM-swapped within a few days by a motivated attacker. Use SMS as a starting point, not a finishing point.

What exactly is MFA fatigue?

It is the tactic of triggering push-notification prompts repeatedly until a user taps Approve out of frustration, confusion, or to silence the buzzing phone. The attacker already has the password and is just trying to get past the second factor. Number matching, which forces the user to type a number shown on the sign-in screen into the authenticator app, eliminates the attack because the attacker cannot tell the user which number to type.

Are authenticator apps really better than SMS codes?

Yes, for two reasons. The code is generated on the device rather than sent over the cellular network, so a SIM swap does not give the attacker the code. The app can also be configured to require number matching, which closes the fatigue attack. The remaining weakness is the AiTM phishing proxy, which both SMS and authenticator app codes are vulnerable to.

Do passkeys actually replace passwords?

For accounts that fully support them, yes. The passkey is a cryptographic credential stored on the device, unlocked by a fingerprint, face, or PIN, and presented to the website without ever traveling over the network in a form that can be intercepted. Most major business platforms now support passkeys, including Microsoft 365, Google Workspace, and the major password managers. The realistic timeline for a small office is to start adding passkeys alongside existing passwords over the next twelve to eighteen months, not to flip a switch tomorrow.

How many MFA methods should a single account have set up?

At least two, and at most three. The primary method is whatever the strongest available option is for that account (ideally a hardware key or passkey). The backup method is an authenticator app for use when the primary device is unavailable. A third method is sometimes useful for emergency reset, typically a printed set of one-time codes stored in a safe. Having too many methods configured creates an attack surface: the attacker just needs to compromise the weakest one.

Can a small business require MFA on every Microsoft 365 account?

Yes. Microsoft now turns on Security Defaults for new tenants, which requires MFA registration for everyone and enforces it on risky sign-ins. For more control, a tenant on Business Premium or above can configure Conditional Access policies that require specific MFA methods, block legacy authentication protocols, and require phishing-resistant MFA for administrators. If your tenant has Conditional Access available and it is not configured, that is the single highest-leverage tightening available without buying any new software.

What happens when an employee loses their phone?

If the rollout was set up correctly, the employee uses a pre-issued backup code to sign in once, then re-enrolls a new authenticator on the replacement device. If backup codes were never issued, the employee has to go through an identity-verification reset with whoever administers the tenant, which is fine when planned ahead and a fire drill when not. The lesson is that backup codes should be generated and stored in a safe at the same time the original MFA is enrolled, not after the first phone breaks.

Where Should You Start If Your MFA Setup Feels Behind?

If the picture above does not match how your accounts are protected today, the fastest useful step is a one-hour review of which methods are in place where, which accounts still rely on SMS codes, and whether number matching and Conditional Access are configured. That review usually surfaces two or three changes that close most of the realistic exposure without disrupting the team. From there, the hardware-key rollout for high-risk accounts is a one-week project, and the broader authenticator-app upgrade is a one-month project that runs alongside normal work. If you would like a second set of eyes, O&O Systems can help with scoping the multi-factor authentication review your office needs and the rollout plan that fits the way your team actually works.