Guide

Two-factor authentication on Microsoft 365

If you only make one security change this year, make it this one. It takes minutes and costs nothing.

If you make only one security change this year, make it this one. Turning on two-factor authentication for Microsoft 365 does more to protect a nursery or small business than anything else for the effort involved. It takes a few minutes to set up and costs nothing. Microsoft says that multifactor authentication, together with blocking older sign-in methods, stops more than 99.9% of common identity-related attacks. Nothing else on the list comes close for the effort.

What two-factor authentication actually is

Your password is the first factor: something you know. Two-factor authentication (2FA), which Microsoft calls multifactor authentication or MFA, adds a second factor, usually your phone.

After you type your password, Microsoft 365 asks for a second proof, normally a tap to approve a notification in the Microsoft Authenticator app. Passwords get stolen, guessed, phished or leaked, often without you noticing. With 2FA, a stolen password on its own is useless, because the attacker does not have your phone.

Why this matters so much for a nursery

For most nurseries, Microsoft 365 is the front door to everything: parent emails, shared files, registers, financial information and photos. One compromised login can expose children's and parents' personal data. That can quickly become a data protection matter for the ICO and something you need to tell Ofsted or Care Inspectorate Wales about.

Attackers look for easy targets: shared logins, reused passwords and no second factor. Turning on 2FA removes that weakness quickly.

Before you start

  • Administrator access. You need an administrator account for your Microsoft 365 tenant. Usually that is the owner or the IT supplier who set it up. If you are not sure who holds it, find out now, because you will need it in an emergency too.
  • A phone for each person. Every member of staff needs their own phone, because the second factor lives on the device.
  • The Microsoft Authenticator app. This is the method to use. It is free on iPhone and Android, approving a sign-in is a single tap, and it is the method Microsoft's security defaults register people for.

Choosing the right method

Microsoft 365 can send codes by text message, but text messages (SMS) are the weakest method and best avoided. Texts can be intercepted, and a criminal can sometimes persuade a mobile network to move your number to their SIM. Microsoft itself recommends that users move away from text messages and voice calls for sign-in and use Microsoft Authenticator instead.

So our advice is simple: register everyone on the Authenticator app and do not rely on texts, not even as a fallback. If someone cannot use the app on their phone, ask your IT supplier about a hardware security key or a passkey instead.

Turning it on for everyone

If you have more than a couple of staff, turn on 2FA across the whole tenant rather than person by person. There are two ways to do this, both managed in the Microsoft Entra admin centre.

Security defaults are free and suit most small nurseries and businesses on Microsoft 365 Business Basic or Business Standard. When security defaults are on, every user must register for multifactor authentication using the Microsoft Authenticator app, and older sign-in methods that cannot do 2FA are blocked. Many newer Microsoft 365 tenants have security defaults switched on already, so it is worth checking yours.

Conditional Access gives you finer control, such as requiring the app rather than weaker methods, or treating sign-ins from unfamiliar countries differently. It needs Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium. If you have Business Premium, Conditional Access is the better choice, and you use it instead of security defaults rather than alongside.

Microsoft changes its menus regularly, so check its current instructions rather than relying on old screenshots. The principle stays the same: an administrator switches the requirement on centrally, and staff register their phones the next time they sign in.

An IT supplier can do this in a few minutes. It is a perfectly reasonable thing to ask, and how they respond tells you a lot about how seriously they take security. It is part of our Microsoft 365 support.

What each member of staff does

The next time each person signs in, Microsoft walks them through a one-off setup: install Microsoft Authenticator, scan the code on screen and approve a test notification. After that, signing in is their usual password followed by a tap on their phone, which adds a couple of seconds.

We recommend getting the team together and doing the setup at the same time. It is the only fiddly step, and it goes much more smoothly when someone is on hand to help.

The common mistakes

  • Leaving out the owner or manager. "They are too busy" is not a reason. Their accounts have access to the most and are the most valuable targets, so they need 2FA most of all.
  • Falling back on text messages. Texts are better than nothing, but they are the weakest option. Use the Authenticator app for everyone, including as the backup method.
  • Ignoring shared or generic logins. A single "office" or "admin" account used by several people is hard to protect with 2FA, because the second factor can only live on one phone. Give each person their own named account. Our guides on strong Windows passwords and access control explain why.
  • Forgetting leavers. When someone leaves, remove their account and their registered phone. Our leavers checklist covers this.

What good looks like

  • Every member of staff has their own login, and every login requires a second factor, including the manager and owner.
  • Everyone uses the Microsoft Authenticator app, not text messages.
  • No shared logins sit outside the protection.
  • If a password leaks, the outcome is a password reset, not a crisis.

If the worst does happen, our guide on what to do if you've been hacked sets out the first hour step by step. Unsure about any of the terms? Try our jargon buster.

The one thing to take away

Two-factor authentication is the most valuable few minutes you will spend on security. It stops the vast majority of account attacks, costs nothing and turns a stolen password into a non-event. Turn it on for Microsoft 365 first, include the owner and manager accounts, and use the Microsoft Authenticator app rather than text messages.

Questions

Is two-factor authentication free on Microsoft 365?

Yes. Security defaults, which turn on multifactor authentication for everyone, are included at no extra cost. Conditional Access needs Microsoft Entra ID P1, which comes with Microsoft 365 Business Premium.

Can staff use text message codes instead of the app?

We advise against it. Text messages are the weakest method and Microsoft recommends moving away from them. The Microsoft Authenticator app is the method to use.

What if a member of staff does not want the app on their personal phone?

The Authenticator app does not give the nursery or business any access to their personal data. If someone still objects, a small hardware security key is an alternative your IT supplier can set up.

What happens if someone loses their phone?

Your Microsoft 365 administrator can reset their sign-in methods so they can register a new phone. Tell your IT supplier straight away so the old device can no longer be used.

Want to know where your business stands?

Our free exposure check shows what an attacker can already see: leaked passwords, email spoofing and exposed systems. Fifteen minutes, nothing to install.

More guides