If you make only one security change this year, make it this one. Turning on two-factor authentication for Microsoft 365 does more to protect a nursery or small business than anything else for the effort involved. It takes a few minutes to set up and costs nothing. Microsoft says that multifactor authentication, together with blocking older sign-in methods, stops more than 99.9% of common identity-related attacks. Nothing else on the list comes close for the effort.
What two-factor authentication actually is
Your password is the first factor: something you know. Two-factor authentication (2FA), which Microsoft calls multifactor authentication or MFA, adds a second factor, usually your phone.
After you type your password, Microsoft 365 asks for a second proof, normally a tap to approve a notification in the Microsoft Authenticator app. Passwords get stolen, guessed, phished or leaked, often without you noticing. With 2FA, a stolen password on its own is useless, because the attacker does not have your phone.
Why this matters so much for a nursery
For most nurseries, Microsoft 365 is the front door to everything: parent emails, shared files, registers, financial information and photos. One compromised login can expose children's and parents' personal data. That can quickly become a data protection matter for the ICO and something you need to tell Ofsted or Care Inspectorate Wales about.
Attackers look for easy targets: shared logins, reused passwords and no second factor. Turning on 2FA removes that weakness quickly.
Before you start
- Administrator access. You need an administrator account for your Microsoft 365 tenant. Usually that is the owner or the IT supplier who set it up. If you are not sure who holds it, find out now, because you will need it in an emergency too.
- A phone for each person. Every member of staff needs their own phone, because the second factor lives on the device.
- The Microsoft Authenticator app. This is the method to use. It is free on iPhone and Android, approving a sign-in is a single tap, and it is the method Microsoft's security defaults register people for.
Choosing the right method
Microsoft 365 can send codes by text message, but text messages (SMS) are the weakest method and best avoided. Texts can be intercepted, and a criminal can sometimes persuade a mobile network to move your number to their SIM. Microsoft itself recommends that users move away from text messages and voice calls for sign-in and use Microsoft Authenticator instead.
So our advice is simple: register everyone on the Authenticator app and do not rely on texts, not even as a fallback. If someone cannot use the app on their phone, ask your IT supplier about a hardware security key or a passkey instead.
Turning it on for everyone
If you have more than a couple of staff, turn on 2FA across the whole tenant rather than person by person. There are two ways to do this, both managed in the Microsoft Entra admin centre.
Security defaults are free and suit most small nurseries and businesses on Microsoft 365 Business Basic or Business Standard. When security defaults are on, every user must register for multifactor authentication using the Microsoft Authenticator app, and older sign-in methods that cannot do 2FA are blocked. Many newer Microsoft 365 tenants have security defaults switched on already, so it is worth checking yours.
Conditional Access gives you finer control, such as requiring the app rather than weaker methods, or treating sign-ins from unfamiliar countries differently. It needs Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium. If you have Business Premium, Conditional Access is the better choice, and you use it instead of security defaults rather than alongside.
Microsoft changes its menus regularly, so check its current instructions rather than relying on old screenshots. The principle stays the same: an administrator switches the requirement on centrally, and staff register their phones the next time they sign in.
An IT supplier can do this in a few minutes. It is a perfectly reasonable thing to ask, and how they respond tells you a lot about how seriously they take security. It is part of our Microsoft 365 support.
What each member of staff does
The next time each person signs in, Microsoft walks them through a one-off setup: install Microsoft Authenticator, scan the code on screen and approve a test notification. After that, signing in is their usual password followed by a tap on their phone, which adds a couple of seconds.
We recommend getting the team together and doing the setup at the same time. It is the only fiddly step, and it goes much more smoothly when someone is on hand to help.
The common mistakes
- Leaving out the owner or manager. "They are too busy" is not a reason. Their accounts have access to the most and are the most valuable targets, so they need 2FA most of all.
- Falling back on text messages. Texts are better than nothing, but they are the weakest option. Use the Authenticator app for everyone, including as the backup method.
- Ignoring shared or generic logins. A single "office" or "admin" account used by several people is hard to protect with 2FA, because the second factor can only live on one phone. Give each person their own named account. Our guides on strong Windows passwords and access control explain why.
- Forgetting leavers. When someone leaves, remove their account and their registered phone. Our leavers checklist covers this.
What good looks like
- Every member of staff has their own login, and every login requires a second factor, including the manager and owner.
- Everyone uses the Microsoft Authenticator app, not text messages.
- No shared logins sit outside the protection.
- If a password leaks, the outcome is a password reset, not a crisis.
If the worst does happen, our guide on what to do if you've been hacked sets out the first hour step by step. Unsure about any of the terms? Try our jargon buster.
The one thing to take away
Two-factor authentication is the most valuable few minutes you will spend on security. It stops the vast majority of account attacks, costs nothing and turns a stolen password into a non-event. Turn it on for Microsoft 365 first, include the owner and manager accounts, and use the Microsoft Authenticator app rather than text messages.