Contact Support

If you are an existing client to get support call us on:

+44 (0)1483 412 042

OR

Login to the portal

Support portal

If you've been given a 6-digit support code

click here

Not an existing customer?

Contact us

Multi-factor authentication: why you should be using it and how to implement it

 

What is multi-factor authentication (MFA)?

 

Multi-Factor Authentication (MFA), is something everyone will have experienced, it’s the additional levels of security used when you sign into a banking app, or when you try to change a password and a verification code is sent to your mobile phone, or when you are asked to answer additional security questions after already providing your password. All of these examples are extra security measures that allow you to prove you are who you say you are and provide peace of mind that hackers can’t impersonate you. Up until now, most organisations have not considered implementing this additional layer of protection into their corporate data, but with Office 365 it’s now a realistic, cost effective option to improve the protection of your business data.

Why use MFA?

 

Obviously, the main reason for using MFA is security, if it is set-up correctly it eliminates the risk of an account being compromised because of a weak, shared or known password. Increasing numbers of accounts (including Office 365) are being compromised, because users have used the same password across different systems, such as LinkedIn and Adobe, (which have had their account databases stolen) giving hackers the ability to hack users work accounts. With MFA even if someone knows your username and password, they are not able to log-in without access to your mobile phone or land-line (if that’s set-up as another authentication mechanism).

What’s the user experience?

 

It is possible to set-up MFA to not to be required when logging in from a trusted network, so users won’t become frustrated by having to provide additional authentication when in the office.

Choosing the security verification method in Office 365

When out of the office a user can log in as normal using their username and password, if they are using an authenticator app on a mobile device (which is certainly the easiest option) they get prompted to approve the login.

Using an authenticator app

If they click ‘approve’ they are logged straight in. Other options are using a code from the authenticator app, being sent a code by text, or a phone call with a recorded message giving a code.

So, the user experience should be quick and fairly seamless.

 

Implementing multi-factor authentication and the risk factors.

 

Introducing MFA must be planned as a project as it’s potentially disruptive to end-users and could leave them unable to work. The risks organisations need to consider prior to implementing MFA, to ensure a smooth implementation experience are

  • End-users may not get the correct authentication methods set-up, leaving them with a poor experience.
  • End-users may forget some apps or devices and have issues at a later stage.
  • Significant risk of end-users not being able to work across multiple applications if they are not given proper support and guidance during the implementation

When implementing MFA for organisations we follow several golden rules.

  1. Identify any applications that may integrate with Office 365, as those integrations may require an app password and will fail when MFA is enabled.
  2. Carry out an initial trial with just one or two users, so the trial can be paused quickly if any issues arise, so they can be quickly resolved
  3. After the initial trial, implement gradually throughout the organisation to minimise disruption if issues are uncovered.
  4. Provide plenty of support to each user to ensure they are confident in how MFA works and have a positive user experience.

 

See more information on how to protect your organisation against cybercrime
Registration No. 26980136
Terms and Conditions | Privacy Notice
Richard Renson
Richard Renson
16:54 10 Dec 18
Great, helpful IT Kings and Queens
Andrew Worth
Andrew Worth
12:37 30 Aug 18
fine bunch
Colin Warner
Colin Warner
08:46 06 Dec 17
Excellent managed service provider.
Selom B
Selom B
11:58 10 Dec 16
First Class!! Responsive, knowledgeable, professional and very easy to work with - Ramsac have been a fantastic strategic IT partner for the last few years and I'm sure will continue to be for many years going forward. I would highly recommend them!
Ian Windle - Inspiring Leadership
Ian Windle - Inspiring Leadership
08:53 04 Jul 16
Great IT business, with a powerful management team. Could not recommend them more highly.
Patrick O'Luanaigh
Patrick O'Luanaigh
10:55 01 Jul 16
A truly fantastic IT support company - I can't speak highly enough about them.
Sarah Whitemore
Sarah Whitemore
11:59 20 Jun 16
I have known Dan May and Ramsac for 5 or 6 years now. Dan is such a great guy and really helpful with strategic advice and input on all things IT. He's so approachable and doesn't baffle you with IT jargon. If you are looking to outsource your IT or you have a problem you need help with Dan is definitely the one to ask.
Jonathan Richards
Jonathan Richards
12:14 31 May 16
I've worked with Ramsac for many years and whole heartedly recommend their services. They are always professional, approachable and have the rare skill of making IT understandable. Their can do attitude leaves you feeling that you are in safe hands.
See All Reviews
© 2019 ramsac. All rights reserved.