Security · Identity & Access

MFA for Small Business: What Should You Protect First?

Turn on MFA everywhere you reasonably can. If you cannot do everything today, protect the accounts that could give an attacker the most control: administrator access, email, financial systems, remote access and sensitive business data.

Research basis: This guide is based on current cybersecurity guidance from CISA, NIST and the FTC. Tech Fit Guide does not claim hands-on testing of authentication products discussed in this guide.

The short answer

Multi-factor authentication (MFA) asks for more than a password before granting access. That matters because a stolen password should not be enough to take over a critical business account. NIST recommends enabling MFA on accounts that offer it, with phishing-resistant MFA preferred.

If you have to prioritize, start here

PriorityProtect firstWhy it matters
1Administrator and privileged accountsThese accounts can change security settings, users and access across other systems.
2Business emailEmail can be used for password resets, impersonation, invoice fraud and access to other services.
3Banking, accounting, payroll and payment systemsCompromise can lead directly to financial loss or fraudulent payments.
4Remote access and cloud productivityThese services can expose files, applications and internal resources from outside the office.
5Systems containing sensitive customer or employee dataHigher-impact data deserves stronger authentication and tighter access control.
6Website, domain, social and other business-critical accountsTakeovers can disrupt operations, redirect customers or damage the business's reputation.

This is a rollout order, not a reason to stop at six categories. The goal is MFA on all supported business accounts, while using stronger methods for the accounts where compromise would hurt most.

Not all MFA is equally strong

MethodPractical fitSecurity note
Passkey / FIDO security keyBest choice for admins and sensitive systems when supportedPhishing-resistant because authentication is bound to the legitimate service.
Authenticator app with push or one-time codeGood practical step for many business accountsStronger than password-only access, but one-time codes and some approval prompts can still be phished or socially engineered.
SMS or email codeUse when stronger options are unavailableStill adds a barrier, but it is not phishing-resistant and should not be your first choice for high-value accounts.

NIST identifies FIDO authenticators used with WebAuthn as a widely available form of phishing-resistant authentication. These may be hardware security keys or authenticators built into a phone or computer. In many services, that experience appears to users as a passkey.

A practical rollout for a small business

  1. Inventory the accounts. Include cloud services, local administrative accounts, financial platforms, remote-access tools, domain and website administration, and vendor portals.
  2. Identify privileged users. Separate everyday accounts from accounts that can administer systems or users.
  3. Enable MFA on the highest-impact accounts first. Start with administrators and email, then financial, remote-access and sensitive-data systems.
  4. Choose phishing-resistant authentication where available. Prioritize it for administrators and applications holding sensitive information.
  5. Roll MFA out to everyone else. Do not leave ordinary employee accounts password-only simply because the highest-risk accounts are finished.
  6. Document recovery. Know how access will be restored if a phone is lost, an employee leaves or a security key fails.

Do not let recovery become the weak link

Before enforcing MFA, create a recovery process. Keep backup authentication methods under business control, protect recovery codes, and make sure more than one authorized person can recover critical company-owned services when appropriate. Avoid building a system where one employee's personal phone is the only path back into a business account.

Onboarding and offboarding matter too

MFA is part of access management, not a one-time setup project. Give new employees only the access they need, require the approved authentication method, and remove access promptly when responsibilities change or employment ends. NIST's small-business guidance specifically recommends limiting administrative privileges and removing access when it is no longer needed.

What about compliance?

Some businesses have legal, contractual or industry-specific authentication requirements. For example, the FTC Safeguards Rule requires covered financial institutions to implement MFA for people accessing customer information, subject to the rule's stated exception. Treat requirements for your business as a compliance question, not as something a general technology guide can determine for you.

Tech Fit Guide's fit rule

Use MFA everywhere it is available; use phishing-resistant MFA where the consequences of compromise are highest. If time or staffing forces a staged rollout, secure privileged accounts and email first, then financial systems, remote access and sensitive-data applications. Do not treat SMS MFA as equivalent to a security key or passkey simply because both are called “MFA.”

Small-business MFA checklist

  • Inventory business accounts and identify which support MFA.
  • Protect all administrator and privileged accounts.
  • Protect business email and password-reset channels.
  • Protect banking, accounting, payroll and merchant accounts.
  • Protect remote-access, cloud-storage and productivity accounts.
  • Use phishing-resistant MFA for high-impact accounts where supported.
  • Store recovery methods securely and test the recovery process.
  • Remove access promptly when an employee or vendor no longer needs it.
  • Review MFA coverage when adding a new business service.

Sources and further reading

Next: Compare Password Managers for Small Business →

Also: Build a Small Business Backup Strategy →

Review the Small Business Cybersecurity Checklist →

← Back to security guides