How to Set Up Multi-Factor Authentication (Step by Step)
Multi-factor authentication (MFA) stops most stolen-password attacks. This guide walks you through turning it on for your email, Microsoft 365 and key apps, choosing an authenticator app over SMS, and saving backup codes so you never get locked out. Set aside an hour and start with the accounts that matter most.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
If you only do one thing to protect your business online this year, make it this. Multi-factor authentication (MFA) is the single most effective, lowest-cost step you can take to stop criminals getting into your accounts — even when they have your password. The NCSC recommends it, Cyber Essentials requires it on all cloud services, and turning it on is genuinely straightforward once someone shows you where to click.
This is a hands-on companion to our plain-English explainer, what MFA is and why it matters. Here we get practical: exactly how to switch it on across your email, Microsoft 365 and the apps your business relies on, how to choose the right method, and how to avoid the one mistake that locks people out.
What you’ll need before you start
Set aside about an hour. You don’t need to be technical — if you can install an app and read a code off a screen, you can do this. Have to hand:
- A smartphone — this becomes your “something you have”, the second factor.
- A list of your important accounts — email first, then anything holding money or customer data.
- Somewhere safe to store backup codes — a password manager is ideal, which we’ll come to.
A quick word on why we’re bothering. A password on its own is a single point of failure: if it’s guessed, phished or leaked in a data breach, whoever has it is straight in. MFA adds a second, separate check — a code or a tap on your phone — so a stolen password alone is no longer enough. That’s why it shuts down the overwhelming majority of account-takeover attempts.
Step 1: Install an authenticator app (not SMS)
When you turn on MFA, you’ll usually be offered a few ways to receive that second factor. The most common are:
- A text message (SMS) with a code.
- An authenticator app that generates a rolling six-digit code.
- A prompt you approve with a tap.
Wherever you can, choose the authenticator app. Text-message codes are better than nothing, but they can be redirected to a criminal through “SIM-swap” fraud, and they fail you the moment you’ve got no signal. An authenticator app creates the code on your phone itself — there’s nothing travelling over the network to intercept.
Good, free authenticator apps include Microsoft Authenticator, Google Authenticator and Proton Authenticator. If your team already uses a password manager, many of those can store your MFA codes too, so everything lives in one secure place. Proton Pass, for example, includes a built-in authenticator alongside your logins.
Install your chosen app now, before you go any further. You’ll point it at each account in turn.
Wherever you can, choose the authenticator app. Text-message codes are better than nothing, but they can be redirected to a criminal through “SIM-swap” fraud, and they fail you the moment you’ve got no signal.
Step 2: Turn on MFA for your main email first
Your email account is the master key to everything else. Think about it: forgotten your password to your bank, your accounting software, your online shop? They all email you a reset link. If a criminal controls your inbox, they can walk into every other account you own. So this is where you start.
The wording differs slightly between providers, but the path is almost always the same:
- Log in and open your account or security settings (often under your name or profile picture, top right).
- Find “Two-step verification”, “2-step verification” or “Multi-factor authentication”.
- Choose “Authenticator app” as your method.
- The screen shows a QR code. Open your authenticator app, tap add / +, and scan the code with your phone’s camera.
- Your app now shows a six-digit code. Type it in to confirm the link, and save.
That’s it — your email is now protected. If you use Microsoft 365 or Google Workspace for email, doing this here also covers a big chunk of Step 3.
Step 3: Cover Microsoft 365, Google Workspace and your key apps
With email done, work through the rest of your business logins. Prioritise anything that holds money or personal data:
- Microsoft 365 / Google Workspace — these control your files, email and shared documents. In Microsoft 365, security settings live in the My Account area; admins can also require MFA for the whole team from the admin centre. If you’d like a hand rolling it out across staff accounts, that’s exactly the kind of thing our managed IT support handles.
- Your accounting and payroll software — Xero, QuickBooks, Sage and similar all support MFA.
- Banking and payment tools — usually already require a second factor; make sure it’s switched on for every user.
- Your website, online shop and social media — an attacker who seizes these can damage your reputation and your revenue.
- Your password manager — protect the vault that protects everything else.
The process for each is the same three-part rhythm: open security settings, choose authenticator app, scan the QR code. Once you’ve done two or three, the fourth feels routine.
Step 4: Save your backup codes (don’t skip this)
Here’s the mistake that trips people up. When you enable MFA, most services offer a set of backup codes — usually eight to ten one-time codes. These are your way back in if you lose your phone, break it, or replace it. Save them the moment they’re offered. People who skip this step are the ones who ring us in a panic, locked out of their own email.
Store them somewhere secure and separate from your phone:
- In a password manager — the neatest option, kept encrypted alongside your logins.
- Printed and locked away — a sensible offline backup for your most critical accounts.
Avoid saving them in a plain document called “passwords” on your desktop, or in a note on the same phone that runs the authenticator. If you lose the phone, you want the codes to survive it. A dedicated tool is worth the small effort — see our guide to the best password manager for a UK small business. Apps like Proton Pass store your logins, MFA codes and backup codes together, encrypted.
While you’re at it, turn on your authenticator app’s encrypted cloud backup if it offers one. That way, if you get a new phone, your codes come with you rather than needing to be set up from scratch.
Step 5: Roll it out to your team
Protecting your own accounts is a great start, but your business is only as secure as its least-protected login. A single member of staff without MFA is a door left unlocked. Make MFA a standard, expected part of how everyone works:
- Set it as a requirement, not a suggestion — Microsoft 365 and Google Workspace let admins enforce it for everyone.
- Help people set it up rather than emailing instructions and hoping. Fifteen minutes side by side saves a lot of confusion.
- Cover leavers and new starters in your joiners-and-leavers process so accounts are protected from day one and closed cleanly when someone moves on.
MFA also pairs naturally with strong, unique passwords and good phishing awareness. It’s not a silver bullet — a convincing phishing email can still try to trick someone into approving a login — but together these habits make you a very hard target.
A sensible order to do it in
If the full list feels daunting, don’t try to boil the ocean. Work down in this order and you’ll have blocked the most likely attacks within the first half hour:
- Main business email.
- Microsoft 365 or Google Workspace.
- Banking, accounting and payroll.
- Password manager.
- Website, shop and social media.
- Everything else that supports it.
Turning on MFA is one of those rare security jobs that’s cheap, quick and genuinely effective — and it moves you towards Cyber Essentials at the same time. If you’d rather someone set it up properly across your whole team and check nothing’s been missed, get in touch and we’ll walk through it with you. You can also see how MFA fits into our wider cyber-security services.
Frequently asked questions
How long does it take to set up MFA?
About five minutes per account once you have an authenticator app installed. Start with your main email and Microsoft 365 or Google Workspace login, then work through your banking, accounting and any app that holds customer data. Most small businesses can protect their important accounts in under an hour.
Is an authenticator app really safer than text-message codes?
Yes. Text-message (SMS) codes can be intercepted or redirected to a criminal through SIM-swap fraud, and they rely on you having phone signal. An authenticator app generates codes on your device itself, so there is nothing to intercept. SMS is still far better than no MFA at all, but an app is the stronger choice.
What happens if I lose the phone with my authenticator app on it?
This is exactly what backup codes are for. When you turn on MFA, most services give you a set of one-time recovery codes — save them somewhere safe and you can still get in. Many authenticator apps also offer an encrypted cloud backup so your codes move to a new phone. Set both up before you need them.
Does MFA meet Cyber Essentials requirements?
Cyber Essentials requires multi-factor authentication on all cloud services, so turning it on is a direct step towards certification. Using an authenticator app rather than SMS, and applying it to every account that supports it, keeps you comfortably on the right side of the requirement.
Will MFA slow my team down every time they log in?
Barely. Most business apps only ask for a second factor occasionally — on a new device, from a new location, or every so often as a check — not on every single login. The few seconds it adds is a fair trade for blocking the vast majority of password-based attacks.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.