Skip to content
TECHNOWARE

A two-factor rollout that staff will actually use

The technology is the easy half. The rollout fails on the twelve people who share a login, the director who will not install an app, and the day the phone is lost.

19 March 20263 min readadmin

A two-factor rollout that staff will actually use
Share

Two-factor authentication on email and remote access is the single most effective control a small business can add, and the one most often abandoned two weeks after it is switched on. It is abandoned because it was rolled out as a setting rather than as a change to how people work.

Start with what is exposed

Email, the VPN or remote-desktop gateway, the accounting system if it is in the cloud, and anything with an administrator role. Not the internal wiki. A rollout that covers everything at once produces a week of lockouts and a general instruction to switch it all off; one that covers the four things that matter is done in a day and stays on.

Choose the method for the people, not the policy

  • An authenticator app for anybody with a company phone, or who is willing to put the app on their own. It is the right default.
  • A hardware key for administrators and for anyone who will not install an app on a personal phone — and that refusal is reasonable, not obstructive. A key costs less than an hour of the argument.
  • SMS only where nothing else is possible. It is much better than nothing and materially weaker than the other two; treat it as the exception, not the fallback.

The shared login

Every business has one: sales@, accounts@, the login for the courier portal. Two-factor cannot be attached to a login that twelve people use, and the usual outcome is that it is exempted, which makes it the one account without protection and the one worth attacking.

Turn shared mailboxes into shared mailboxes — delegated access from named accounts, which most mail platforms support natively. For the portal logins that genuinely cannot be individual, put the code in the password manager the team shares, and make sure it is a team password manager rather than a spreadsheet.

Enrol in person, in one session

Do not send the instructions by email. Book fifteen minutes with each person, sit with them, and enrol the app or the key while they watch. Register a second method at the same time — a backup phone number or a printed set of recovery codes in a sealed envelope — because the question is never whether a phone will be lost.

Write down the lost-phone procedure before the first phone is lost

Who can reset a factor, how they verify the person asking, and how long it takes. If the answer is "the IT company, by email, next working day", then a sales manager at an airport on Friday evening has no email until Monday, and the next thing that happens is somebody switching two-factor off for them. A named person in the business with the right to reset, and a verification step that is not "they sounded like themselves on the phone".

Measure it after a month

Every platform reports which accounts have a second factor. The number should be everyone; if it is everyone minus three, those three are the accounts worth attacking, and they are usually the senior ones.

Related

Ran into this on your own network?

If something here matches a problem you are seeing, describe it and we will tell you what we would check first.