Password management, Multi-Factor Authentication, and access control are the three most foundational security controls your business can implement — and MFA alone blocks 99.9% of automated account compromise attacks. None of this requires an enterprise budget; Microsoft 365 includes MFA for free.

How a Reused Password Cost $220,000 in Ten Minutes
An accounting firm’s bookkeeper used the same password for her email, cloud accounting software, and a recipe website. The recipe site was breached. Attackers tried those exact credentials on Microsoft 365 — they got in. Over three weeks they monitored emails, identified two pending wire transfers, and intercepted both. Total loss: $220,000. The attack itself cost the attacker about ten minutes.
How Attackers Actually Get In
- Credential stuffing — reusing passwords stolen from other breaches; stopped by unique passwords per account
- Password spraying — trying common passwords against many accounts; stopped by a strong password policy plus MFA
- Phishing — tricking an employee into entering real credentials on a fake page; stopped by MFA plus training
- Brute force — automated guessing of short passwords; stopped by length (14+ characters)
- Insider threat — a current or former employee misusing access; stopped by least-privilege and prompt offboarding
- Session hijacking — stealing a browser session token after login; stopped by short session timeouts and device management
What “Strong” Actually Means Now (NIST 2025 Guidance)
The old advice — change every 90 days, add a symbol — has been replaced by guidance that prioritizes length and uniqueness over complexity. A 16-character passphrase of four random words takes an estimated 2.5 million years to crack by brute force; “P@ssw0rd!” takes less than three hours. Length wins. Use a password manager, never reuse passwords, and stop mandating frequent rotation, which just trains employees to add a “1” to the end.
MFA Types, Ranked Weakest to Strongest
- SMS text code — better than nothing, but vulnerable to SIM-swap attacks; avoid if possible
- Email OTP code — only as secure as the email account itself
- TOTP authenticator app (Microsoft Authenticator, Google Authenticator, Authy) — strongly recommended, free, phishing-resistant
- Push notification app — excellent convenience, but train users to never approve a request they did not initiate (MFA fatigue attacks)
- Hardware security key (YubiKey) — the gold standard, phishing-proof; recommended for admins and executives
Enable MFA on Microsoft 365 in 30 Minutes — Free
- Log in to admin.microsoft.com with a Global Administrator account
- Navigate to Identity → Overview → Properties
- Click “Manage security defaults” at the bottom of the page
- Toggle “Security defaults” to Enabled and save
- All users will be prompted to register MFA at next login
- Confirm admin accounts have MFA enforced via Conditional Access
- Tell your team: “You will be asked to set up a second login step — use the Microsoft Authenticator app when prompted”
Least Privilege: Give People Only What They Need
When an attacker compromises a user account, they inherit everything that account can access. If a bookkeeper’s account has admin rights to your entire Microsoft 365 tenant, a compromise of her account means every employee’s email is exposed. Cap Global Administrator accounts at 2-3 people maximum, each protected with hardware MFA, and default every new employee to standard-user access.
Get the Free Password, MFA & Access Control Guide
Our full guide includes the complete password manager comparison table, the MFA fatigue attack warning your employees need to hear, a five-tier access control model, and an offboarding checklist.
The Highest-Impact Change You Can Make Today
Enabling MFA costs nothing and takes 30 minutes. See how we help small businesses implement password, MFA, and access control policies the right way.