How does multi-factor authentication work?
- Switch it on for email and the identity provider first, because those reset passwords everywhere else.
- Prefer an authenticator app or a hardware key over text messages, which can be redirected to another phone.
- Enforce it by policy across every account rather than leaving it to individual choice.
- Keep recovery codes somewhere secure and separate, so a lost phone does not lock out a whole desk.
- Audit each quarter for accounts that still lack it, starting with finance and admin logins.
A worked example
A freight brokerage had a booking address compromised through a reused password and nearly paid an altered invoice. It now enforces app-based verification on Microsoft 365 for everyone, including the remote assistants working the load board, and keeps recovery codes in a password manager the operations manager controls. Two months later a phishing attempt captured a password, the login failed at the second step, and the alert reached the manager the same morning.
Where does multi-factor authentication show up in your tools?
Google Workspace and Microsoft 365 both enforce it centrally across every connected app, which is the change worth making first. Zendesk, HubSpot, Shopify, Xero, RingCentral and Dialpad each carry their own setting under security or admin, for accounts that sign in directly.
Common mistakes
- Protecting the CRM but leaving the mailbox open, which is exactly where password resets arrive.
- Relying on text codes for finance logins, which fail against a phone number takeover.
- Switching it off for a shared account because it was inconvenient, which reopens the original hole.
Why does multi-factor authentication matter?
Most small-business breaches start with a password rather than anything sophisticated, and passwords get reused far more often than anyone admits. A second step makes a stolen one close to useless and turns an attack into an alert you can act on. For a business letting remote staff into its systems, it is the single control that does the most work.
How does AssistBPO handle multi-factor authentication?
Every AssistBPO assistant signs in to your systems through a named account protected by a second factor, from a managed device in a controlled workspace. We never ask you to send a password by email or chat, and we never work from a login shared between people. Where your tools support single sign-on we prefer it, because it keeps the whole access list under your control.