CTS - Computer Technology Specialists
MFA Enforcement for Melbourne SMBs
Multi-factor authentication is the single highest-impact cybersecurity control for Melbourne SMBs — it blocks the majority of credential-based attacks, including phishing and password spraying, regardless of whether passwords are already compromised.
Melbourne IT support with visible local credentials
CTS - Computer Technology Specialists has supported Melbourne SMBs since 2000. Contact: 1300 790 780, hello@cts.au, L30 - 35 Collins St Melbourne 3000.
Certifications, affiliations and technology partners
Microsoft Partner, ACSC Essential Eight aligned, ISO 27001 practices, NBN Business Accredited Adviser, Cisco Partner, Dell Partner, HPE Partner, Arcserve Partner, Broadcom Partner, Kyocera Partner.
Why MFA is non-negotiable for Melbourne businesses
Credential theft is the most common initial access method in cyberattacks against Australian SMBs. Once an attacker has a valid username and password — through phishing, credential stuffing, or purchase from a breach database — they can access cloud services, email, files, and financial systems as if they were the legitimate user. MFA stops this by requiring a second factor that the attacker does not have. Microsoft reports that MFA blocks more than 99% of automated credential attacks. For Melbourne businesses using Microsoft 365, Entra ID, or any cloud service accessible from the internet, MFA on every account is the baseline.
Authenticator app vs SMS — the security difference
SMS-based MFA is better than no MFA, but it is vulnerable to SIM swapping — where an attacker convinces a telco to port the victim's number to a new SIM. Authenticator app MFA (Microsoft Authenticator, Google Authenticator) does not depend on the phone number and cannot be intercepted the same way. Number matching — where the app displays a number that must be entered to approve a sign-in request — also defends against MFA fatigue attacks, where attackers spam approval requests hoping the user will accept one. CTS recommends Microsoft Authenticator with number matching as the standard MFA method.
Phishing-resistant MFA — FIDO2 and passkeys
The Essential Eight Maturity Level 3 requires phishing-resistant MFA — methods where the second factor cannot be captured by a fake login page. FIDO2 hardware security keys (such as YubiKey) and device-bound passkeys meet this requirement. They work by binding the credential to the specific website domain — even if a user is redirected to a convincing fake login page, the passkey will not authenticate because the domain does not match. For Melbourne businesses handling sensitive data under regulatory frameworks, phishing-resistant MFA is increasingly required.
Conditional access policies in Entra ID
Entra ID conditional access allows MFA to be enforced based on context — who is logging in, from which device, from which location, and at what risk level. A well-configured conditional access policy can require MFA for all users on all apps, enforce device compliance as a condition of access, block sign-ins from high-risk countries, and require additional verification when the sign-in risk score is elevated. CTS configures baseline conditional access policies for all managed IT clients, with additional policies tailored to the client's industry risk profile.
MFA and the Essential Eight
MFA is one of the eight mitigation strategies in the ACSC Essential Eight, and the one with the most prescriptive maturity level requirements. Maturity Level 1 requires MFA for remote access and internet-facing services. Maturity Level 2 requires MFA for all cloud services and for users accessing sensitive data systems. Maturity Level 3 requires phishing-resistant MFA for privileged accounts and all users accessing sensitive systems. For Melbourne businesses targeting Essential Eight Maturity Level 2 — which is the standard required by most insurers and regulators — MFA must cover all Microsoft 365 accounts without exception.
How CTS enforces MFA for Melbourne SMBs
CTS implements MFA enforcement through Entra ID conditional access as part of the managed IT onboarding process. Legacy authentication protocols (which bypass MFA) are blocked. All accounts — including service accounts and shared mailboxes — are audited for MFA registration. Exceptions require documented justification and mitigating controls. CTS monitors MFA health through the Entra ID identity protection dashboard and reports on coverage in quarterly reviews.
Frequently asked questions
What is the difference between SMS MFA and an authenticator app?
SMS MFA is better than no MFA but is vulnerable to SIM swapping — where an attacker convinces a telco to port your number to a new SIM. Microsoft Authenticator with number matching is more secure: it cannot be intercepted the same way and defends against MFA fatigue attacks where attackers spam approval prompts hoping a user will accept one. CTS recommends Microsoft Authenticator with number matching as the standard MFA method for Melbourne SMBs.
Is MFA required for Essential Eight compliance?
Yes. MFA is one of the eight Essential Eight mitigation strategies. Maturity Level 1 requires MFA on internet-facing services and remote access. Maturity Level 2 requires MFA on all cloud services without exception. Maturity Level 3 requires phishing-resistant MFA (FIDO2 keys or passkeys) for privileged accounts and all users accessing sensitive systems. For most Melbourne SMBs targeting ML2, every Microsoft 365 account must have MFA enforced through conditional access.