In short
Two-factor authentication requires two different proofs at sign-in: something you know (a password) and something you have (a phone or a security key). A stolen password alone then opens nothing. It is the single measure with the best ratio of effort to effect.
Why the password alone stopped working
Because it is rarely guessed — it is reused. A password leaked at any one service gets tried automatically at every other. Length and special characters do nothing against that.
The second factor breaks the chain: what leaks at one service opens nothing at a second.
Not all second factors are equal
SMS is the weakest — numbers can be hijacked, codes intercepted. Still better than no second factor. An authenticator app is the practical standard for an SME. Security keys are the only form that also holds against well-made phishing, because the key checks the website's address.
For most businesses the app is the right point: free, set up in minutes, and it catches the bulk of cases.
Where it snags in practice
On shared accounts. An info mailbox used by three people cannot be cleanly protected with a second factor — the answer is not an exempt account but a shared mailbox with personal sign-ins.
The second snag is recovery codes. Store them nowhere and the first device change locks you out — after which the second factor gets switched off.
How we handle it
We switch two-factor sign-in on across the board, not only for administrators, and set up the recovery path at the same time. A measure that fails at the first device change gets switched off again.
How we work: IT security and Microsoft 365.
Related terms
A term in your quote that nobody explained?
In a strategy call we translate the offer in front of you — even when it did not come from us.