The short answer
Multi-factor authentication (MFA) asks for a second proof of identity, such as an app prompt or a security key, as well as a password. It makes a stolen password far less useful to an attacker, and insurers and clients increasingly expect it. To roll it out without a revolt:
- Explain the why in plain language, from leadership, before anyone gets an enrolment email.
- Pick methods that fit how people work, including an option for staff who will not use a personal phone.
- Pilot with a friendly group, fix the rough edges, then roll out in waves.
- Prepare the help desk and a recovery process for lost or replaced phones.
- Enforce on a date people know about, and close exceptions rather than leaving them open.
Choose the right methods
The Canadian Centre for Cyber Security describes three kinds of factor: something you know, something you have and something you are. It strongly recommends phishing-resistant options based on FIDO, and recommends number matching to resist "MFA fatigue" attacks, where an attacker sends prompt after prompt hoping someone taps approve (Cyber Centre).
| Method | Security | Staff experience | Where we use it |
|---|---|---|---|
| Authenticator app with number matching | Good | Familiar, quick | Most staff |
| FIDO2 security key or passkey | Strongest against phishing | Very quick once set up | Administrators, finance, executives |
| Hardware token with one-time codes | Good | Slower, but no phone needed | Staff without a work phone |
| SMS or voice code | Weakest | Easy | Only as a temporary fallback |
In Microsoft 365, number matching is enabled for all Microsoft Authenticator push notifications, so users type the number shown on the sign-in screen into the app (Microsoft Learn). That small step is what defeats most prompt-bombing.
The personal phone objection
This is the question you will hear most, and it deserves a respectful answer. Some staff do not want work apps on a personal phone; some do not have a smartphone; some unions or collective agreements address it. Options:
- Explain that an authenticator app does not give the organization access to the phone's contents.
- Offer a hardware key or token as an equal alternative, not a punishment.
- Provide work phones where the role already justifies one.
Settle this before launch. Nothing drains goodwill faster than a manager telling a staff member "just use your phone".
A phased rollout plan
Weeks 1 to 2: prepare.
- Inventory every way people sign in: email, VPN, remote desktop, cloud apps, finance and payroll portals, and any line-of-business systems.
- Identify service accounts, shared mailboxes and devices such as scanners that send email. These need their own approach, not a blanket exception.
- Create two emergency "break-glass" administrator accounts, protected with strong keys, stored securely and monitored.
- Write the lost-phone process: how staff prove who they are to the help desk, and who can issue a temporary pass.
Week 3: pilot.
- Enrol IT, a few managers and at least one person who is not comfortable with technology.
- Note every question they ask. Those questions become your FAQ.
Weeks 4 to 6: roll out in waves.
- Leadership first, visibly. It is much easier to ask staff to enrol when the CEO already has.
- Department by department, with a short drop-in session or video and a named contact.
- Schedule enrolment away from month-end, payroll and busy seasons.
Week 7: enforce and close gaps.
- Require MFA for everyone and block legacy sign-in protocols that cannot use it.
- Review every exception with an owner and an end date.
Rather talk it through? If your last MFA attempt stalled on exceptions and lost phones, we can plan and support a rollout that sticks. Talk to a Promatics specialist
Communication that works
Keep messages short and specific. A good launch email answers four questions: what is changing, why, what the person needs to do and by when, and where to get help. Avoid jargon such as "conditional access policy". Say "when you sign in from a new device, you will confirm it's you on your phone or with a key".
Bilingual organizations should send messages and instructions in English and French at the same time. Screenshots help more than paragraphs.
What usually goes wrong
- The surprise switch-on. MFA is enforced overnight, half the office is locked out on Monday, and leadership orders it turned off.
- Permanent exceptions. A senior leader, a shared account or an old app is excluded "for now". Attackers find those accounts first.
- SMS forever. SMS codes were meant as a fallback and became the default.
- No recovery process. Someone drops their phone in a lake, and the help desk resets MFA for anyone who calls, which is exactly what an attacker hopes for.
- Forgetting the admins. Staff get MFA; administrator and third-party support accounts do not.
Rollout checklist
- Every sign-in route listed, including VPN, remote desktop and finance portals
- Methods chosen, with a non-phone option available
- Break-glass accounts created, secured and monitored
- Lost-phone and identity verification process written
- Pilot completed and FAQ updated
- Leadership enrolled first
- Messages ready in the languages your staff use
- Legacy sign-in blocked after enforcement
- Every exception has an owner and an end date
- Phishing-resistant methods required for administrators
When to bring in help
A small team on Microsoft 365 or Google Workspace can often roll out MFA with the built-in tools and this plan. Bring in a professional when you have several systems with separate sign-ins, older applications that do not support modern authentication, remote access through a VPN or remote desktop, or a previous attempt that stalled.
An AI assistant can draft your staff email. It cannot see the service account buried in your tenant, sit with a nervous user during enrolment, or take the 7 a.m. call from an executive locked out before a board meeting. Our cybersecurity services team plans the rollout, supports staff through it, and for managed-service clients provides 24/7 monitoring and support afterwards. For Microsoft-specific configuration, see our Microsoft 365 security baseline.
Limitations
This article describes a general approach. Product features, licence requirements and defaults change; check current vendor documentation for your platform. Employment and privacy considerations around personal devices vary by province and workplace, so involve HR and, where relevant, employee representatives.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Secure your accounts and devices with multi-factor authentication (ITSAP.30.030), Canadian Centre for Cyber Security
- How number matching works in MFA push notifications for Authenticator, Microsoft Learn
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.