Home / Blog / Security

MFA for MSMEs: The Highest Value Spend

SECURITY · OCTOBER 2026 · 4 MIN READ · TEKPRO CLOUD TEAM

If you have a limited security budget and want the largest reduction in risk per rupee, the answer is not a firewall, an antivirus upgrade or a monitoring tool. It is multi factor authentication on your identity provider, and the gap between it and everything else is wide.

The reason is where attacks actually come from. Microsoft reports in the order of 600 million identity attacks a day across its estate, and more than 99 percent of them are password based. Not clever exploits, not zero days. Someone trying a password that worked somewhere else.

We are a Microsoft partner, so the licensing detail below is Microsoft specific. The principle applies whatever identity provider you use.

The evidence

Microsoft's own study of Azure AD accounts found MFA reduced the risk of compromise by 99.22 percent. The figure that matters more for a small business is the second one: even for accounts whose passwords had already leaked, MFA still prevented compromise 98.56 percent of the time.

Read that again, because it is the whole argument. Your staff reuse passwords. Some of those passwords are already in a breach dump. MFA means that mostly does not matter.

Nothing else available to an MSME at this price does that.

The part most articles leave out

MFA is not a solved problem, and pretending otherwise sets you up badly.

The residual attacks succeed through three routes: SIM swapping, MFA fatigue where a user eventually taps approve on the twentieth prompt, and phishing proxies. That third one deserves attention because it defeats the MFA most businesses deploy.

An adversary in the middle kit puts a fake login page between your user and the real service. The user enters their password, receives a genuine code or push, approves it, and the attacker captures the session cookie issued afterwards. The MFA worked exactly as designed, and the attacker now holds a valid session. These kits are commercial products, sold and hosted at scale.

One time codes and push approvals do not stop this. That is not a configuration mistake, it is how those factors work.

So not all MFA is equal

CISA classifies only two things as phishing resistant: FIDO2 and WebAuthn, which in practice means passkeys and hardware security keys, and PKI certificates. These resist proxy attacks because the credential is bound to the real website origin, so there is nothing for a fake page to replay.

If you cannot move everyone to passkeys yet, number matching on push approvals is the recommended interim step, because it stops a user approving a prompt they did not trigger.

The practical position for most Indian MSMEs: get everyone onto app based MFA with number matching now, and move your administrators and anyone touching money onto passkeys or hardware keys first. Those accounts are where a proxy attack pays for itself.

What it actually costs

Less than most owners assume, because the basics are already in your tenant.

  • Security defaults are free on every tier. One switch enforces MFA registration for all users, requires MFA for administrators, prompts on risky sign ins, and blocks legacy authentication protocols. For a business with nothing in place, this is the single highest value hour of work available.
  • Per user MFA is also free, and is the older approach. It prompts on nearly every sign in regardless of context, which is why people disable it.
  • Conditional access is the modern method, deciding when to require MFA based on user, application, location, device state and risk. It needs Entra ID P1, which is included in Microsoft 365 Business Premium and E3.

Two things worth knowing before you flip anything. Security defaults are all or nothing, so every user is treated identically with no way to apply stricter rules to privileged accounts or relax anything on a trusted network. And security defaults and conditional access cannot both be enabled, so moving to conditional access means turning the simple option off.

Security defaults are the right starting point and the wrong ending point. Turn them on today, and plan the move to conditional access as you grow.

A realistic order of work

  • Turn on security defaults if you have nothing, today, before reading further.
  • Move administrators to separate accounts that are not used for daily email.
  • Put passkeys or hardware keys on administrators and finance accounts.
  • Enable number matching for everyone still on push approvals.
  • When you reach Business Premium or E3, replace security defaults with conditional access so you can treat privileged accounts differently.
  • Review who holds administrative rights every quarter. Most businesses have more admins than they think.

This is the practical detail behind the argument we made in zero trust for SMBs without a security team, which is that identity is where a small business should start.

If you would like a straightforward review of your current identity position and what your existing licences already cover, start the conversation on our contact page.

Share this Link copied

Want this applied to your business?

Book a free 30 minute strategy session with our certified experts.

Book a Session