Multi-Factor Authentication (MFA) requires something you know plus something you have. Rank the methods: passkeys and hardware keys are strongest, then app-based number matching, then push approval, then one-time codes, and Short Message Service (SMS) last — SMS is better than nothing and vulnerable to SIM swapping.
Conditional access turns MFA from a blanket rule into a policy: require MFA for all users, require compliant or hybrid-joined devices for admin roles, block legacy authentication protocols, and optionally restrict sign-in from countries where the business does not operate. Blocking legacy authentication alone removes a huge share of password-spray success.
Roll out in three waves: pilot with the owner and one manager, then departments, then everyone, with a firm deadline announced twice. Run a lunchtime enrolment session with a printed one-pager. The technical work takes an hour; the human work takes two weeks, and skipping it is why MFA projects stall at 60% coverage.
Plan for the lost phone in advance. Document how a user re-enrols: verified identity, temporary access pass, re-register the authenticator, revoke old methods and sessions. Without that runbook, a lost phone becomes a four-hour emergency.