What MFA does

Multifactor authentication asks for a second proof after the password — usually a code or approval in an authenticator app on the phone. A stolen password alone is then not enough.

In Microsoft 365 you set this centrally for users. Floor ICT can enable or enforce MFA as part of cloud management in the MSP package; you stay responsible for who may have access.

What you set up in practice

Typical SMB steps:

  • prefer an authenticator app (not SMS-only where you can avoid it);
  • put every Microsoft 365 user under the same MFA requirement;
  • define a recovery path for lost phones with your IT partner or admin;
  • add security awareness so phishing is less likely to yield a password.

More depth

MFA versus “a strong password only”

Strong passwords help, but they still leak via phishing, reuse, or a breach elsewhere. MFA adds a second factor so that one password is rarely enough.

What users notice

On new devices or unusual sign-ins they approve a prompt or enter a code. After that, the session often stays usable for a while. Clear onboarding cuts support tickets.

What Floor ICT does

For MSP customers on Microsoft 365, Floor ICT can enable or tighten MFA policy, onboard/offboard accounts, and handle issues via the ticket portal. Academy security awareness helps staff spot phishing — practical hygiene, not a legal guarantee.

Microsoft 365 with Floor ICTView MSP packagesExplore Academy

Questions

Frequently asked questions

Is MFA mandatory?

There is no general Dutch law that forces every SMB to use MFA. It is still a standard security control; insurers and customers often expect it. This is not legal advice.

Does MFA also apply to Google Workspace?

Yes — Google Workspace has 2-step verification. This article focuses on Microsoft 365; the idea is the same: password plus a second factor.

What if someone loses their phone?

An admin or your MSP can reset MFA or help restore access through a documented recovery process — not via a public email address.

All Insights