Email security remains one of the biggest risks facing businesses today. The vast majority of cyber attacks we see start with a compromised email account, often caused by stolen or guessed passwords.
To significantly reduce this risk, we’re taking the stance that Multi-Factor Authentication (MFA) needs to be on for every person and every mailbox used in Microsoft 365.
With immediate effect, if we identify a Microsoft 365 person or business that is not using Multi-Factor Authentication (MFA), we will enable it by default.
This will no longer be treated as an optional recommendation. The volume and frequency of email-related security compromises have reached a point where MFA must be considered a minimum security requirement for Microsoft 365.
Multi-Factor Authentication (MFA) adds an extra layer of security to your Microsoft 365 account.
In simple terms:
Even if a password is stolen, reused, or guessed, MFA makes it significantly harder for an attacker to gain access to your account.
Email is the primary entry point for cyber attacks, including phishing, invoice fraud, and account takeovers. Across the industry, we see compromises regularly. Turning on MFA reduces the chances of your account being compromised.
If MFA is not currently enabled for your business or mailboxes:
Most users will use the Microsoft Authenticator app, installed on a smartphone (iOS or Android).
In practice:
A smartphone with access to install apps is required to use Microsoft Authenticator. If this is not currently possible for you, this needs to be discussed with us as a priority.
Enabling Microsoft’s Security Defaults policy (required to properly enforce MFA) has an important side effect:
If you rely on scan-to-email from printers or multifunction devices, we will need to look at secure alternatives, such as:
Scan-to-email using Microsoft 365 credentials should be considered legacy and insecure, and we will advise on the most appropriate alternative for your setup.
While MFA dramatically improves account security, it does not make you immune to compromise.
Accounts can still be breached through:
Good security still relies on vigilance:
MFA is a critical layer of defence, but it is not a silver bullet.
If enabling MFA impacts any of your systems or workflows (particularly scanning), please contact us. We will help you plan and implement secure alternatives.
If you already know that you are not using MFA and would like it enabled sooner rather than later, please contact us at help@lucidcomputersolutions.co.uk.
Yes. Strong passwords help, but they can still be stolen through phishing, malware, or data breaches elsewhere. MFA protects your account even if your password is compromised.
No. MFA typically prompts you:
Day-to-day use is usually unaffected.
A smartphone is the preferred and most secure method. If this is not possible for you, please contact us so we can discuss alternative options. This must be addressed before MFA is enforced.
In most cases, yes. Microsoft blocks scan-to-email using Microsoft 365 credentials when Security Defaults are enabled. We will help you move to a more secure alternative, such as scan-to-folder or SharePoint.
Yes, it is still possible, but far less likely. MFA significantly reduces risk, especially from common attacks. Remaining vigilant is still essential.
No. For Microsoft 365 environments we support, MFA is now a baseline security requirement and will be enabled where it is not already in place.