The owners’ blog #1
5th December 2025
AI Phishing: The New Threat to Small Businesses
13th February 2026
Show all

Email security remains one of the biggest risks facing businesses today. The vast majority of cyber attacks we see start with a compromised email account, often caused by stolen or guessed passwords.

To significantly reduce this risk, we’re taking the stance that Multi-Factor Authentication (MFA) needs to be on for every person and every mailbox used in Microsoft 365.

What is changing?

With immediate effect, if we identify a Microsoft 365 person or business that is not using Multi-Factor Authentication (MFA), we will enable it by default.

This will no longer be treated as an optional recommendation. The volume and frequency of email-related security compromises have reached a point where MFA must be considered a minimum security requirement for Microsoft 365.

What is Multi-Factor Authentication (MFA)?

Multi-Factor Authentication (MFA) adds an extra layer of security to your Microsoft 365 account.

In simple terms:

  • You enter your email address and password as normal
  • You are then asked to approve the sign-in using a second factor
  • This second factor is typically a prompt on your mobile phone

Even if a password is stolen, reused, or guessed, MFA makes it significantly harder for an attacker to gain access to your account.

Why are we enforcing MFA by default?

Email is the primary entry point for cyber attacks, including phishing, invoice fraud, and account takeovers. Across the industry, we see compromises regularly. Turning on MFA reduces the chances of your account being compromised.

If MFA is not currently enabled for your business or mailboxes:

  • We will enable it over the coming weeks
  • It will be enabled by default for any new staff members

How does MFA work in practice?

Most users will use the Microsoft Authenticator app, installed on a smartphone (iOS or Android).

In practice:

  • The app sends a notification when you sign in
  • You approve the sign-in by confirming a number shown on screen or approving the prompt
  • This usually happens when signing in on a new device or location

A smartphone with access to install apps is required to use Microsoft Authenticator. If this is not currently possible for you, this needs to be discussed with us as a priority.

Impact on scan-to-email and printers

Enabling Microsoft’s Security Defaults policy (required to properly enforce MFA) has an important side effect:

  • Scan-to-email using Microsoft 365 credentials will stop working
  • Microsoft considers this method insecure and actively blocks it

If you rely on scan-to-email from printers or multifunction devices, we will need to look at secure alternatives, such as:

  • Scan to a network folder
  • Scan to SharePoint or OneDrive
  • Using a separate email service configured directly on the printer

Scan-to-email using Microsoft 365 credentials should be considered legacy and insecure, and we will advise on the most appropriate alternative for your setup.

Important: MFA improves security, but it is not a guarantee

While MFA dramatically improves account security, it does not make you immune to compromise.

Accounts can still be breached through:

  • Sophisticated phishing attacks
  • Malicious or accidental approval of sign-in requests
  • Infected or poorly secured devices
  • Using Insecure Wifi networks

Good security still relies on vigilance:

  • Be cautious with unexpected emails and links
  • Question unusual sign-in prompts
  • Report anything suspicious immediately
  • Avoid using public Wi-Fi networks (for example, cafés and shops)

MFA is a critical layer of defence, but it is not a silver bullet.

If this change affects your systems

If enabling MFA impacts any of your systems or workflows (particularly scanning), please contact us. We will help you plan and implement secure alternatives.

If you already know that you are not using MFA and would like it enabled sooner rather than later, please contact us at help@lucidcomputersolutions.co.uk.


Frequently Asked Questions (FAQ)

Do I really need MFA if I have a strong password?

Yes. Strong passwords help, but they can still be stolen through phishing, malware, or data breaches elsewhere. MFA protects your account even if your password is compromised.

Will I have to approve a sign-in every time I check my email?

No. MFA typically prompts you:

  • When signing in on a new device
  • When signing in from a new location
  • When Microsoft detects unusual activity

Day-to-day use is usually unaffected.

What if I don’t have a smartphone?

A smartphone is the preferred and most secure method. If this is not possible for you, please contact us so we can discuss alternative options. This must be addressed before MFA is enforced.

Will MFA stop my printer from scanning to email?

In most cases, yes. Microsoft blocks scan-to-email using Microsoft 365 credentials when Security Defaults are enabled. We will help you move to a more secure alternative, such as scan-to-folder or SharePoint.

Can accounts still be hacked with MFA enabled?

Yes, it is still possible, but far less likely. MFA significantly reduces risk, especially from common attacks. Remaining vigilant is still essential.

Is this optional?

No. For Microsoft 365 environments we support, MFA is now a baseline security requirement and will be enabled where it is not already in place.

Comments are closed.