← All guides
Guide

How to Set Up Azure AD MFA for Your Small Business

Step-by-step guide to enabling multi-factor authentication in Azure Active Directory for small businesses. Protect your team without the complexity.

Multi-factor authentication (MFA) is one of the most effective ways to protect your business from unauthorized access. If you're using Microsoft 365 or Azure services, you already have access to Azure Active Directory (Azure AD) MFA—and setting it up is more straightforward than you might think.

This guide walks you through enabling MFA for your small business, without the enterprise jargon or unnecessary complexity.

Why MFA Matters for Small Businesses

Before we dive into the setup, let's be clear about why this matters. Passwords alone aren't enough anymore. Even strong passwords can be compromised through phishing emails, data breaches, or simple human error.

MFA adds a second layer of verification—usually a code sent to a phone or generated by an app—that makes it exponentially harder for attackers to access your systems. For small businesses, this is critical protection that doesn't require a massive IT budget.

What You'll Need Before Starting

Before you begin the setup process, make sure you have:

  • Admin access to your Microsoft 365 or Azure AD tenant
  • A list of users who need MFA enabled (we recommend everyone)
  • Communication plan to notify your team about the change
  • 15-30 minutes of uninterrupted time

It's also helpful to have your own smartphone ready, as you'll likely want to test the setup with your own account first.

Step 1: Access Azure Active Directory

Log into the Microsoft 365 admin center with your administrator account.

From the left navigation menu, look for "Show all" to expand all options, then navigate to Azure Active Directory. You may see it listed under "Admin centers."

If this is your first time accessing Azure AD, you might be prompted to set up your Azure account. Follow the prompts—this doesn't cost anything for basic MFA functionality.

Step 2: Navigate to MFA Settings

Once you're in the Azure Active Directory admin center:

  1. Click on Users in the left sidebar
  2. Look for Per-user MFA in the top menu (you may need to click "..." for more options)
  3. This opens the multi-factor authentication configuration page

Alternatively, you can use Security Defaults or Conditional Access policies for a more modern approach (we'll cover this option later).

Step 3: Enable MFA for Users

On the multi-factor authentication page, you'll see a list of all your users.

For each user you want to protect:

  1. Check the box next to their name
  2. Click Enable in the quick steps panel on the right
  3. Confirm the action when prompted

The user's MFA status will change from "Disabled" to "Enabled." The next time they sign in, they'll be prompted to set up their MFA method.

Pro tip: Start with a small group of tech-savvy users first, then roll out to everyone once you've worked out any kinks.

Step 4: Configure MFA Methods

Click on service settings at the top of the MFA page. Here you can choose which verification methods your users can use:

  • Microsoft Authenticator app (recommended—most secure and user-friendly)
  • Phone call (good for users without smartphones)
  • Text message (convenient but less secure)

We recommend enabling the Microsoft Authenticator app as the primary option, with phone call as a backup. Text messages are better than nothing, but they're vulnerable to SIM-swapping attacks.

You can also set the number of days users can remember MFA on trusted devices (we suggest 14-30 days for a good balance of security and convenience).

Step 5: User Setup Experience

When your users sign in after MFA is enabled, they'll see a prompt to set up additional security verification. The process looks like this:

  1. User enters their password as usual
  2. They're redirected to a setup page
  3. They choose their verification method
  4. They verify it works (entering a code or approving a notification)
  5. They're signed in and won't need to set it up again

The entire process takes about 2-3 minutes per user.

Alternative: Using Security Defaults (Easier Option)

If the per-user approach seems too manual, Azure AD offers Security Defaults—a simpler way to enable MFA for everyone at once.

To enable Security Defaults:

  1. In Azure Active Directory, go to Properties
  2. Click Manage Security defaults at the bottom
  3. Set "Enable Security defaults" to Yes
  4. Save your changes

This automatically requires MFA for all users and blocks legacy authentication protocols. It's a great option for small businesses that want maximum protection with minimum configuration.

Note: You can't use Security Defaults if you have any Conditional Access policies enabled—it's one or the other.

Communicating the Change to Your Team

Technology changes can frustrate employees if they're not prepared. Send an email to your team before enabling MFA that:

  • Explains why you're implementing MFA (security, protecting company data)
  • Tells them when it will happen
  • Provides simple instructions or a link to Microsoft's user guide
  • Offers support contact information for questions

Consider holding a brief team meeting or sending a quick video walkthrough. The five minutes you spend on communication will save hours of support requests.

Troubleshooting Common Issues

Users can't receive codes: Make sure their phone number is entered correctly in their profile. Check that they have cell service or WiFi for app-based authentication.

Lost or broken phone: Administrators can temporarily reset a user's MFA settings from the per-user MFA page, allowing them to set up a new device.

App not working: Have users remove and re-add the account in the Microsoft Authenticator app. Make sure they're using the official Microsoft app, not a generic authenticator.

Need Help with Your Security Setup?

Setting up MFA is a critical first step in protecting your business, but it's just one piece of a comprehensive security strategy. If you're looking for guidance on securing your cloud infrastructure or need help implementing these changes, we're here to help.

Get in touch with our team to discuss your security needs. We specialize in making enterprise-level security accessible for small businesses.

Frequently Asked Questions

How much does Azure AD MFA cost for small businesses?

If you have Microsoft 365 Business Basic or higher, MFA is included at no additional cost. You don't need to purchase any add-ons or premium licenses for basic MFA functionality.

What happens if an employee loses their phone?

As an administrator, you can reset their MFA settings from the Azure AD admin center. They'll be prompted to set up MFA again on their next login. This is why it's good to have users register multiple methods (like both an app and a phone number).

Can users bypass MFA on trusted devices?

Yes, you can configure MFA to remember devices for a set number of days (typically 14-90 days). Users will check a "Don't ask again for X days" option during login. This reduces friction while maintaining security.

Related services

Need a hand with this?

O-Cyrus helps small businesses with websites, DNS, custom apps, and the everyday tech that keeps things running.

Talk to us →