Cybersecurity

Multi-Factor Authentication: Why Every Business Needs IT

A practical COMNEXIA guide to Multi-Factor Authentication: Why Every Business Needs IT: what it means for your business, how it works, and the steps to get it right.

By COMNEXIA
#Cybersecurity

Passwords alone stopped being enough years ago. If a credential leaks in a breach (and breaches happen constantly), an attacker with your username and password can walk straight into your email, your bank portal, or your dealership’s DMS with zero friction.

What Is Multi-Factor Authentication (MFA)?

Multi-factor authentication, often abbreviated as MFA or called two-factor authentication (2FA), requires a user to prove their identity using two or more independent factors before gaining access to a system. Those factors fall into three categories:

  • Something you know: a password or PIN
  • Something you have: a one-time code sent to your phone, a hardware token like a YubiKey, or an authenticator app such as Microsoft Authenticator or Google Authenticator
  • Something you are: a fingerprint, face scan, or other biometric

A login protected by MFA means a stolen password by itself is worthless to an attacker. They also need that second factor, which is almost always in the legitimate user’s physical possession.

How MFA Works in Practice

When you log into a Microsoft 365 account secured with MFA, the sequence looks like this:

  1. Enter your username and password on the sign-in page.
  2. Microsoft prompts for a second factor. Depending on your configuration, that may be a push notification to the Authenticator app, a six-digit TOTP (time-based one-time password) from an authenticator app, an SMS code, or a hardware key.
  3. You approve or enter the code. Only then does the session open.

The entire second step takes roughly five seconds. The protection it adds is substantial because that one-time code expires in 30 to 60 seconds and cannot be reused.

Where MFA is commonly required or strongly recommended:

  • Microsoft 365, Google Workspace, and any cloud email platform
  • Remote Desktop (RDP) and VPN gateways
  • Dealership management systems (CDK, Reynolds and Reynolds, DealerSocket)
  • Banking and payroll portals
  • Administrative accounts in Azure AD or Active Directory

What Is MFA Fatigue?

MFA fatigue (also called push bombing) is an attack technique where a threat actor who already has your stolen credentials repeatedly sends MFA push approval requests to your phone, hoping you will tap “Approve” out of frustration, confusion, or just to stop the notifications. The 2022 Uber breach succeeded largely because an attacker kept sending push requests until the employee eventually approved one.

Signs you or an employee may be experiencing an MFA fatigue attack:

  • You receive MFA push requests you did not initiate, especially late at night or in rapid succession
  • The requests come from an unfamiliar location or device shown in the notification detail
  • Someone contacts you claiming to be IT support and asking you to approve the request

How to stop MFA fatigue attacks:

  • Switch from simple push approvals to number-matching, where the app requires you to type a number displayed on the login screen before approving. Microsoft Authenticator supports this and Microsoft has enabled it by default in Entra ID.
  • Enable context-aware Conditional Access policies in Azure AD or Entra ID that block logins from unusual geographies or unmanaged devices.
  • Train employees never to approve an MFA request they did not personally initiate, and to call IT immediately if they receive unsolicited requests.

MFA on Consumer Platforms: Discord and Fortnite

Two platforms employees and younger family members ask about most often are Discord and Fortnite. Both support MFA and the setup process is nearly identical.

Discord: Go to User Settings, then the My Account tab. Under “Two-Factor Authentication,” click “Enable Two-Factor Auth” and scan the QR code with an authenticator app. Discord also provides backup codes, which you should save offline in case you lose your phone. Without MFA on a Discord account, a credential-stuffed password gives an attacker full access to every server and direct message in that account.

Fortnite (Epic Games): Log into your account at epicgames.com, navigate to Password and Security, scroll to Two-Factor Authentication, and enable either an authenticator app, SMS, or email verification. Epic actually rewards players with a free emote for enabling MFA, and accounts with MFA enabled can send gifts to other players.

The mechanism on both platforms is the same TOTP standard used in corporate environments. Practicing MFA on a gaming or chat account builds the habit before it matters at work.

Why MFA Matters for Your Business, Especially in Auto Dealerships

Dealerships are high-value targets. A finance manager’s email account contains wire instructions, deal jackets with Social Security numbers, and lender credentials. A single compromised account can enable business email compromise (BEC) fraud worth tens of thousands of dollars.

COMNEXIA works with dealerships across the metro Atlanta area and has seen firsthand how much damage a single unprotected account can cause. Enforcing MFA across Microsoft 365, VPN, and the DMS, combined with Conditional Access policies and employee training, closes the most exploited entry point in the dealership threat model.

MFA is also increasingly a compliance and insurance requirement. Cyber liability carriers routinely ask whether MFA is enforced on email and remote access, and some will deny claims or cancel policies if it was not.

Get Help from COMNEXIA

COMNEXIA has delivered security-first managed IT for 35 years from our Roswell, GA headquarters. If you need MFA deployed and enforced across your organization, or want a broader assessment of your security posture, call us at (877) 600-6550 or contact us.

Learn more about our managed IT services and cybersecurity programs built for businesses that cannot afford to get this wrong.

Need Expert Technology Guidance?

Don't navigate complex technology decisions alone. Our consulting team provides the strategic guidance you need to make informed technology investments.