Setting Up Multi-Factor Authentication Across Your Entire Company: A Practical Guide

Company-wide multi-factor authentication is the single highest-return security control an SMB can deploy: Microsoft reports that more than 99.9% of common identity attacks are stopped by MFA combined with blocking legacy sign-in protocols. The rollout itself is a sequencing exercise:

Verified against Google Workspace, Microsoft Entra ID, and Okta on 2026-09-02.

Prerequisites

Step 1: Choose the Factors You Will Support

  1. Set app-based and phishing-resistant methods as the standard: passkeys (FIDO2 WebAuthn), Okta Verify or Okta FastPass, Google prompt or Google Authenticator, and Microsoft Authenticator.
  2. Keep SMS codes as a fallback for the few people who need one, not as the default. Text messages are the weakest common factor.
  3. Decide where backup codes are stored. The company password manager is the answer that survives a lost phone.

Step 2: Open Enrollment Before You Enforce Anything

  1. Google Workspace: in the Admin console, go to Menu → Security → Authentication → 2-step verification and confirm users are allowed to turn on 2-Step Verification. You must be signed in as a super administrator.
  2. Microsoft Entra ID: in the Entra admin center, go to Entra ID → Overview → Properties, select Manage security defaults, set Security defaults to Enabled, and select Save. Tenants on Entra ID P1 or P2 should use Conditional Access policies instead.
  3. Okta: in the Admin Console, go to Security → Authenticators, add the authenticators you chose in Step 1, and attach them to an enrollment policy.

Enrollment-first matters because people register calmly when their login still works, and the enforcement date becomes a formality instead of an event.

Step 3: Announce the Rollout With a Date

  1. Send one announcement naming the enforcement date, the supported factors, and a two-minute enrollment walkthrough. Microsoft publishes ready-made communication templates, and Entra users can enroll directly at myprofile.microsoft.com under Security Info.
  2. Have leadership and admins enroll first. Exceptions at the top become everyone's argument for an exception.
  3. Answer the prompt-fatigue objection up front: trusted-device settings mean a second factor is requested rarely on a laptop someone uses every day, not at every login.

Step 4: Track Enrollment and Close Out the Stragglers

  1. Google Workspace: go to Menu → Reporting and review 2-Step Verification enrollment status per user.
  2. Okta and Entra: pull the equivalent authenticator-registration report from the admin console.
  3. Chase the remaining names individually. A personal message with the enrollment link resolves most of them the same day.

Step 5: Enforce

  1. Google Workspace: on the same 2-step verification page, set enforcement to On or On from date. The On from date option takes effect within 24 to 48 hours of the chosen date, so use On when you need a precise cutover.
  2. Set the New user enrollment period (from 1 day to 6 months) so new hires can sign in during their first days while onboarding, and check Allow user to trust the device under Frequency to keep daily prompts rare.
  3. Microsoft Entra ID: with security defaults enabled, registration is required at sign-in. Revoking active sessions forces the registration prompt for anyone coasting on an old token.
  4. Okta: set the enrollment policy for your chosen authenticators to required.

Step 6: Time-Box Every Exception

  1. Move shared logins into the password manager with MFA enforced on the vault itself, and retire the exception.
  2. Give any remaining exception an expiry date and an owner. An exception with no end date is a policy change nobody approved.
  3. Review the exception list on your quarterly security pass so it shrinks instead of accumulating.

Verify

Troubleshooting

Would you like MFA rolled out company-wide, with the reports, the exceptions, and the stragglers handled for you? We can help. Book a free call and we will run it as part of your managed IT.

Verified against Google Workspace, Microsoft Entra ID, and Okta on 2026-09-02. Vendor docs: https://support.google.com/a/answer/9176657, https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults, https://help.okta.com/en-us/content/topics/identity-engine/authenticators/about-authenticators.htm.