Multi-Factor Authentication (MFA)
Protect your business accounts with an essential second layer of security.
Weak or stolen passwords are the number one cause of business account compromise. ROI Technologies implements and manages Multi-Factor Authentication (MFA) across your Microsoft 365, VPN, applications and devices — stopping attackers even when passwords are stolen.
Sound Familiar?
MFA is one of those controls almost everyone has partially deployed. Partially is where the risk lives:
- MFA is on for some people and not others, and nobody can say exactly who's covered.
- Your cyber insurer has asked whether MFA is enforced on all users and you can't evidence it.
- Staff find the prompts irritating and some have quietly found ways around them.
- It's enforced on email but not on VPN, or the other way round.
- The administrator accounts — the ones that matter most — were the ones granted an exemption.
- You're worried about being locked out of your own tenant if something goes wrong.
What's included in our MFA service
Everything you need from a modern mfa partner — delivered by our engineering team.
- Microsoft 365 MFA — Authenticator App and SSPR
- Conditional Access policies (Entra ID / Azure AD)
- VPN and remote access MFA
- Application-level MFA for line-of-business apps
- Phishing-resistant FIDO2 / hardware key support
- MFA rollout planning and staff communication
- Break-glass emergency access accounts
- MFA compliance reporting
- MFA deployment that supports POPIA and cyber insurance requirements
How we deploy MFA
Multi-factor authentication across all users is our standard on every environment we manage. It is also the control most frequently found missing, or half-finished, when we assess a new one.
All users — especially the awkward ones
The accounts that get exempted during a rollout are almost always the senior and administrative ones, which is precisely backwards. Those are the accounts worth compromising, and an exemption list is the first thing an attacker hopes to find.
Applied intelligently, not constantly
Where your licensing supports Conditional Access, we use signals like device health and location so people aren't approving prompts all day. MFA that irritates users gets circumvented, and a control people work around protects nobody.
Break-glass access planned in advance
Emergency access accounts are configured, documented and protected before they're needed, so a misconfiguration or a lost device doesn't lock you out of your own tenant.
Evidence you can hand over
Coverage reporting you can put in front of an insurer or a customer's security review, rather than an assurance that it's mostly enabled.
Frequently asked questions
Won't this irritate everyone?
It does if it's deployed badly. Prompting people repeatedly through the day is the fastest way to have MFA quietly circumvented. Where licensing allows Conditional Access, prompts can be reserved for genuinely riskier sign-ins — a new device, an unusual location — so most people encounter it rarely. How you communicate the rollout matters as much as how you configure it.
Our insurer asks whether MFA is enforced. What do they actually want?
Usually evidence rather than a yes: that it applies to all users including administrators, that it covers remote access and email, and that exceptions are documented and justified. "It's turned on" is rarely enough at renewal, and a coverage report is what closes the question.
What is Conditional Access?
A way of deciding when to challenge a sign-in based on context — who is signing in, from what device, from where, to reach what. It lets you apply strong requirements where risk is higher without applying friction everywhere. It needs the right licensing, which is one of the reasons Business Premium comes up in these conversations.
What if we get locked out?
That is what break-glass accounts are for, and configuring them is part of the deployment rather than an afterthought. They are set up before enforcement is switched on, documented, and protected appropriately, so there is always a controlled route back in.
Is SMS good enough?
It's better than nothing and weaker than the alternatives. SMS codes can be intercepted and are vulnerable to SIM-swap attacks, which is a well-documented problem in South Africa. Authenticator apps are stronger, and hardware keys stronger still. For most businesses the sensible position is app-based by default, with hardware keys for administrators.
Does it cover VPN and our other applications?
It should. MFA on email while remote access stays single-factor is a common and dangerous gap. We look at remote access, line-of-business applications and administrative interfaces as part of the rollout, not just the Microsoft 365 sign-in.
Other IT services
Managed IT Services
Fully managed IT support, proactive monitoring, helpdesk and device management for South African businesses that are serious about IT.
Learn moreCybersecurity Services
ROI Technologies delivers end-to-end cybersecurity services including EDR/XDR endpoint protection, vulnerability scanning, network security and compliance. We support SentinelOne and Sophos Intercept X for endpoint protection.
Learn moreCompliance & Governance
CIS Controls implementation, IT governance, risk assessments and POPIA compliance readiness.
Learn moreNeed MFA?
Get a free assessment today and see how ROI Technologies can streamline your IT.
Book a Free Assessment