Multi-Factor Authentication Configuration -- Perth IT Care
Last month, a Subiaco accounting firm discovered their "bulletproof" MFA setup was about as secure as a screen door. They'd enabled multi-factor authentication on Microsoft 365, patted themselves on the back, and moved on. Until hackers waltzed past their SMS codes and spent three days downloading client tax files through an old app they'd forgotten existed.
The firm thought they were protected. Their cyber insurance provider thought they were protected. The ACSC's Essential Eight checklist had a nice tick in the MFA box. But proper MFA configuration isn't about ticking boxes — it's about closing every door hackers use to get in.
Why Your Current MFA Setup Probably Has Holes
Most Perth businesses enable MFA the same way they approach fire extinguishers: buy one, mount it on the wall, never think about it again. But MFA isn't a set-and-forget solution. It's a security layer that needs proper configuration, or it becomes security theatre.
The biggest mistake? Trusting SMS and phone call authentication. These methods feel secure because you're getting a code on your phone, but they're trivially easy for attackers to bypass. SIM swapping attacks let hackers port your number to their device in minutes. SMS interception tools grab codes in transit. Phone call forwarding redirects authentication calls straight to the attacker.
We've seen Perth businesses lose everything because they relied on SMS codes. One Northbridge law firm had their entire client database stolen after attackers bypassed SMS MFA using a $50 SIM swapping service.
Microsoft Authenticator App: Your Minimum Standard
If you're still using SMS for MFA, you're using 2010 technology to fight 2024 threats. Microsoft Authenticator app should be your baseline, not your upgrade.
The app generates time-based codes that change every 30 seconds and don't rely on your phone network. Attackers can't intercept them, port them, or redirect them. The codes are mathematically tied to your specific device and account combination.
Setting it up properly means configuring it for number matching and location verification. When someone tries to sign in to your account, you'll get a notification showing the exact location and a number you need to enter. If the sign-in attempt is from Romania and you're sitting in your Fremantle office, you'll know something's wrong.
But even Microsoft Authenticator isn't bulletproof if you don't configure the surrounding policies correctly.
Conditional Access: Closing the Loopholes
Here's where most Perth businesses trip up: they enable MFA but leave gaping holes through Conditional Access policies. These policies control when, where, and how MFA gets enforced. Get them wrong, and you've got expensive security gaps.
The most critical policy? Blocking legacy authentication protocols. Old email clients, outdated mobile apps, and ancient software often can't handle modern MFA. Instead of upgrading, many businesses create "legacy app exemptions" that bypass MFA entirely.
That Subiaco accounting firm? Their breach happened through a legacy Exchange Web Services connection that bypassed all their shiny new MFA policies. The hackers found it in minutes using automated scanning tools.
Essential Conditional Access Configurations
Your Conditional Access policies need to cover these scenarios:
Location-based restrictions: Block sign-ins from countries where your business doesn't operate. If your Perth accounting firm suddenly has sign-ins from Belarus, that's not your team working late.
Device compliance requirements: Only allow access from managed devices that meet your security standards. Personal phones and unpatched laptops shouldn't get the same access as your properly managed business devices.
Application-specific policies: Different apps need different security levels. Your CRM might need stricter controls than your company blog. Configure MFA requirements per application, not as a blanket policy.
Risk-based authentication: Microsoft's identity protection can spot suspicious behaviour patterns and require additional verification when something looks wrong.
The Legacy App Problem That's Killing Perth Businesses
Legacy applications are the hidden weak point in most MFA deployments. These are older programs that connect to your Microsoft 365 environment using outdated authentication methods. They can't handle modern MFA prompts, so businesses either leave them unprotected or create broad exemptions.
Common legacy apps that cause problems:
- Older versions of Outlook (before 2016)
- Scanner-to-email functions on multifunction printers
- Line-of-business applications with hardcoded credentials
- Mobile apps that haven't been updated in years
The solution isn't to exempt these applications — it's to replace or upgrade them. Every legacy app exemption is a door you're leaving unlocked for attackers.
If you can't immediately replace legacy apps, create highly specific exemptions. Don't exempt "all legacy protocols" — exempt the specific application, from specific IP addresses, for specific users. Make the exemption as narrow as possible while you plan the replacement.
Per-Application MFA Settings That Matter
Microsoft 365 doesn't just offer blanket MFA settings. You can configure different requirements for different applications based on their risk level. Most Perth businesses miss this entirely and apply the same weak settings everywhere.
Critical applications like your financial software or client management systems should require MFA every time, from every device. Less critical applications might allow trusted devices to skip MFA for a limited time.
The key is understanding which applications store your most sensitive data and configuring protection accordingly. Your company SharePoint with client contracts needs stricter controls than your staff newsletter system.
Testing Your Setup Before Hackers Do
The only way to know if your MFA is working is to test it regularly. Create test scenarios that replicate real-world attack patterns. Try signing in from unusual locations, different devices, and legacy applications.
Most importantly, document what you find. Every security gap you discover during testing is one less door for attackers to exploit. Regular testing turns security from a checkbox exercise into a living, breathing protection system.
Your business data is too valuable to protect with wishful thinking. Get your MFA configuration right the first time, or watch hackers prove you wrong the expensive way.

