Tech Tip Video #140

An employee receives a convincing email that looks like a routine sign-in request. They enter their password, and someone else now has the same access to company email, shared files, and customer messages.

A password alone creates a single checkpoint. Multi-factor authentication, or MFA, adds another proof of identity, such as a prompt on a trusted device or a security key. That extra step helps keep an account protected even when a password is exposed or reused.

First, turn on MFA for the accounts that matter most. Start with business email, then protect payroll, banking, file storage, and administrator accounts. Use the security settings provided by each service.

Second, choose the strongest method available. A security key or authenticator app is generally preferable to a code sent by text message. Follow your company’s approved setup and keep any recovery codes in a secure location, not in your inbox or on your desk.

Third, treat every unexpected approval prompt as a sign to pause. Deny requests you did not start. Then check the account’s recent activity and report the prompt to your IT contact or service provider.

Protect key accounts, use a strong verification method, and reject unrequested prompts to make stolen passwords less useful.

Enable multi-factor authentication on your primary business email account before the end of today.