Business IT projects · Across Québec Request a quoteFrançais

Multi-factor authentication

Multi-factor authentication (MFA) requires more than a password to sign in: a second factor, such as a security key, a passkey or an authenticator app, confirms the person's identity. An MFA project determines which accounts to protect, with which methods, and how to roll it out without locking out your employees.

Updated on

Not all methods offer the same protection. In its publication Defending against adversary-in-the-middle threats with phishing-resistant multi-factor authentication (ITSM.30.031), the Canadian Centre for Cyber Security explains that phishing-resistant MFA "is the only way to completely stop these campaigns." It gives FIDO2 security keys, passkeys and Windows Hello for Business as examples of phishing-resistant methods.

Short answer

You describe your accounts, your tools and your employees: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The methods and rollout order are chosen with you.

What the quote should cover

  • An inventory of the accounts and services to protect: email, cloud services, remote access, business applications
  • The choice of methods, including which accounts require a phishing-resistant method
  • Access rules, for example based on device or location
  • Emergency access accounts and the procedure when a factor is lost
  • A phased rollout, with a pilot group
  • Communication to employees, training and support during enrolment

Which accounts to protect first

In ITSM.30.031, the Centre recommends deploying phishing-resistant MFA to every user, without exception. In practice, a rollout happens in stages. The publication Steps for effectively deploying multi-factor authentication (ITSAP.00.105) advises starting with high-value accounts, such as administrator accounts and senior management email, then expanding.

The Centre's baseline cyber security controls call for requiring two-factor authentication for important accounts: financial accounts, system administrators, cloud administration, privileged users and senior executives (BC.5.1). Add remote access and any service reachable from the Internet.

Choosing the methods

According to Secure your accounts and devices with multi-factor authentication (ITSAP.30.030), some attacks target MFA itself, such as MFA fatigue from repeated prompts, token theft and machine-in-the-middle interception. The Centre strongly recommends FIDO methods and number matching for push notifications.

The Centre is also clear about text messages: SMS codes should be considered only for low-risk logins, because text messages are not a secure channel and codes are sent unencrypted (ITSAP.00.105). Finally, it notes that most phishing-resistant MFA methods are fee-based: the quote should therefore state which accounts receive them and what that means in licences or hardware.

How a rollout works

  1. Planning: inventory of accounts, services and devices, and consultation with the people involved.
  2. Preparation: configuring methods, access rules and emergency accounts, then testing.
  3. Pilot group: a few users try enrolment and report difficulties.
  4. Rollout waves: high-value accounts first, then the rest of the staff.
  5. Awareness: explaining why, how to enrol and what to do with an unexpected approval request.
  6. Follow-up: handling exceptions, lost devices and employee feedback.

Emergency accounts and lost factors

A lost phone or a forgotten key should neither stop the business nor open a back door. The Centre recommends a clear recovery plan for lost factors (ITSAP.30.030) and, for administrator accounts, removing any backup methods that are not phishing-resistant (ITSM.30.031).

For Microsoft Entra ID, for example, Microsoft recommends creating two or more emergency access accounts, protected by phishing-resistant methods that differ from those of regular administrator accounts. The quote should describe these accounts, how they are monitored and how they are tested.

Questions to ask yourself before requesting a quote

  • Which services do you use: email, cloud tools, remote access, business applications?
  • Which accounts have administrator rights, and who uses them?
  • Do employees use company-issued devices or their personal devices?
  • Do some employees have no cell phone, or work where phones are not allowed?
  • Have you already enabled MFA for some accounts, and with which methods?
  • Who will help an employee who has lost their authentication factor?

Risks and pitfalls to avoid

  • Leaving permanent exceptions for a few accounts, often those of management
  • Keeping text messages as the only method for sensitive accounts
  • Forgetting service accounts, shared mailboxes and legacy protocols that bypass MFA
  • Rolling out to everyone on the same day, with no pilot group or planned support
  • Not telling employees that an unexpected approval request must be denied and reported

What to specify in your request

  • The number of users and administrator accounts
  • The services to protect and your email provider
  • Methods already in place, if any
  • The type of devices used, company-owned or personal
  • Whether you are open to providing security keys to some employees
  • The support you want during and after the rollout
  • Requirements from a client, an insurer or a contract that must be met

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

What is the difference between two-factor and multi-factor authentication?

Two-factor authentication uses exactly two factors; multi-factor authentication uses two or more. The Canadian Centre for Cyber Security also distinguishes two-factor authentication from two-step verification, which may rely twice on the same type of factor (ITSAP.30.030).

What is a phishing-resistant method?

It is a method that a fake site cannot intercept or replay. The Centre gives FIDO2 security keys, passkeys and Windows Hello for Business as examples (ITSM.30.031). A code received by text message or typed in by hand is not one.

Are text message codes enough?

The Centre limits them to low-risk logins, because codes are sent unencrypted and can be hijacked, notably through SIM swapping (ITSAP.00.105). They are better than a password alone, but not enough for sensitive accounts.

What if an employee loses their phone or key?

Plan a recovery procedure before the rollout: verifying the employee's identity, disabling the lost factor and enrolling a new one. The Centre suggests, for example, keeping spare hardware tokens at the help desk (ITSAP.30.030).

Is multi-factor authentication enough to protect our accounts?

No. It is an important control, but it must be combined with updates, limited privileges and training. The Centre recommends, among other things, training employees to recognize phishing. See our Security awareness training page.

Multi-factor authentication

Audits, penetration testing and compliance

Request a quote