Turning on multi-factor authentication, or MFA, is one of the best things a contractor can do. It stops most attacks that rely on stolen passwords. But "MFA" covers several methods that differ in strength, convenience and cost, and attackers have adapted to the weaker ones.
Choosing the right method for each group of users, such as office staff, executives, administrators and field crews, balances security against usability.
The Main Methods
Text message codes
A code is sent by SMS. It is easy, requires no app and works on any phone. It is also the weakest common method. Attackers can trick carriers into moving a number to a different device, and codes can be intercepted or tricked out of users. Still, SMS is far better than a password alone, and it may be the practical starting point for people with limited access to smartphones.
Authenticator app codes
A smartphone app generates a six-digit code that changes every thirty seconds. It does not depend on the phone network and is harder to intercept than SMS. The weakness is that users can be tricked into typing the code into a fake website, where the attacker uses it immediately.
Push notifications with number matching
The app sends a prompt, and the user must enter a number displayed on the sign-in screen. This blocks the "prompt bombing" tactic, in which attackers send repeated approvals hoping the user taps yes just to make it stop. Microsoft Authenticator and similar apps support number matching, and it should be turned on.
Hardware security keys
A small physical device, often USB or NFC, that the user taps to sign in. Keys based on the FIDO2 standard are resistant to phishing, because they verify the website's identity as part of the process. They are the strongest option generally available and well suited to administrators, executives and finance staff.
Passkeys
Passkeys use the same cryptographic approach as security keys but can be stored on a phone or computer and unlocked with a fingerprint, face or device PIN. They are increasingly supported and combine strength with convenience.
Matching Methods to Roles
- Administrators and IT staff: hardware keys or passkeys. These accounts can do the most damage if compromised.
- Finance and accounting: phishing-resistant methods where possible, since these accounts are prime targets for payment fraud.
- Executives and project managers: authenticator app with number matching at minimum, with keys or passkeys for those with access to sensitive data.
- Field crews: authenticator app on a company or personal phone, or a method that works with shared devices, depending on your setup.
- Contractors and vendors: require MFA for any access to your systems, using the strongest practical method.
Field Realities
Crews present special problems.
- Poor connectivity. Authenticator app codes work without a signal; push prompts need data.
- Shared devices. Several people using one tablet makes personal authentication harder. Consider individual sign-ins with quick, secure methods rather than shared accounts.
- Gloves and dirt. Fingerprint readers may not work. Consider PIN or key options.
- No smartphone. Provide a hardware key or token for those without one.
- Phone replacement. Plan for recovery when someone loses or upgrades a phone.
Avoiding Common Pitfalls
- Exceptions that never end. A temporary exemption for the owner often becomes permanent. Require MFA for everyone, owners included.
- Weak recovery paths. If an attacker can reset your MFA by calling the help desk, the control is hollow. Verify identity carefully before resetting.
- Legacy protocols. Older email connection methods may bypass MFA. Disable them in Microsoft 365 and similar systems.
- Only protecting email. Cover remote access, cloud storage, accounting software, construction platforms and password managers.
- Not using conditional access. Where available, require stronger checks for unusual locations, new devices or risky sign-ins.
Rolling It Out
- Start with administrators and finance, then expand to everyone.
- Communicate why, and when, in plain language.
- Provide help sessions and a simple one-page guide.
- Configure recovery methods before enforcing.
- Monitor for failures and help-desk volume, and adjust.
- Review the setup annually as better options become available.
Choosing Your Mix
Most contractors end up with a tiered approach: strong methods for high-risk roles and a good-enough method for broad adoption. The worst choice is delaying because the perfect option is unclear. Ironfield Cyber can assess your current MFA coverage, recommend methods for each group and handle rollout, including the field-specific challenges that generic guides miss.