Rolling Out MFA to Field Crews Without Revolting the Foremen

A practical plan for introducing multifactor authentication to jobsite staff, with options for people who cannot use a phone app or work in poor coverage.

3 min readBy Ironfield Cyber Team

Ask any security professional for the single most valuable improvement a business can make and multifactor authentication is usually near the top of the list. It blocks a large share of account takeover attempts that begin with a stolen or guessed password. Ask a construction superintendent how they feel about it and you may hear a different opinion: phones get dusty, gloves make typing hard, coverage is poor and nobody wants another thing to do before they can read a drawing.

Both viewpoints are valid. A rollout that respects field realities is the way to reconcile them.

Why field staff matter for MFA

Attackers do not care whether an account belongs to the controller or a foreman. A phished field account can be used to read email, send convincing messages to subcontractors, access project documents and sometimes pivot to other systems. Accounts with weak protection often belong to people who log in rarely and are least prepared to spot a suspicious request.

Know your options

Not all multifactor methods are equal, and the best choice varies by person and site.

  • Authenticator app with push or code. Works well for most people with a smartphone. Number-matching prompts reduce accidental approvals.
  • Hardware security keys. Good for shared trailers, people without smartphones and high-risk roles. They plug in or tap, with no coverage required.
  • Passkeys and device-based sign-in. Using a company laptop or tablet that is itself managed and trusted can reduce prompts.
  • Text message codes. Better than no second factor, but weaker than the options above. Use only where nothing else is feasible.

Plan for the real obstacles

Poor or no signal

Code-generating apps work offline because the code is generated on the phone. Hardware keys also work without coverage. Avoid methods that depend on a text message or a push at remote sites.

No smartphone, or no desire to use a personal phone

Offer a company-issued device or a hardware key. Do not force anyone to install company software on a personal phone without a clear policy.

Shared devices

For shared trailer computers, move to individual sign-in with a security key, and disable shared accounts.

Gloves and rough conditions

Test devices on site. A key on a lanyard may work better than a phone in a pocket.

A rollout sequence that works

  1. Start with the highest risk. Administrators, executives, accounting, and anyone who can approve payments come first.
  2. Move to office staff and project managers.
  3. Pilot with one field team. Choose a respected superintendent who will give honest feedback.
  4. Fix what the pilot reveals. Adjust methods, timing and instructions.
  5. Roll out to all remaining staff in waves, with support available.
  6. Enforce. Set a date after which accounts without MFA cannot sign in.

Make it easy to get help

Hold short in-person sessions at yard meetings or toolbox talks. A ten-minute demonstration, with someone helping each person enroll, beats a long email. Provide a simple one-page guide with screenshots. Offer a phone number staff can call, and make sure the help desk knows how to verify a caller before resetting access.

Anticipate common problems

  • Lost or replaced phones. Have a verified process for re-enrolling, and encourage people to register a backup method.
  • Prompt fatigue. Teach staff to deny any prompt they did not start and to report it.
  • Contractors and subcontractors. Require MFA for outside users of your project platforms as well.
  • Legacy applications. Some older tools cannot use modern authentication. Identify them and plan for replacement or additional protections.

Communicate the why

People accept inconvenience more readily when they understand the purpose. Share an example, clearly marked as hypothetical, of how a stolen password could allow a fraudulent payment request to a subcontractor. Emphasize that the goal is protecting the company and the jobs it supports.

Track results

Measure the percentage of accounts with MFA enabled, the number of support requests and the number of blocked sign-in attempts. Report progress to leadership monthly during the rollout.

How Ironfield Cyber helps

Ironfield Cyber plans and supports MFA rollouts for contractors and energy companies, including hardware key options and training sessions for field crews. If you are trying to get MFA turned on across a mixed office and jobsite workforce, we can help you design a plan that people will follow.