Guide · Scams & security
How to set up two-factor authentication across your business accounts
A step-by-step guide to turning on two-factor authentication in Microsoft 365, Google Workspace, Xero, MYOB and Meta, and what to do when a phone is lost.

Two-factor authentication (also called 2-Step Verification, 2FA or multi-factor authentication, MFA) asks for a second proof, usually from your phone, after the password. It means a stolen or guessed password isn’t enough on its own to get into the account. Microsoft says that “more than 99.9% of those common identity-related attacks are stopped by using multifactor authentication and blocking legacy authentication”. Google says 2-Step Verification “can cut account takeover by as much as 50%”. Both figures are the vendors’ own.
This guide works through the accounts most small businesses depend on, in the order we would do them. Menu names change often, so if a path below doesn’t match your screen, search the vendor’s help centre for the heading given.
Which method to choose
Most services offer several second steps. The vendors rank them roughly the same way:
- Text message or phone call codes. Better than nothing, but Google says they “can be vulnerable to phone number-based hacks”, and Microsoft “recommends users move away from using text messages or voice calls”. Keep SMS as a backup, not the main method.
- An authenticator app or app prompt (Microsoft Authenticator, Google Authenticator, Google prompts, Xero Verify). Google calls Google prompt or Google Authenticator “good alternatives” to security keys, and says prompts help protect against SIM swap. Authenticator codes work without an internet connection.
- Passkeys and security keys. Google says security keys are “the most secure form of 2SV and protect against phishing threats”, and that passkeys give the same level of phishing protection. Microsoft recommends “phishing-resistant authentication methods such as Windows Hello for Business, passkeys (FIDO2) and FIDO2 security keys, or certificate-based authentication”.
For a small team, on our reading, an authenticator app on each person’s own phone is the practical baseline, with passkeys or security keys for the owner and anyone who administers email or banking.
1. Email first: Microsoft 365
Email comes first because it can reset the password on almost everything else.
Microsoft says Microsoft 365 organisations created after October 2019 have security defaults turned on by default, although its Entra documentation says only that they “might be enabled” for newer tenants, so check. Security defaults require every user to register for MFA, require admins to use MFA each time they sign in, and block older sign-in methods (legacy authentication) that can’t do MFA. Users register with the Microsoft Authenticator app using notifications. Since 29 July 2024 there is no 14-day grace period for users to register.
To check or turn it on, sign in to the Microsoft Entra admin center as an administrator and go to Overview > Properties > Manage security defaults, set it to Enabled and save. Microsoft’s two help pages give slightly different menu names for this screen and different minimum admin roles, so on our reading a Global Administrator account is the simplest way in. Microsoft otherwise advises using the role with the fewest permissions for everyday admin work. Microsoft says not to turn security defaults off unless you’re replacing them with Conditional Access policies, which need Microsoft Entra ID P1 or P2 licences (included in Microsoft 365 Business Premium, for example).
Each user adds or changes their methods at myprofile.microsoft.com under Security info.
2. Email first: Google Workspace
In Google Workspace, a super administrator turns on 2-Step Verification (2SV) in the Admin console under Security > Authentication > 2-step verification. Google’s own rollout has two stages:
- Allow it. Tick Allow users to turn on 2-Step Verification, leave enforcement off and save. Staff can then enrol.
- Enforce it. Once people have enrolled (check Reporting > User Reports > Security), set Enforcement to On or pick a start date. Google says enforcement starts within 24 to 48 hours of the chosen date. You can give new staff a new user enrollment period of 1 day to 6 months, during which they can sign in with just a password.
Under Methods you can allow any method, block text and phone codes, or allow only security keys and passkeys. Google warns that blocking text and phone codes locks out users who rely on them, so move those people to an app first. Google is also enforcing 2SV on administrator accounts itself.
Using a personal Gmail account for the business? Turn on 2-Step Verification at your Google Account under Security & sign-in. On our reading, turn it on for any Google Account that manages your Google Business Profile too.
3. Accounting: Xero and MYOB
Xero says MFA became mandatory in Australia in 2018 under the ATO’s Operational Framework, so every Xero user should already have it. Xero supports its Xero Verify app for push notifications, or Google Authenticator or FreeOTP for codes. To set it up, click your initials or image, then Account, then Set up under Multi-factor authentication. Xero says anyone you invite into Xero or a client file needs their own login and MFA.
MYOB recommends an authenticator app, with SMS as a backup method. It says email codes are its “least secure option” and that it will phase them out in 2027, and it recommends passkeys for the strongest security. Add or change methods at myaccount.myob.com under Account security. MYOB says you can only reset a 2FA method if you have more than one set up, so add a second.
4. Facebook and Instagram
Meta lets whoever has full control of a business portfolio require two-factor authentication for Admins only or Everyone with access. In Meta Business Suite, go to Settings > Business portfolio info > Business options and use the drop-down next to Two-factor authentication. Meta says the requirement takes effect immediately, and that it already requires it for some portfolios more than 90 days old.
Each person turns it on in their own Facebook account under Accounts Center > Password and security > Two-factor authentication.
5. When someone loses their phone
Set up recovery before you need it:
- Backup codes. Google lets each user print or download a set of 10 single-use backup codes, and creating a new set cancels the old one. Facebook offers 10 recovery codes. MYOB provides a recovery code when you set up SMS 2FA.
- A second method. An authenticator app plus a backup phone number or security key means one lost phone isn’t a lockout.
- A second administrator. In Google Workspace, an admin can issue backup codes to a locked-out user from Directory > Users > the user > Security > 2-step verification > Get Backup Verification Codes, and Google says only super administrators can do this for another admin. In Microsoft 365, an admin can open the user in the Entra admin center under Authentication methods and choose Require re-register MFA, which removes their phone and app methods so they set up new ones at next sign-in. Microsoft also recommends two emergency access admin accounts.
If an account has already been taken over, follow our first-hour guide for a hacked business email account.
Checklist
- List the accounts that matter. Email, accounting software, Google Business Profile, Facebook and Instagram, with who holds admin access to each.
- Check Microsoft 365 security defaults. In the Entra admin center under Properties, confirm security defaults are enabled, or that Conditional Access policies replace them.
- Turn on 2-Step Verification in Google Workspace. Allow it, let staff enrol, then set enforcement to On with a new user enrollment period.
- Move staff off text-message codes. Have each person install an authenticator app and make it their main method, keeping SMS only as a backup.
- Require 2FA in your Meta business portfolio. Whoever has full control goes to Meta Business Suite > Settings > Business portfolio info > Business options and sets Two-factor authentication to Everyone.
- Give every Xero user their own login. Xero says each person you invite needs their own login and MFA, so stop sharing one login.
- Add a second method for each person. A backup phone number, security key or second device, so one lost phone doesn’t lock them out.
- Print backup codes for the owner’s Google and Facebook accounts. Keep them somewhere safe, and make a new set if they run out or may have been seen by someone else.
- Make sure there are two admins. Two people who can reset a locked-out user in Microsoft 365 or Google Workspace.
Tick items as you go. Your ticks stay in this browser.
Sources 16 sources
- Protect your business with 2-Step Verification (Google Workspace Admin Help)
- Deploy 2-Step Verification (Google Workspace Admin Help)
- Recover an account protected by 2-Step Verification (Google Workspace Admin Help)
- Turn on 2-Step Verification (Google Account Help)
- Sign in with backup codes (Google Account Help)
- Security defaults in Microsoft Entra ID (Microsoft Learn)
- Set up multifactor authentication for Microsoft 365 (Microsoft Learn)
- Authentication methods overview (Microsoft Learn)
- Phone authentication options (Microsoft Learn)
- Manage user authentication methods (Microsoft Learn)
- Multi-factor authentication (Xero)
- Multi-factor authentication FAQ (Xero)
- Two-factor authentication (MYOB support)
- Setting up additional two-factor authentication methods (MYOB support)
- How to require two-factor authentication for people in your Meta business portfolio (Meta Business Help Centre)
- Two-factor authentication on Facebook (Facebook Help Centre)

