How to Enable MFA for Microsoft 365 in Your Philippine Business (2026 Guide)

Multi-factor authentication is the single most effective security control a Philippine business can implement today. Microsoft estimates that MFA blocks over 99.9% of account compromise attacks. Yet in 2026, a significant portion of Philippine SMEs are still running Microsoft 365 without it — often because no one has sat down to turn it on.
This guide walks through every method available, from the simplest one-click option to the full Conditional Access configuration used by regulated enterprises — so you can choose what fits your organisation and get it done.
Why MFA Is Urgent for Philippine Businesses
Two regulatory drivers are pushing Philippine organisations toward stronger authentication right now.
NPC Circular 2023-04 on data breach notification requires organisations to report breaches within 72 hours and demonstrate that reasonable security measures were in place. A compromised M365 account that had no MFA is difficult to defend in a post-incident investigation.
BSP Circular 1213 phases out SMS-based OTP for financial transactions — a signal that SMS authentication is no longer considered sufficiently secure. While the circular directly targets BSP-supervised entities (banks, EMIs, quasi-banks), its risk logic applies to any organisation protecting sensitive data: SMS OTP is interceptable through SIM swap attacks and SS7 exploits. The Authenticator app is the right replacement.
Three Ways to Enable MFA in Microsoft 365
Option 1: Security Defaults (Fastest — All Plans)
Security Defaults is Microsoft's pre-configured baseline security policy, available on every Microsoft 365 plan including Business Basic. It requires MFA for all users and blocks legacy authentication protocols.
To enable:
- Sign in to the Microsoft Entra admin centre as a Global Administrator
- Navigate to Identity → Overview → Properties
- Select Manage Security Defaults
- Toggle Enable Security Defaults to Yes
- Save
All users will be prompted to register an MFA method at their next sign-in. The supported methods are Microsoft Authenticator app, TOTP authenticator apps, and phone call.
Best for: SMBs on Business Basic or Business Standard without Entra ID P1 licensing. Simple, effective, zero configuration.
Limitation: Security Defaults is all-or-nothing. You cannot exclude users, set grace periods, or apply different policies to different groups. If you need granular control, use Conditional Access instead.
Option 2: Per-User MFA (Legacy — Avoid for New Deployments)
Per-user MFA in the Microsoft 365 admin centre is the older mechanism. It works, but Microsoft has deprioritised it in favour of Conditional Access. If you are starting fresh, skip this option.
If you have existing per-user MFA configurations, they continue to function — but disable Security Defaults first if you plan to use them alongside Conditional Access, as they conflict.
Option 3: Conditional Access Policies (Full Control — Requires Entra ID P1)
Conditional Access is the enterprise-grade approach. It lets you require MFA based on conditions: user group, location, device compliance, application being accessed, sign-in risk level. It requires Microsoft 365 Business Premium, Entra ID P1, or any plan that includes Entra ID P1.
Creating a baseline MFA policy:
- Go to Entra admin centre → Protection → Conditional Access → Policies
- Select New policy
- Name it (e.g., "Require MFA – All Users")
- Under Users, select All users (exclude your break-glass emergency access account)
- Under Target resources, select All cloud apps
- Under Access controls → Grant, select Grant access → tick Require multifactor authentication
- Set Enable policy to Report-only first to see who would be affected
- After reviewing the sign-in logs for a week, switch to On
Recommended additional policies:
- Block legacy authentication — legacy protocols (IMAP, POP3, SMTP AUTH) bypass MFA entirely. Create a policy that blocks all legacy auth clients across all apps.
- Require compliant device for admins — Global Admins should require both MFA and Intune device compliance. Pair with Microsoft Intune endpoint management.
- Sign-in risk policy — if you have Entra ID P2, enable identity protection to automatically require step-up MFA when a risky sign-in is detected.
Setting Up Microsoft Authenticator for Your Users
The Authenticator app is the recommended MFA method for Philippine businesses replacing SMS OTP. It works offline, generates time-based one-time codes, and supports number matching (prevents push notification fatigue attacks).
User registration steps:
- Download Microsoft Authenticator from the App Store or Google Play
- On the next M365 sign-in, the user is prompted for "More information required"
- Select Next → Choose Microsoft Authenticator
- Scan the QR code displayed on screen
- Approve the test notification to complete setup
Admin tip: For bulk onboarding, use the Authentication methods blade in Entra to set Microsoft Authenticator as the default method tenant-wide. Disable SMS as a registration option if you want to enforce app-based authentication.
Combined MFA Registration Campaigns
If you are enabling MFA across a 50+ person organisation and cannot absorb the disruption of everyone hitting the registration prompt at once, use a Registration campaign:
- In Entra → Protection → Authentication Methods → Registration Campaign
- Set a Snooze duration (e.g., 3 days) to give users a short grace period
- Target specific groups to phase the rollout department by department
This approach reduces helpdesk load and gives your team time to communicate the change before it takes effect.
What to Tell Your Users
A two-sentence explanation works: "We are adding a second step when you sign in to Microsoft 365. Download the Microsoft Authenticator app and approve a notification from your phone — it takes 30 seconds once set up."
Expect 5–15% of users to need helpdesk assistance on their first login. Pre-staging accounts with admin-initiated MFA nudges via Entra reduces this significantly.
Licensing Reference
| Feature | Minimum License |
|---|---|
| Security Defaults (basic MFA) | All M365 plans (including Basic) |
| Conditional Access policies | Business Premium / Entra ID P1 |
| Sign-in risk-based MFA | Entra ID P2 |
| FIDO2 hardware key support | All plans |
| Number matching in Authenticator | All plans (recommended) |
Technica Can Configure This for You
Technica Solutions Inc. is a Microsoft 365 partner in the Philippines. We handle MFA enablement, Conditional Access policy design, user registration campaigns, and Authenticator app rollouts for Philippine businesses — including regulated organisations that need documentation for BSP or NPC compliance reviews.
Related reading
- Microsoft 365 Licence Optimisation for Philippine Businesses
- Microsoft Intune: Endpoint Management for Philippine Enterprises
- Zero Trust Security: A Practical Guide for Philippine Enterprises
- BSP Circular 1213 and the SMS OTP Phase-Out


