Multi-Factor Authentication Best Practices for Arizona Organizations

MFA is mandatory across all three of your compliance frameworks

Multi-factor authentication isn’t optional anymore. The FTC Safeguards Rule mandates it for CPA firms. The proposed HIPAA Security Rule update makes it mandatory for healthcare. CMMC and NIST 800-171 require it for all CUI systems. If your Arizona business touches any regulated data, MFA is a baseline requirement.

Yet many Arizona SMBs still rely on SMS-based MFA, which is vulnerable to SIM swapping, SS7 interception, and social engineering attacks on carriers. A real-world example: an attacker calls your carrier, claims your phone was stolen, transfers your number to their device, and intercepts your MFA codes. It happens daily.

Phishing-resistant MFA options

FIDO2 security keys (YubiKey, Google Titan): Physical hardware keys that use public key cryptography. Can’t be phished because the key verifies the website’s identity before authenticating. Cost: $25-50 per key. Best for high-value accounts and administrator access.

Authenticator apps (Microsoft Authenticator, Google Authenticator): Generate time-based one-time codes on your phone. Better than SMS because codes aren’t transmitted over the cellular network. Free. Good enough for most business users.

Push notifications: Your authenticator app sends a push notification you approve or deny. Convenient but vulnerable to “MFA fatigue” attacks where attackers spam push requests until the user approves one. Mitigate with number matching (user must enter a code shown on screen).

Deployment strategy for Arizona businesses

  1. Start with admin accounts. Your IT admin, financial controller, and anyone with elevated permissions gets FIDO2 keys immediately.
  2. Roll out authenticator apps to all staff. Set a 30-day deadline. Provide a 15-minute training session showing how to set it up.
  3. Disable SMS MFA entirely. Once authenticator apps are deployed, turn off SMS as a fallback. It’s the weakest link.
  4. Enable conditional access policies. Require MFA for all external access, access from new devices, and access to sensitive data.
  5. Monitor MFA enrollment. Track who has enrolled and follow up with anyone who hasn’t by the deadline.

Getting MFA right

Asteroid IT deploys phishing-resistant MFA as part of every managed IT engagement. Whether you’re a CPA firm, medical practice, or defense contractor, we configure MFA that satisfies your compliance requirements.

Call us at 480-937-7021 or schedule a conversation.

Scroll to Top