Skip to content

Compliance · 6 min read

MFA Before Your Cyber-Insurance Renewal: A 10-Minute Setup

Cyber-insurance applications now require multi-factor authentication, and answering wrong can void your policy. Here is how to turn on MFA across Microsoft 365 or Google Workspace before you sign.

By Orion Grimm May 14, 2026

If your business carries cyber-liability insurance, you have probably noticed the renewal application getting longer and more pointed every year. Somewhere on that form is a question that looks innocent and is not: “Is multi-factor authentication enforced for all users on email and remote access?”

Answer “yes” when it is not actually true, and you have created a problem that only surfaces at the worst possible moment. When you file a claim after a breach, the insurer investigates. If they find MFA was not actually enforced, they can deny the claim on the grounds that you misrepresented your controls. The policy you paid for years becomes worthless exactly when you need it.

So before you sign the renewal, make the answer honestly “yes.” For most small businesses, that is genuinely a ten-minute job.

Why insurers care so much about this one control

Insurers are not being arbitrary. They have the claims data. The overwhelming majority of business email compromise and account-takeover claims trace back to a password that was phished or reused, on an account with no second factor. MFA stops that attack cold: even with the right password, the attacker is stopped at the second step. From the insurer’s point of view, MFA is the cheapest, highest-impact thing a small business can do, so they have made it a requirement rather than a recommendation.

The word that matters on the form is enforced. “Available” means the option exists. “Enforced” means a user literally cannot sign in without it. Insurers mean enforced.

Turning it on in Microsoft 365

The modern way to do this in Microsoft 365 is security defaults or, better, a Conditional Access policy in Microsoft Entra ID.

  1. Sign in to the Microsoft Entra admin center as a global administrator.
  2. For the simplest path, enable security defaults (Entra ID, Properties, Manage security defaults). This forces MFA registration for everyone, including admins, and is free on every tenant.
  3. For more control, leave security defaults off and build a Conditional Access policy that requires MFA for all users. This lets you exclude break-glass accounts and tune for trusted locations, and is the route we use for managed clients.
  4. Tell your team it is coming, with a day to enroll, so the first prompt is expected rather than alarming.

A word of caution: always create and test a break-glass admin account before you flip enforcement on, so you cannot lock yourself out of your own tenant. This is the step that turns a ten-minute task into a bad afternoon if skipped.

Turning it on in Google Workspace

In Google Workspace the feature is called 2-Step Verification, and the key is enforcement, not just availability.

  1. In the Google Admin console, go to Security, Authentication, 2-Step Verification.
  2. Turn it on and set it to enforce for the relevant organizational units. “Allow users to turn on” is not enforcement; “Enforcement: On” is.
  3. Set a reasonable enrollment grace period so people can register their phones or security keys.
  4. For higher-risk accounts (owners, finance, admins), consider requiring a hardware security key rather than codes.

Before you flip enforcement on, designate and test a super-admin break-glass account — a separate credential stored securely and used only for emergency recovery — so you have a verified path back in if your primary admin is locked out before enrollment completes.

As with Microsoft, give your team a heads-up and keep a recovery path for administrators.

What “all users” really means

The form says “all users,” and the gaps that void claims are almost always the accounts people forget:

  • Shared mailboxes and service accounts. These often get excluded “because it is inconvenient,” and that is exactly where attackers go.
  • The owner. Owners frequently exempt themselves and become the easiest target in the company.
  • Remote access and VPN. The form usually asks about remote access separately. If you have a VPN or remote-desktop setup, MFA needs to be on that too.
  • Former employees. An account that was never disabled, with no MFA, is a live door.

After you turn it on

Once MFA is enforced, you can answer the renewal question honestly, and you have measurably reduced the most common way small businesses get breached. Keep the screenshot of your enforcement settings with your policy documents; if you ever do file a claim, that evidence is worth having.

If you would rather have someone set this up correctly the first time, with break-glass accounts, the right exclusions, and a tested rollout, that is part of what a managed IT relationship covers. The free IT Health Check includes an honest read on whether your MFA is actually enforced or just switched on, which is the difference that matters when you sign that form.

Want this applied to your own business?

The free 30-minute IT Health Check turns the general advice in this guide into specific findings for your actual setup. Real findings, no sales pitch.