Skip to content

Free tool · Private to your browser · No signup

Where is MFA missing in your business?

"We have MFA" and "MFA actually protects us" are different statements. Check the login surfaces attackers target — including the legacy protocols that bypass MFA entirely — and see your most dangerous gap. Nothing is sent anywhere.

Optional — it personalizes the result. Every employee is a potential entry point through any surface you leave unprotected.

Check every surface where MFA is enforced today (for the legacy-protocols row, check it if those protocols are turned off). Leave the rest unchecked — those are your gaps.

Reading this without JavaScript?

The list above is the checklist itself: any surface you can't honestly say is MFA-protected is a gap worth closing. The most important line is the legacy-protocols one — if those are still on, MFA can be bypassed on every account. The free IT Health Check covers all of them against your real setup.

Want the gaps closed?

Book the free IT Health Check

Straight answers

Is having MFA "on" enough?

Not by itself. Two things quietly defeat MFA: leaving it optional instead of enforced, and leaving legacy sign-in protocols (IMAP, POP, older SMTP auth) enabled — those bypass MFA entirely. This calculator asks about both, because "we have MFA" and "MFA actually protects us" are different statements.

Why weight some surfaces higher?

Because a gap on remote desktop, VPN, email, admin accounts, or legacy protocols is where real incidents start — those carry the highest weight. A missing MFA on a low-traffic app matters less than an exposed RDP login. The score reflects real-world risk, not a flat checklist.

Do you store what I enter?

No. There is no signup and nothing is sent anywhere — the whole calculation runs in your browser. Your answers never leave this page.

We are tiny. Is MFA worth the friction?

Yes, and it is cheaper than you think — most of it is configuration on licenses you already own, not new spend. Enforced MFA with legacy protocols disabled is the single highest-return security control a small business can turn on, and it is what cyber-insurance carriers now require.

MFA done right is a morning's work.

Enforcing MFA everywhere and turning off the legacy protocols that bypass it is standard managed-IT work — and the highest-return security control a small business can turn on.