What a year of password requests says about multi-factor sign-in

What a year of password requests shows about where a multi-factor sign-in rollout will snag, and how to plan around it.

Back to Insights
Photo: What a year of password requests says about multi-factor sign-in

The Story

Password requests are the most ordinary tickets we get, and they’re a good early warning for how a multi-factor sign-in rollout will go. The same phones, shared logins and devices that generate password calls are the ones that trip a rollout up.

From 19 August 2025 to 18 August 2026, 44 of our clients raised 69 tickets with “password” in the title, taking 13.7 hours. Most were short: a reset, a forgotten password, or the email password needed for a new phone or iPad. Only four tickets, from four clients, used multi-factor wording in the title.

What the password tickets were really about

Reading through them, a few patterns stand out.

  • New devices. Several requests were for the email password to set up a new phone, iPad or PC. Those are exactly the moments multi-factor sign-in asks for a phone to approve.
  • Shared logins. A few asked for the usernames and passwords to a business’s accounts, or for a shared sales login on a laptop.
  • Things that aren’t people. A scanner needing its scan-to-email password is an account that can’t approve a sign-in on a phone.
  • A warning from outside. At one client, dark web monitoring reported that a staff member’s password had turned up in a breach, and we changed it.

The four multi-factor tickets were problems with the authenticator app, a call about two-factor sign-in for business email, and a reset alongside a password request.

Why multi-factor sign-in is worth the friction

Microsoft says multi-factor authentication can block over 99.2% of identity-based attacks, and its security defaults require every user to register for it. A stolen password on its own stops being enough to get into someone’s mailbox.

The friction is real, though, and it lands on the people least interested in IT. Planning for it is what keeps a rollout from turning into a week of frustrated calls.

The objections you’ll hear

“I don’t want work apps on my personal phone.” Fair enough. Talk it through before the switch, not on the morning.

“I share this login with the front desk.” That’s usually the first account to sort out. Shared mailboxes can be opened by named people with their own sign-in, so nobody has to share a password or a phone.

“The scanner stopped working.” Microsoft notes that the older password-only way for a device to send email isn’t compatible with security defaults. Check printers and business software that send email before you turn anything on.

The order we’d switch it on

  1. Administrator accounts first, because they can change everything else.
  2. Find the accounts that aren’t one person: shared logins, scanners, and software that sends email. Give each one a plan.
  3. Pick a quiet week and tell staff what’s coming, what the prompt looks like and who to ring.
  4. Turn it on for everyone, with someone free to help on the first morning.
  5. Follow up the stragglers: people on leave, part-timers and anyone who changed phones.

What the first week looks like

Going by the tickets above, expect new phones, lost phones, an authenticator app that isn’t showing the prompt, and a scanner or shared login someone forgot. None take long if someone is ready to answer the phone.

If you’d like us to plan a rollout for your team, get in touch.

  • The Impact of Inaction

    "Without multi-factor sign-in, one stolen password is enough to get into someone's mailbox. Putting it off because the rollout sounds painful leaves that door open for longer."

  • The Bastion Fix

    We read through a year of password and sign-in tickets to find the patterns that cause trouble: new devices, shared logins and scanners. From those we set out the objections to expect and the order to switch multi-factor sign-in on.

Next Action

List the accounts in your business that aren't one person, including shared logins and scanners, before planning a multi-factor rollout.

Teaching Moment

The people aren't what trips up a rollout. It's the shared logins and devices nobody remembered, so find those first.

Want these results for your business?