Business account and MFA protection in Scotland

Make access safer without losing sight of the user

Business accounts open email, files, financial systems and services that keep work moving. Stratiis helps Scottish organisations review who has access, where multi-factor authentication (MFA) is needed, which methods fit the risk and how users recover access safely. The result should be a workable sign-in process with clear ownership and support.

What is multi-factor authentication?

MFA adds another check to a sign-in, such as a trusted device, authenticator app or security key. This makes a stolen password less useful to an attacker. MFA works best alongside appropriate permissions, account monitoring and a secure recovery process. Some methods resist phishing better than others, so the choice should reflect the service and the sensitivity of the access.

Why it matters

Protect the accounts people rely on

Start with access that could expose business information or allow important changes.

Harder account takeover

An extra sign-in check reduces reliance on a password alone.

Clearer ownership

Each account and elevated role has a named owner.

Safer recovery

Lost devices and changed roles have a defined support route.

Better visibility

Unexpected prompts and sign-ins can be reported and reviewed.

Access plan

What should an accounts and MFA plan include?

Review the users, services and recovery routes before switching on a new sign-in method.

Area Question to answer Useful output
Account inventory Which business-critical services and account types are in use? Prioritised account list.
Ownership Who approves access and reviews it when roles change? Named business owners.
Permissions Does each user have only the access needed for their work? Role and privilege review.
MFA method Which supported method gives suitable protection and usability? Method choice by risk.
Enrolment How will users register trusted devices or credentials safely? Guided rollout and checks.
Recovery How is identity verified before a reset or replacement device is approved? Secure support procedure.
Monitoring Who reviews suspicious sign-ins, repeated prompts and bypasses? Alert and response route.
Lifecycle How are accounts changed or removed when people leave or move role? Joiner, mover and leaver steps.

Keep emergency access and service accounts within the wider access plan, with appropriate controls, ownership and review rather than treating them as ordinary user accounts.

Practical starting points

Which accounts should be reviewed first?

Prioritise services where compromise would expose sensitive information or allow significant change.

Email and collaboration

Protect the mailbox and file access that can be used to reset or reach other services.

Administrator access

Review elevated roles, require strong sign-in and separate them from everyday work where appropriate.

Finance and payroll

Check access to payment, banking, HR and payroll services and their approval rights.

Remote access

Protect access from outside the workplace and review devices and sign-in context.

Shared or legacy accounts

Identify accounts with unclear ownership and reduce shared use where the service allows.

Recovery routes

Check how MFA is reset after a lost phone, changed device or support request.

How support starts

Move from account inventory to a supported rollout

Test normal sign-in, a suspicious prompt and a lost-device scenario before wider use.

1

Discover

List critical services, account owners, access routes and existing MFA.

2

Design

Agree methods, exceptions, recovery and support responsibilities.

3

Pilot

Enrol a small user group and test everyday and difficult cases.

4

Improve

Review adoption, sign-in issues, alerts and account changes.

Identity and Access covers how account decisions fit a wider system deployment.

People and safeguards

Make sign-in responsibilities clear

Users need straightforward guidance; owners need a safe way to approve access and recovery.

What Stratiis can help plan

An account and MFA readiness review.

Practical method selection and rollout support.

User guidance for unexpected prompts and lost devices.

Monitoring, recovery and review procedures.

What your team owns

Business approval for access and elevated roles.

Verification rules for account recovery requests.

Prompt reporting of suspicious sign-ins.

Updates when people join, move or leave.

Choosing a method

How should an organisation choose MFA?

Use the strongest practical method supported by the service and suitable for its users and risk.

Method Practical consideration What to plan
Passkeys or security keys Where supported, these can offer strong resistance to phishing. Device support, enrolment and recovery.
Authenticator challenge An app can be convenient, but users must reject prompts they did not initiate. Clear prompt guidance and reporting.
One-time codes Codes add a check but may still be entered into a fake site. Trusted sign-in route and user guidance.
Message-based codes SMS or email may be the available option for some services. Service limitations and account recovery.
Backup and recovery Lost credentials must not lead to an easy bypass. Identity checks and approved support.

The NCSC's MFA method guidance explains the different levels of protection. Choose and configure methods for your actual services rather than assuming every second factor offers the same protection. For a broader introduction, read why MFA matters.

When something looks wrong

Help users respond to unexpected account activity

Keep the reporting route easy to find, including when a user approved a prompt by mistake.

Unexpected prompt

Do not approve it. Report the prompt and check the account through a trusted route.

Repeated prompts

Report repeated requests promptly; they may indicate an attempted sign-in.

Lost device

Use the agreed support process to protect the account and replace the method.

Unusual sign-in

Ask the response team to review the event and any related account activity.

Monitoring and Response connects these reports to investigation and action.

Related Stratiis services

Connect account security to the wider plan

Sign-in protection works alongside clear access decisions, staff guidance and monitoring.

Common questions

Accounts and MFA FAQs

Answers to common questions about protecting business sign-ins.

What is MFA?

Multi-factor authentication uses more than one factor to verify identity. This may involve a password and a trusted device, or a passkey unlocked with a local PIN or biometric. It makes password theft alone less useful.

Which business accounts should use MFA?

Prioritise email, administrator, financial, HR, remote-access and other accounts that can reach sensitive information or important settings. Review all supported services as part of the account inventory.

Are passkeys and security keys better than codes?

Where supported and properly configured, FIDO2 passkeys and security keys can resist common phishing attacks better than one-time codes. The suitable method still depends on the service, devices, users and recovery plan.

Can MFA stop every account takeover?

No. Some methods can be phished or misused through approval prompts, and sessions or recovery routes may be targeted. Use MFA alongside limited access, monitoring and user reporting.

What should a user do with an MFA prompt they did not request?

Do not approve it. Report it through the organisation's trusted support route so the account and sign-in activity can be checked.

What happens when someone loses their phone or key?

Use a documented recovery process that verifies the person's identity before replacing the method. Do not bypass MFA simply because a caller says the request is urgent.

Should administrator accounts use a stronger method?

Elevated accounts can change important settings and should receive protection proportionate to that risk. Review stronger supported methods, separate roles and tighter monitoring.

How should MFA rollout be measured?

Track coverage of priority accounts, enrolment and recovery issues, unsupported services, unexpected prompts and any sign-in incidents. Use those findings to improve the plan.

Talk to Stratiis

Make business sign-ins safer and easier to manage

Tell us which services and account types matter most. We can help review access, plan MFA and give users a clear support route.

Contact Stratiis →