Skip to content

Passwords and Multi-Factor Authentication

Passwords are still the front door to most of your accounts, and weak or reused ones are behind a large share of breaches. Two habits fix most of the risk: unique passwords and multi-factor authentication.

Use a long, unique password for every account

Section titled “Use a long, unique password for every account”

About 73% of passwords are duplicates, which means one leak can unlock several of your accounts. Give every account its own password. Longer is stronger, so favor a passphrase of several words over a short, complex string you cannot remember. Do not write passwords on notes near your desk, where anyone passing by can read them.

Nobody can remember a different long password for dozens of accounts, and you should not try. A password manager stores them in an encrypted vault and fills them in for you. You remember one strong master password, and it handles the rest. We can help you roll one out across your team.

Multi-factor authentication (MFA) asks for a second proof of identity after your password, usually a code or a tap on your phone. Even if someone steals your password, they cannot get in without that second step. Turn it on for email, banking, remote access, and any account that holds sensitive data.

Not all MFA is equal. Text-message codes are better than nothing, but they can be intercepted. In late 2020, Microsoft urged people to move off phone-based codes and use an authenticator app or a physical security key instead. Those options are harder to bypass, and we can set them up for your organization.

Administrator accounts are a top target, because they can change settings and create new accounts. Removing admin rights from everyday user accounts would prevent an estimated 98% of critical Windows vulnerabilities from being exploited. Give people only the access their job needs, and keep separate accounts for administrative work.

  • Every account has its own long password.
  • A password manager holds them, not sticky notes.
  • MFA is on for email, banking, and remote access.
  • MFA uses an app or security key rather than text messages where possible.
  • Daily work happens on standard accounts, not admin accounts.

Want help putting this in place? Call Robb Technology Group at (806) 370-4700 or email support@robb.tech.

Was this helpful?