ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

MFA for Law Firms: Which Methods to Use and Which to Retire

A guide to choosing multi-factor authentication methods for a law firm, ranking authenticator apps, hardware keys and SMS, and planning a smooth rollout.

4 min readBy Counsel Cyber Team

Multi-factor authentication is the single most effective step most law firms can take to protect email and cloud systems. Yet "we have MFA" can mean very different things. A hardware security key and a code sent by text message both count as a second factor, but they resist attacks to very different degrees.

This post compares the common methods, explains where each fits, and offers a rollout approach that will not infuriate your attorneys.

Why MFA, and why not all MFA is equal

Passwords are stolen constantly, through phishing, reuse across sites and data breaches. MFA adds a second proof that an attacker usually does not have. CISA has long recommended MFA, and has also encouraged organizations to move toward phishing-resistant methods where possible.

Attackers have adapted. Some run fake sign-in pages that capture both your password and your one-time code, then use them immediately. Others bombard a user with approval requests until they tap "approve" out of frustration. Choosing the method matters.

The common methods, from strongest to weakest

Hardware security keys and passkeys

These use cryptographic proof tied to the real website, so a fake page cannot capture a usable credential. They are considered phishing-resistant. Physical keys are well suited to partners, administrators, and anyone handling trust accounts. Passkeys built into modern devices offer similar protection with less hardware to manage.

Trade-offs: cost per key, the need to issue spares, and a recovery process for lost keys.

Authenticator apps with number matching

Authenticator apps generate or approve sign-ins on a phone. When the sign-in requires the user to type a number shown on the login screen into the app, accidental or fatigued approvals become much harder. This is a strong, practical choice for most staff.

Trade-offs: depends on a phone, and still vulnerable to some real-time phishing kits.

Authenticator apps with simple push approval

A plain "Approve or Deny" prompt is convenient but susceptible to push fatigue. If your system still uses simple approvals, look for a setting that requires number matching or additional context.

One-time codes from an app

Time-based codes are better than SMS, but a user can still be tricked into typing the code into a fake site.

SMS text message codes

Text messages are better than no second factor, but they can be intercepted or redirected through SIM swapping and are easily phished. Use them only as a fallback while migrating users to stronger methods.

Voice call approvals and email codes

These are weakest. If a mailbox is the thing being protected, an emailed code offers little. Retire these where you can.

Where to apply MFA first

  1. Email and Microsoft 365 sign-ins, including mobile and webmail.
  2. Administrator accounts for every system.
  3. Remote access, such as VPN and remote desktop.
  4. Practice management and document management.
  5. Banking and trust account portals.
  6. Password manager and backup consoles.

Do not forget shared mailboxes, service accounts and older protocols such as legacy email access, which may bypass MFA unless disabled.

A rollout that works

Phase 1: Prepare

Inventory accounts and systems. Decide on a standard method and a fallback. Draft one page of plain instructions with screenshots. Plan how lost or replaced phones will be handled, including identity verification before resetting anyone's MFA.

Phase 2: Pilot

Start with the administrator, the managing partner and two or three tolerant volunteers. Fix anything that confuses them before the wider launch.

Phase 3: Roll out by group

Move through the firm in waves, with IT staff available for the first week. Provide a clear deadline and a simple way to get help.

Phase 4: Close the gaps

After the deadline, audit for accounts without MFA and for exceptions. Disable legacy sign-in methods and enforce MFA through policy, not through user choice.

Handling resistance

Attorneys may complain about inconvenience. Useful responses include:

  • Explain the risk in terms of client confidentiality and wire fraud, not technical jargon.
  • Use trusted device settings that reduce prompts on firm-managed machines without removing protection.
  • Have partners go first and speak positively about it.
  • Offer hardware keys to frequent travelers or those with unreliable phone service.

Recovery and reset procedures

MFA resets are a favorite attack path. An attacker calls the help desk pretending to be a locked-out partner. Require identity verification, such as a call-back to a known number or approval from a manager, before resetting any second factor.

Measure and maintain

Track MFA coverage monthly, aiming for every account. Review sign-in logs for unusual patterns such as repeated prompts. Revisit method choices annually as threats and products change.

Counsel Cyber configures and enforces MFA for law firms as part of broader security work, including migrations away from weaker methods. If you are not sure how your firm's MFA is configured, we can review it and give you a plain-English summary.