Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

News

The one setting IT experts wish everyone would turn on today

The One Setting IT Experts Wish Everyone Would Turn On Today
The One Setting IT Experts Wish Everyone Would Turn On Today

Ask any IT professional what single change would do the most good for the average person's digital life, and you'll get the same answer almost every time. It isn't a fancy new antivirus program or a complicated password manager setup. It's a feature that already sits inside nearly every account you own, quietly waiting to be switched on. Most people ignore it because it takes an extra fifteen seconds at login. That small inconvenience, though,...

Ask any IT professional what single change would do the most good for the average person's digital life, and you'll get the same answer almost every time. It isn't a fancy new antivirus program or a complicated password manager setup. It's a feature that already sits inside nearly every account you own, quietly waiting to be switched on.

Most people ignore it because it takes an extra fifteen seconds at login. That small inconvenience, though, is doing an enormous amount of heavy lifting behind the scenes, and the data on just how much protection it provides has only gotten stronger heading into 2026.

What this setting actually is

What this setting actually is (Image Credits: Unsplash)
What this setting actually is (Image Credits: Unsplash)

The setting in question is multi-factor authentication, often shortened to MFA or called two-factor authentication. Instead of relying on a password alone, it asks for a second proof of identity, something like a code sent to your phone, a tap on an authenticator app, or a fingerprint scan.

The idea is simple. Even if someone steals or guesses your password, they still cannot get into your account without that second piece.

It's the digital version of needing both a key and a code to open a safe, and it closes a gap that password strength alone never could.

Why passwords alone keep failing

Why passwords alone keep failing (Image Credits: Pexels)
Why passwords alone keep failing (Image Credits: Pexels)

Passwords have been the weak link in online security for years, and the numbers back that up clearly. Okta's 2025 Secure Sign-in Trends Report says workforce MFA adoption reached 70% as of January 2025, which also means nearly a third of users still lacked MFA.

That gap is exactly where attackers focus their energy. Credential theft remains one of the most common ways criminals break into accounts.

22% of all 2025 breaches began with stolen credentials, the leading initial-access vector, per the Verizon 2025 Data Breach Investigations Report. People reuse passwords across sites, and a single leak from one unrelated service can hand an attacker the keys to a completely different account.

The number IT experts keep repeating

The number IT experts keep repeating (Image Credits: Unsplash)
The number IT experts keep repeating (Image Credits: Unsplash)

There's one statistic that shows up in nearly every security briefing, webinar, and internal memo about this topic. Research by Microsoft shows that MFA can block more than 99.2% of account compromise attacks, which is why starting in 2024 the company began enforcing mandatory MFA for all Azure sign-in attempts. That figure comes from a large scale internal study, not a marketing estimate. It's the kind of number that turns a nice to have setting into something closer to a baseline requirement, and it's a big reason security teams push this so hard rather than treating it as optional advice.

It still works even after your password leaks

It still works even after your password leaks (Image Credits: Pexels)
It still works even after your password leaks (Image Credits: Pexels)

One of the more reassuring parts of the research is what happens after a password has already been exposed in a breach. Microsoft's research demonstrates that MFA reduces account compromise risk by 99.22% across all user populations, and even when credentials are leaked through breaches, MFA maintains a 98.56% reduction in successful attacks. That distinction matters because password leaks happen constantly, often through no fault of the user. A stolen password from an old, unrelated website can end up on criminal marketplaces years later, and MFA is the thing standing between that leaked credential and your current, active accounts.

The sheer scale of the attacks being blocked

The sheer scale of the attacks being blocked (Image Credits: Unsplash)
The sheer scale of the attacks being blocked (Image Credits: Unsplash)

It helps to understand just how many attempts are happening every single day, because the volume puts the protection in perspective. Microsoft Entra ID blocked an average of 7,000 password attacks per second over the past year, and identity-based attacks rose 32% in the first half of 2025 compared with the same period in 2024.

Most of those attempts follow a predictable pattern. 97% of all identity attacks were password spray, where an attacker tests common passwords against thousands of accounts in parallel, and MFA breaks that math because even if the attacker guesses right, the second factor stops the login.

Scale like that is exactly why a control that stops the vast majority of attempts matters so much.

Not every version of this setting is equally strong

Not every version of this setting is equally strong (Image Credits: Unsplash)
Not every version of this setting is equally strong (Image Credits: Unsplash)

Here's where things get a little more nuanced, and where IT experts tend to add a caveat. Text message codes, authenticator apps, and hardware security keys all technically count as MFA, but they don't offer the same level of protection.

SMS codes are far better than nothing, yet they can be intercepted or phished, and regulators have started phasing them out in sensitive sectors. Authenticator apps are a step up, though still vulnerable to prompt bombing, where an attacker floods someone with approval requests hoping they'll accidentally tap approve.

Hardware keys and passkeys sit at the top of the tier list because they're cryptographically tied to the real website, leaving nothing for an attacker to intercept or trick a user into typing.

Passkeys are becoming the new standard

Passkeys are becoming the new standard (David Shankbone, CC BY 3.0)
Passkeys are becoming the new standard (David Shankbone, CC BY 3.0)

The push toward stronger, phishing-resistant authentication has picked up real momentum. Per the FIDO Alliance State of Passkeys 2026 report, 68% of surveyed organizations have deployed or are actively deploying passkeys for workforce sign-in, with the strongest momentum in the United States and United Kingdom.

Passkeys work differently from a typical code based system. Instead of typing anything, a user simply confirms their identity with a fingerprint, face scan, or device unlock, and the underlying cryptography handles the rest.

It's faster than a password and, so far, far harder for attackers to bypass at scale.

Why insurers and regulators are forcing the issue

Why insurers and regulators are forcing the issue (Image Credits: Pexels)
Why insurers and regulators are forcing the issue (Image Credits: Pexels)

This setting has quietly moved from a best practice to something closer to a requirement, largely because of how the insurance industry now treats it. Industry reporting on Marsh McLennan and other major brokers shows that missing or partial MFA is now among the top reasons for first-submission cyber policy denials, with carriers requiring MFA on remote network access, privileged accounts, and email at minimum, meaning an organization without MFA on those surfaces is often uninsurable in 2026.

That shift has ripple effects beyond large companies. Vendors, contractors, and smaller businesses working with insured partners increasingly face the same expectations, since one weak link in a supply chain can expose everyone connected to it.

What used to be a recommendation in an IT policy document is turning into a contractual necessity.

The excuses that keep people from turning it on

The excuses that keep people from turning it on (Image Credits: Pexels)
The excuses that keep people from turning it on (Image Credits: Pexels)

Given how strong the evidence is, it's fair to ask why adoption still isn't universal. Part of the answer is friction.

People worry about losing a phone, forgetting an app, or dealing with a login process that feels slower than what they're used to. There's also a lingering misconception that MFA requires buying special hardware or learning complicated new software.

In reality, most services let you enable it using an app you likely already have on your phone, and the setup usually takes only a few minutes. The perceived hassle rarely matches the actual experience once someone gets past that first setup screen.

How to actually switch it on

How to actually switch it on (Image Credits: Pexels)
How to actually switch it on (Image Credits: Pexels)

Turning this setting on is far less complicated than most people expect. Almost every major email provider, banking app, and social media platform has a security or login settings page with an option labeled two-factor authentication, two-step verification, or multi-factor authentication.

The general process looks the same everywhere. You choose a method, ideally an authenticator app or passkey rather than text messages when that option exists, confirm it once, and you're done.

From that point forward, a stolen or guessed password on its own simply isn't enough to get an attacker in.

Final thoughts

Final thoughts (Image Credits: Pexels)
Final thoughts (Image Credits: Pexels)

Security advice changes constantly, but this particular recommendation has stayed remarkably consistent for years, and the data keeps reinforcing it rather than contradicting it. A single setting, available for free on almost every account, blocks the overwhelming majority of the attacks people actually face.

It won't stop every sophisticated, targeted attack, and choosing the strongest available method still matters. Still, for the average person weighing a few extra seconds at login against the risk of losing an account entirely, the trade feels less like a hassle and more like an easy decision.

Read full story on Our Wabi Sabi Life

Related News

More stories you might be interested in.

1995 vs. 2026: How grocery store layouts have quietly changed to make you spend more
Our Wabi Sabi Life·6 hours ago

1995 vs. 2026: How grocery store layouts have quietly changed to make you spend more

Walk into almost any supermarket today and it feels familiar enough: carts, aisles, a wall of refrigerators humming in the back. Yet if you could drop a shopper from 1995 into a 2026 store, they would notice something is off almost immediately, even if they couldn't quite name it. The floor plan has been rebuilt, quietly and constantly, around behavioral data that simply didn't exist thirty years ago. The entrance used to be a doorway. Now it's...

6 passwords you should never reuse (yet most people still do)
Our Wabi Sabi Life·7 hours ago

6 passwords you should never reuse (yet most people still do)

Most of us know, at least in theory, that reusing passwords is a bad idea. Yet the habit persists almost everywhere, quietly linking accounts that were never meant to be connected. It only takes one leaked database for that convenience to turn into a much bigger problem than most people expect. 1. Your email password Your inbox is not just another account. It is the recovery point for almost everything else you own online, from banking to social...

The one setting IT experts wish everyone would turn on today
Our Wabi Sabi Life·8 hours ago

The one setting IT experts wish everyone would turn on today

Ask any IT professional what single change would do the most good for the average person's digital life, and you'll get the same answer almost every time. It isn't a fancy new antivirus program or a complicated password manager setup. It's a feature that already sits inside nearly every account you own, quietly waiting to be switched on. Most people ignore it because it takes an extra fifteen seconds at login. That small inconvenience, though,...

Billionaire Jeff Bezos called Amazon’s customer service to prove a point but waited in silence for more than 10 minutes — ‘It was really long’
Barchart·1 day ago

Billionaire Jeff Bezos called Amazon’s customer service to prove a point but waited in silence for more than 10 minutes — ‘It was really long’

Numbers can tell a story. Amazon (AMZN) founder Jeff Bezos believed they could also tell the wrong one. When customer complaints didn’t match what his team’s reports were saying, he decided there was only one way to settle the debate. Speaking on the Lex Fridman Podcast in December 2023, Bezos recalled an early Amazon meeting where executives revie...

Top