Skip to main content

Second Renaissance

A Case Study in MFA Rollout

If you ask any cybersecurity professional for the single most effective, low-hanging fruit to secure an organization, Multi-Factor Authentication (MFA) usually tops the list. Adding that extra verification step stops the vast majority of automated credential attacks dead in their tracks. It’s the digital equivalent of adding a second deadbolt to your front door (or calling up the Ghostbusters when there’s something strange in your neighborhood).

On paper, rolling out MFA sounds straightforward: enable a setting in your identity provider, ask everyone to download an authenticator app, and call it a day.

In practice? Expanding MFA across a massive, diverse enterprise is less like flipping a switch and more like trying to herd cats while riding a unicycle. We recently led a six-month effort to deploy MFA for a municipality with over 5,000 users. While the technical steps were complex, the real plot twist was that the “people problem” proved far more challenging than the technology itself.

The Human Factor is Not to be Forgotten

When you ask 5,000 employees across dozens of public departments to change their daily login habits, you are bound to hit a few bumps in the road. Getting stakeholders on board required addressing deeply held concerns from non-technical users who viewed the new security requirement with extreme skepticism.

Then came the logistical and legal edge cases:

  • Personal Phone Use For Work. Workers’ unions raised legitimate questions about requiring employees to install work-related authenticator apps on their personal smartphones. Does the city pay a phone stipend? Is the app tracking them? (Spoiler: it wasn’t, but building that trust took clear communication and alternative solutions like hardware security keys).
  • First Responders. Picture a firefighter or police officer rushing out the door for a 12-hour shift, leaving their personal cell phone sitting on their kitchen counter. If MFA blocks them from accessing their shift logs or squad car terminals because they forgot their phone, public safety is suddenly impacted.

Navigating these real-world scenarios required empathy, flexibility, and endless clear communication. The last thing we need is a Communication Breakdown (Sorry, Led Zepplin fans!)

Technical Hurdles

While winning over hearts and minds took up a massive chunk of project time, the technical environment offered plenty of its own hurdles:

  • Non-Standard Access Devices. A city infrastructure network isn’t just laptops and desktop PCs. It includes specialized field tablets, legacy industrial control hardware, and public kiosk systems that don’t play nicely with standard OAuth or modern authenticator flows.
  • Shared Accounts. We uncovered widespread use of shared or group accounts across shift workers (a cybersecurity cardinal sin on its own). Dismantling those shared logins and assigning individual, accountable identities without disrupting 24/7 operations was a massive undertaking.
  • Conditional Access Tuning. Finding the sweet spot for Conditional Access policies was critical. Require MFA every five minutes, and productivity grinds to a screeching halt; require it too rarely, and you leave doors wide open for attackers.

Striking the Balance Between Usability and Security

By the end of the six-month rollout, the city successfully transitioned over 5,000 employees to a secure, MFA-protected environment. The secret to success wasn’t just turning on security features—it was crafting a rollout strategy that respected operational realities, listened to user feedback, and provided flexible authentication pathways for unique workforce needs.

Securing your organization’s digital front door shouldn’t create operational chaos. At Second Renaissance, we specialize in guiding both government agencies and commercial enterprises through complex security transformations.

Whether you need expert Identity and Access Management (IDAM) strategies to streamline user authentication, or reliable Managed IT Services to keep your day-to-day operations running securely, our team has the hands-on experience to handle both the technical stack and the human element.

Ready to upgrade your access controls without alienating your workforce? Connect with Second Renaissance today to learn how we can help secure your enterprise.

more insights

Space Invaders arcade game PAUSED.
Assessment and Audit
Austin Clements

CMMC Paused But Not Forgotten

CMMC Paused But Not Forgotten If you work anywhere near the defense industrial base (or spend your days tracking federal cybersecurity mandates just for fun like I do), the recent

Read More »