Shared and individual accounts.
FOR INDIVIDUAL ACCOUNTS
Each person enables it on their own account.
Require it for anyone with administrative access.
FOR SHARED BUSINESS ACCOUNTS
More difficult, since the second factor is on one device.
WHAT TO DO
Use accounts supporting multiple users where possible Where a shared login is unavoidable, ensure more than one person can authenticate Store recovery codes accessibly to authorised people
WHY SHARED LOGINS ARE A PROBLEM
No attribution The second factor on one device Nobody can be removed individually
WHAT TO PREFER
Services allowing individual accounts with roles.
WHEN SOMEONE LEAVES
Remove their account For shared accounts, change the password and reset the second factor
THAT SECOND PART
Frequently forgotten. A former employee may still have a working authenticator.
WHAT TO DOCUMENT
Which accounts have it enabled Where recovery codes are Who can authenticate
WHAT TO REVIEW
Quarterly.