Stolen passwords sit behind many of the account takeovers that hit insurance agencies. Multi-factor authentication stops most of those attacks, because a password alone no longer opens the door. This guide explains where agencies need it, which methods work best, and how to roll it out smoothly.
Why multi-factor authentication matters for agencies
Your agency holds a lot of valuable data. For example, a single mailbox can contain driver’s license numbers, dates of birth, loss runs, and bank details for premium payments. Attackers know this, so agency staff get a steady stream of phishing emails.
When a CSR enters a password on a fake login page, the attacker has it within seconds. However, with MFA in place, the attacker also needs the second factor. That extra step blocks one of the most common types of intrusion.
Carriers and cyber insurers care about this too. Many applications and renewal questionnaires ask whether you enforce MFA on email, remote access, and admin accounts. A weak answer can limit your coverage options.
Where agencies need MFA first
Start with the systems that hold the most data or grant the widest access. Then work outward to everything else.
- Email and Microsoft 365. This is the top target, so protect every account, including part-time staff and producers.
- Agency management system. Turn on MFA in your AMS if it supports it, or place it behind single sign-on.
- Remote access. VPNs, remote desktop gateways, and remote support tools all need a second factor.
- Carrier and rater portals. Enable MFA on every carrier portal and comparative rater that offers it.
- Banking and premium trust accounts. Require MFA for anyone who can move money or change payees.
- Admin accounts. IT and owner accounts with elevated rights need the strongest method you have.
Choosing the right MFA method
Not all second factors offer the same protection. Text message codes beat passwords alone, but attackers can intercept them through SIM swapping. Also, a fake help desk caller can talk staff into reading a code aloud.
Authenticator apps with push notifications make a solid default. However, turn on number matching, so users must type a number shown on the login screen. This stops push fatigue attacks, where criminals send approval requests until someone taps yes.
For owners, admins, and accounting staff, consider phishing-resistant methods. These include hardware security keys and passkeys that follow the FIDO2 standard. They only work on the real website, so a fake login page gets nothing useful.
Plan the rollout before you flip the switch
A rushed rollout creates lockouts and frustrated staff. Instead, plan it in stages and communicate early.
- Inventory every system that staff sign in to, including carrier portals and raters.
- Decide which method each group will use, starting with admins and accounting.
- Tell staff what is changing, when it happens, and why it protects clients.
- Enroll a pilot group first, then fix any problems they find.
- Roll out to everyone else in small batches, not all at once.
- Block legacy sign-in methods that skip MFA, such as older email protocols.
- Document a recovery process for lost or replaced phones.
Handle the exceptions carefully
Every agency has edge cases. For example, some producers resist installing apps on personal phones. In that case, a hardware key on a keychain works well and needs no app.
Shared logins cause another common problem. Some older carrier portals let a whole team use one account. Whenever possible, request individual logins, so each person has their own MFA and their own audit trail.
Finally, watch out for service accounts and scanners that send email. These often break when you disable legacy protocols. Therefore, test them during the pilot, and move them to modern authentication or a secure relay.
Keep MFA working over time
Multi-factor authentication is not a one-time project. Staff change phones, new hires join, and vendors add new portals. So review enrollment regularly and remove access for anyone who has left.
Also, pair MFA with conditional access policies where your licensing supports them. These rules can block sign-ins from unfamiliar countries or unmanaged devices. As a result, a stolen password and a tricked approval still face another barrier.
Help desk procedures matter too. Attackers often call while pretending to be a locked-out employee. Your IT provider should verify identity before resetting any MFA method.
How WEBIT helps
WEBIT plans and manages MFA rollouts for agencies, from the first inventory to final enrollment. We offer Duo MFA as an add-on and configure Microsoft 365 sign-in protections, including conditional access where your licensing allows. Learn more about our cybersecurity services.
Every client gets a CIS Controls baseline by default. In addition, our unlimited help desk handles lockouts and phone changes with verified identity checks. See how we support agencies on our insurance industry page.
Key takeaways
- Multi-factor authentication blocks most attacks that rely on stolen passwords.
- Protect email, the AMS, remote access, banking, and carrier portals first.
- Use number matching or phishing-resistant keys instead of text codes where possible.
- Roll out in stages, and plan for lost phones and shared logins.