Your Pa$$word doesn't matter - Microsoft

“Focusing on password rules, rather than things that can really help – like multi-factor authentication (MFA), or great threat detection – is just a distraction.”

I’d not ventured into MFA until the recent attacks on GitHub/GitLab where users’ Git repos were being held ransom. It’s a lot easier than people perceive it, but the biggest issue I have with wanting to roll it out across my development team is that not everyone has a company issued smart device to put Google Authenticator (others are available) on to use for 2FA, and not everyone has a personal smart device. I don’t think it’s fair to ask colleagues to use their personal device as a 2FA device for work.

