MICROSOFT 365ILLUSTRATIVE
SCOUTz product evidence supporting MFA Adoption Statistics for Small Business (2026)
What percentage of small businesses enforce MFA?

Kaseya's 2026 SaaS Security Report found that only 27 percent of more than 50,000 monitored small businesses were actively enforcing MFA policies in 2025.

MFA STATE

Policy enforcement and account state are different questions.

27%businesses enforcing MFA policy
56%end-user accounts disabled or inactive
Kaseya 2026 SaaS Security Report · 50,000+ small-business environments · calendar 2025
SCOUTz raccoon mascot carrying an evidence checklist forward

Short answer: MFA adoption in small businesses is still low. Kaseya's 2026 SaaS Security Report, based on more than 50,000 small-business environments monitored through 2025, found only 27 percent of those businesses were actively enforcing MFA policies, and 56 percent of individual end-user accounts had MFA disabled or inactive. Nearly three in four small businesses remain open to password-only attacks.

The two numbers, and why both matter

The 27 percent figure is about policy: whether the business requires MFA across its environment. The 56 percent figure is about accounts: whether a given user actually has it working. They measure different failures.

A business can have a policy on paper and still have accounts slipping past it, such as a service mailbox excluded years ago, a guest never enrolled, an executive who asked for an exception. A business with no policy at all depends on each person choosing to turn MFA on, and the account number shows how that goes.

Why this is the first thing to fix

Accounts without MFA fall to phishing, credential theft and password reuse far more easily, and once an attacker holds a working account they operate as that user inside email and files. Kaseya ties this directly to business email compromise and fraud, and notes that AI-written phishing is making the password step easier to beat.

MFA is also the control a cyber insurance application asks about first, which gives the MSP a second reason the owner will care: renewal.

What closing the gap involves

Kaseya's guidance: enforce MFA on every end-user and administrator account, monitor for accounts with MFA disabled or inactive, require it on risky sign-ins, block legacy authentication that bypasses it, and alert on MFA status changes and failed attempts.

In practice the policy flip is the easy part. The work is the exceptions: shared mailboxes, scanners that send mail, the owner's phone that is always "about to be replaced," the legacy app that breaks. A good MSP rollout inventories those first, fixes or documents each one, then enforces. That inventory is the billable project.

Using the gap in a sales conversation

Opening with "most small businesses don't enforce MFA" is a statistic. Opening with "eleven of your twenty-three accounts can sign in with a password alone, including two admins" is a finding. The first earns a nod. The second earns a meeting, because the owner now has a specific, checkable problem with a clear fix and a clear owner for the fix.

Frequently asked questions

What percentage of small businesses enforce MFA?

Only 27 percent of the more than 50,000 small businesses monitored in Kaseya's 2026 SaaS Security Report were actively enforcing MFA policies in 2025.

What percentage of accounts have MFA turned off?

56 percent of end-user accounts monitored in Kaseya's 2026 SaaS Security Report had MFA disabled or inactive.

Why is MFA still not universal in small businesses?

Exceptions accumulate: shared mailboxes, devices and legacy apps that cannot handle MFA, and individual users who were never enrolled. Without an enforced policy, adoption depends on each user.

How do you enforce MFA in Microsoft 365 for a small business?

Inventory accounts and exceptions first, fix or document each exception, block legacy authentication, then enforce MFA for all users and administrators with alerting on status changes.

Does cyber insurance require MFA?

Most cyber insurance applications ask whether MFA is enforced for email, remote access and administrator accounts, and a missing answer can affect eligibility or premium. Check the specific carrier's application.

How SCOUTz gets you there

SCOUTz is prospect intelligence for MSPs. With a prospect's read-only Microsoft 365 consent, it reads identity configuration and reports MFA state account by account, admins called out separately, alongside the policies that are or are not enforcing it, all without touching mail or files. The finding lands in a branded report in your MSP's name, with the exception list and rollout plan ready to become the first statement of work. Point it at any client and walk out with a deal. The open beta is free for thirty days at scoutzsecurity.io.