Start with the accounts that matter, answer the real objections about shared phones and lost devices, set it up with each person rather than instructing them, and lead by doing it first.

The objections are real

Resistance to this is usually treated as a discipline problem, and it is almost always a practical one.

People do not want to install a work application on a personal phone. People who share a device cannot see how it will work. People who have been locked out of something before are wary of adding another way to be locked out.

And somebody who has never seen an account compromised has no reason to accept daily friction for a risk that feels theoretical.

Each of those has an answer, and a rollout that supplies the answers works while one that repeats that it is important does not.

The objections and what to say

The fourth removes most of the perceived cost. People imagine entering a code on every login, and in practice a trusted device is asked once every few weeks.

The personal phone problem

Worth taking seriously, since it is the objection most often dismissed.

Requiring somebody to install something on a device they own, for work, is a genuine imposition and some people will simply refuse.

The alternatives are real: a small hardware key, a shared work device kept on site, or codes by message where the account supports it.

A hardware key costs a modest amount, requires no installation, works on any machine, and removes the objection entirely.

For a business with three or four people who need protecting, buying keys is cheaper than the argument and produces better security than an application anyway.

Offering a choice converts a refusal into a preference.

Sequence it

Rather than announcing that everybody must do it by Friday.

Start with the owner and whoever has the most access, publicly, so the first people affected are the ones asking.

Then the accounts that matter most rather than every account: email first, then hosting and the registrar, then everything else over time.

Doing email first also demonstrates the value, since that is where a compromise does the most damage and where the person can see why.

Everything else can follow over weeks, which spreads the friction and lets people get used to it one account at a time.

A rollout that starts with the least important account produces the most complaint for the least benefit.

Sit with each person

The step that makes the difference and that nobody budgets for.

Setting this up takes about ten minutes per person if somebody does it with them, and an indefinite amount of time if they are sent instructions.

Do it in person or on a call, together, and finish by having them log out and back in so the whole cycle has been seen once.

Print or record their recovery codes at the same time, since that is the moment they exist and the moment they are otherwise ignored.

Ten minutes each removes almost all of the resistance, because most of it is uncertainty rather than objection.

A worked example

A business of six announced by email that two-factor would be required on all accounts within a week.

Two people did it, three did nothing, and one said plainly she would not install anything on her own phone.

They restarted differently: the owner set his up first and said so, bought two hardware keys for the people who did not want an application, and booked ten minutes with each person over a fortnight.

Email was done first and everything else followed over the next month.

All six were covered within three weeks, including the person who had refused, because the objection had been about the phone rather than about the measure.

Prepare for the lockout before it happens

Since one bad experience undoes the whole thing.

Somebody will lose a phone, get a new one, or wipe the device, and how that goes determines whether the rest of the team keeps cooperating.

Hold recovery codes for every account somewhere the business can reach, so restoring access takes minutes rather than a day of support requests.

Make sure at least two people can administer each account, so nobody is dependent on one person being available.

Tell everybody in advance what to do if it happens, so the first occurrence is a procedure rather than a crisis.

A smooth first recovery is worth more to adoption than any amount of explanation beforehand.

Say why, once, concretely

Rather than repeatedly and in general terms.

Explain the specific thing it prevents: somebody who has your password, obtained from a leak or a fake login page, still cannot get in.

Mention that passwords do leak, routinely, and that this is why reused passwords matter.

Where you have had an actual incident, or a near miss, say so, since a real example does more than any explanation.

Then stop mentioning it, because repetition reads as nagging and the setup conversation is where the work is done.

The counter-case

Not every account needs it.

Applying it to everything produces friction with no benefit and hardens attitudes for the accounts where it matters.

Some tools also implement it badly, asking for a code constantly or handling recovery poorly, and those are worth exempting rather than defending.

And where somebody genuinely cannot manage it, a strong unique password on a well-monitored account is a reasonable compromise rather than a failure.

Cover email, hosting, the registrar, and anything financial, offer a choice of method, and sit with each person for ten minutes.

The rollout

  1. Do your own first, and say so.
  2. Offer hardware keys as an alternative.
  3. Start with email, then hosting and the registrar.
  4. Book ten minutes with each person.
  5. Store recovery codes as you go.
  6. Make sure two people can administer each account.
  7. Say what happens if a phone is lost.

Step two removes the objection that stops rollouts entirely, and a small hardware key costs less than the argument it prevents.

The technical side is covered in turning on two-factor everywhere that matters.


Frequently asked questions

Why do people resist?

The objections are practical rather than obstinate: not wanting work software on a personal phone, sharing a device, having been locked out before, and a risk that feels theoretical.

What about the personal phone objection?

Take it seriously and offer alternatives: a small hardware key, a shared work device, or codes by message. A key costs less than the argument and works better anyway.

What order should I roll it out in?

The owner first and publicly, then email, then hosting and the registrar, then everything else over weeks. Starting with the least important account produces complaint for no benefit.

What makes it stick?

Sitting with each person for ten minutes rather than sending instructions. Most resistance is uncertainty, and it disappears once somebody has seen the whole cycle once.

What about somebody losing their phone?

Prepare first. Hold recovery codes where the business can reach them and make sure two people can administer each account, so the first recovery is a procedure rather than a crisis.

Should it go on every account?

No. Applying it everywhere produces friction without benefit and hardens attitudes where it matters. Cover email, hosting, the registrar, and anything financial.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Announced it by email and nothing happened?

Book ten minutes with each person instead. Most of the resistance is uncertainty rather than objection.

Start a Conversation