Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own.
Step-by-step, plain-language instructions for turning on the security settings that matter — in Microsoft 365, AWS, Google Workspace, Google Cloud, and Azure Government. Every guide is written to be understood by a beginner, with a diagram and a checklist you can actually follow.
Pick your cloud, then work through the ten requirements in order. Each requirement is explained in everyday words, shows a process-flow diagram, and gives you a click-by-click checklist. Your checklist progress is saved only in this browser. The official campaign remains the authoritative source.
Read the official campaign ↗Email, files, Teams, and identity for the whole company.
Servers, storage, databases, and networking you rent by the hour.
Gmail, Drive, Docs, and Meet with a single admin console.
Google's rent-by-the-hour compute, storage, and networking.
A separate, sovereign Azure cloud built for U.S. government data.
Each maps to the Brilliant at the Basics IT Top 10 and to the NIST SP 800-171 / CMMC Level 2 controls behind DFARS 252.204-7012.
Make a stolen password useless on its own.
Give each person only the access their job needs — and no more.
Keep a live list of every device, identity, and app you defend.
Record important events and watch for trouble.
Keep one compromised thing from reaching everything else.
Find weak spots and fix the risky ones first.
Scramble sensitive data so only the right people can read it.
Be able to restore your data after an attack or outage.
Start every service from a known-good, hardened setting.
Use AI and share files without leaking sensitive information.
Click any cell to jump straight to that guide.
These guides are independent education. Cloud consoles and product names change often, so confirm each step against the provider’s own documentation. Following these steps does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Content last reviewed 2026-07-21.