What it actually is
A password can be guessed, reused, leaked in someone else's data breach, or typed into a convincing fake login page. Multi-factor authentication adds a second thing that an attacker in another country doesn't have: the phone in your pocket. Sign in, approve a prompt, done.
What it looks like day to day
Less than people expect. On a work computer you'll typically approve a prompt once every couple of weeks, not every morning. On a new device or from an unfamiliar location, you'll be asked immediately — which is exactly the point.
SMS codes
Better than nothing, worse than an app. Text messages can be intercepted by transferring a phone number to a new SIM, which has happened to Australian businesses. Use the app where you can.
The objections we hear
"Our staff aren't technical." Neither are most people who use it. The prompt is a button that says approve or deny, and the first week is the only awkward one. "We're too small to be a target." Small businesses aren't targeted; they're swept up. The attacks are automated and they check every password that has ever leaked, against every account they can find.
"We'll get locked out." That's a real risk and it's why the rollout matters. We register a second method for every person and keep documented break-glass access for the business, so a lost phone is an inconvenience rather than a crisis.
Where to turn it on first
If you only do one of those this month, do email. It's where invoices live, and invoices are what the people trying to get in are actually after.