We're in the process of deploying TOTP tokens to all staff across the organisation via Azure AD. We strongly encourage all staff to use Microsoft Authenticator as the default, and those with company issued mobile devices already have it pushed out via MDM. We also encourage all others to install Microsoft Authenticator (or similar) on their personal mobile devices. We're almost done with the rollout, but there are already people coming to us saying they've lost their token, or regularly forget it at home. Currently we're temporarily disabling MFA, or issuing a new token.
As the IT department, we exist to serve the needs of the organisation and we don't have the power to stop people from working because they don't have their token. Most of our users care for vulnerable people in care home settings, so we can't just send them home. They NEED access to our systems if they're at work, full stop.
We've suffered a couple phishing attacks recently that likely would have been prevented by MFA, which accelerated our rollout. The IT team all agree that we should never compromise our security standards for any one user's ignorance, incompetence, or forgetfulness... but we have to balance this with our obligations to the vulnerable people for whom our staff provide care.
Any tips or advice on how we could do this better? How do your organisations tackle these issues?
EDIT: I forgot to mention that IT are based at head office, and 80% of our staff are based in remote sites, many 1 hour or more by car away. We can't simply give users a new token on demand unless they work at head office.