Not all multifactor authentication offers the same protection. SMS codes and simple push approvals can be phished or abused, while FIDO2 security keys and passkeys are designed to resist those attacks.
Key takeaways
What to know before you act
- Any MFA is far better than none, but SMS codes and simple push approvals can be phished, intercepted, or abused through prompt fatigue.
- Passkeys and FIDO2 security keys bind sign-in to the real website, so a fake page cannot capture a usable credential.
- Roll out phishing-resistant MFA in phases, starting with administrators and the people who move money.
Why it matters
What business leaders should understand
Attackers now target MFA directly with fake sign-in pages that relay codes, repeated push prompts, and SIM-swap fraud. Moving the highest-risk accounts to phishing-resistant methods closes the most common gaps.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with cybersecurity services and security awareness training.
Related reading: What is session hijacking? and 3 steps to a secure password.
How attackers get around weaker MFA
Attackers adapted as MFA became common. Adversary-in-the-middle phishing pages relay a user's password and one-time code to the real service in real time and capture the resulting session. Push-bombing sends repeated approval prompts until a tired user taps 'approve.' SIM swapping moves a victim's phone number to the attacker's device so SMS codes are delivered to them.
- SMS and voice codes: vulnerable to phishing relays and SIM swaps.
- Authenticator app codes: stronger, but still phishable on fake sign-in pages.
- Push approvals: improved by number matching, but still vulnerable to some phishing techniques.
- FIDO2 security keys and passkeys: designed to resist phishing by verifying the website's identity.
What makes passkeys and security keys different
Passkeys and FIDO2 security keys use public-key cryptography. The private key never leaves the user's device or security key, and the authenticator will only respond to the legitimate website it was registered with. A look-alike domain receives nothing it can reuse.
For users, passkeys can be simpler than passwords: they unlock with a fingerprint, face, or device PIN. Major platforms, including Microsoft Entra ID and Google Workspace, support passkeys and security keys, though available options depend on your licensing and configuration.
A practical rollout plan
Start where compromise would do the most damage and where users are most targeted. Keep a strong fallback method during the transition, and make recovery secure—an attacker who can talk the help desk into resetting MFA bypasses all of it.
- Phase 1: administrators, executives, finance, and payroll.
- Phase 2: remote access, email, and other high-value applications for all staff.
- Enable number matching and sign-in context for push MFA in the meantime.
- Issue two security keys to privileged users so one can be kept as a backup.
- Require identity verification before any MFA reset.
Practical action plan
Steps your business can take
Inventory which accounts and applications support passkeys or FIDO2 security keys.
Move administrators, finance staff, and executives to phishing-resistant MFA first.
Enable number matching for push-based MFA while the rollout continues.
Define a secure recovery process for lost keys and replaced phones.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
What is session hijacking?
See how stolen sessions bypass weaker MFA methods.
Explore nextRelated guide
3 steps to a secure password
Pair stronger MFA with unique passwords and a password manager.
Explore nextRelated guide
Microsoft 365 security checklist
Apply MFA, admin protections, and conditional access in Microsoft 365.
Explore nextService
Microsoft 365 management & security
Plan and roll out passkeys and conditional access for your users.
Explore nextWarning signs
Do not ignore these indicators
- Users report MFA prompts they did not initiate
- Administrators still sign in with SMS codes
- MFA reset requests are approved by phone without identity verification
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
Cybersecurity and Infrastructure Security Agency
Implementing Phishing-Resistant MFA
CISA's fact sheet on MFA attacks, FIDO/WebAuthn authenticators, and phased rollout of phishing-resistant MFA.
National Institute of Standards and Technology
NIST SP 800-63B: Digital Identity Guidelines—Authentication and Authenticator Management
NIST guidance on authenticator types, phishing resistance, and authentication assurance levels.
Cybersecurity and Infrastructure Security Agency
Zero Trust Maturity Model
A roadmap for maturing identity, device, network, application, and data protections over time.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
