Cybersecurity

Phishing-Resistant MFA and Passkeys for Business

Compare MFA methods, understand MFA fatigue and token theft, and plan a move to passkeys and security keys.

Reviewed October 10, 2026 3 minute read Reviewed by Meta IT Pro
Part of the Cybersecurity Learning Center

Not all multifactor authentication offers the same protection. SMS codes and simple push approvals can be phished or abused, while FIDO2 security keys and passkeys are designed to resist those attacks.

Key takeaways

What to know before you act

  • Any MFA is far better than none, but SMS codes and simple push approvals can be phished, intercepted, or abused through prompt fatigue.
  • Passkeys and FIDO2 security keys bind sign-in to the real website, so a fake page cannot capture a usable credential.
  • Roll out phishing-resistant MFA in phases, starting with administrators and the people who move money.

Why it matters

What business leaders should understand

Attackers now target MFA directly with fake sign-in pages that relay codes, repeated push prompts, and SIM-swap fraud. Moving the highest-risk accounts to phishing-resistant methods closes the most common gaps.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

How attackers get around weaker MFA

Attackers adapted as MFA became common. Adversary-in-the-middle phishing pages relay a user's password and one-time code to the real service in real time and capture the resulting session. Push-bombing sends repeated approval prompts until a tired user taps 'approve.' SIM swapping moves a victim's phone number to the attacker's device so SMS codes are delivered to them.

  • SMS and voice codes: vulnerable to phishing relays and SIM swaps.
  • Authenticator app codes: stronger, but still phishable on fake sign-in pages.
  • Push approvals: improved by number matching, but still vulnerable to some phishing techniques.
  • FIDO2 security keys and passkeys: designed to resist phishing by verifying the website's identity.

What makes passkeys and security keys different

Passkeys and FIDO2 security keys use public-key cryptography. The private key never leaves the user's device or security key, and the authenticator will only respond to the legitimate website it was registered with. A look-alike domain receives nothing it can reuse.

For users, passkeys can be simpler than passwords: they unlock with a fingerprint, face, or device PIN. Major platforms, including Microsoft Entra ID and Google Workspace, support passkeys and security keys, though available options depend on your licensing and configuration.

A practical rollout plan

Start where compromise would do the most damage and where users are most targeted. Keep a strong fallback method during the transition, and make recovery secure—an attacker who can talk the help desk into resetting MFA bypasses all of it.

  • Phase 1: administrators, executives, finance, and payroll.
  • Phase 2: remote access, email, and other high-value applications for all staff.
  • Enable number matching and sign-in context for push MFA in the meantime.
  • Issue two security keys to privileged users so one can be kept as a backup.
  • Require identity verification before any MFA reset.

Practical action plan

Steps your business can take

01

Inventory which accounts and applications support passkeys or FIDO2 security keys.

02

Move administrators, finance staff, and executives to phishing-resistant MFA first.

03

Enable number matching for push-based MFA while the rollout continues.

04

Define a secure recovery process for lost keys and replaced phones.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • Users report MFA prompts they did not initiate
  • Administrators still sign in with SMS codes
  • MFA reset requests are approved by phone without identity verification

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.