What is phishing-resistant MFA and do we need it?
Phishing-resistant MFA is multifactor authentication that a fake login page cannot capture and replay, meaning FIDO2/WebAuthn passkeys or security keys and PKI-based smart cards. CISA calls it the gold standard. Text codes, one-time codes and plain push approvals can be phished or abused, so roll out phishing-resistant MFA to administrators and high-value users first, then to everyone else.
Why ordinary MFA is not enough
Any MFA beats none. But CISA's fact sheet lists the attacks that defeat weaker forms: phishing pages that collect your password and six-digit code in real time, push bombing that floods a user with approval prompts until they tap Accept, SS7 network exploitation to intercept text codes, and SIM swaps that move your phone number to an attacker.
Phishing-resistant methods work differently. The credential is bound to the real website, so a look-alike site cannot use it, and there is no code for a user to read out or type into the wrong place.
The options, strongest to weakest
- FIDO2/WebAuthn: passkeys built into laptops and phones, or separate USB/NFC security keys. Phishing-resistant and the most widely supported.
- PKI-based: smart cards and certificate-based authentication. Phishing-resistant but requires mature identity management.
- Authenticator app codes or push with number matching: resistant to push bombing but still phishable. CISA calls these the best interim option for small and mid-size businesses.
- Push without number matching: vulnerable to push bombing and user error.
- SMS or voice codes: vulnerable to phishing, SS7 and SIM swap; a last resort.
Where to start
CISA suggests phasing the rollout by asking which resources matter most and which users are high-value targets. In most companies that means:
- Global and privileged administrators, including your MSP's technician accounts
- Help desk staff who can reset passwords
- Finance staff who approve payments, and executives
- HR and legal staff with access to sensitive records
- Email, single sign-on and remote access first, because most hosted mail and SSO systems already support FIDO
Doing it in Microsoft 365
Microsoft Entra ID supports passkeys (FIDO2) and certificate-based authentication, and Conditional Access can require a phishing-resistant method for specific users or apps. Microsoft also recommends protecting emergency access accounts with a passkey or certificate-based authentication, using a method different from your regular admin accounts, and keeping those accounts excluded from Conditional Access policies that could lock them out.
Microsoft recommends FIDO2 security keys, or passkeys in the Microsoft Authenticator app, for highly regulated industries and users with elevated privileges, and synced passkeys as a convenient option for most other users. Plan for lost keys and new devices: register a backup method, document recovery, and make sure the help desk cannot be talked into bypassing the process.
Handle the systems that cannot do it
Some older applications support no MFA, or only weak MFA. CISA recommends putting them behind your identity provider and single sign-on where possible, planning upgrades or replacements, and escalating any remaining risk to senior leadership so it is a decision, not an accident.
The same applies to the rollout itself. CISA advises IT and security leaders to present the risks of weak or missing MFA to top leadership for approval, because senior leaders are best placed to manage the cultural and communication side of the change. Where phishing-resistant MFA is not yet possible, CISA recommends number matching and other detection controls in the meantime.
Common follow-up questions
Is Microsoft Authenticator phishing-resistant?
Authenticator codes and push approvals with number matching are not phishing-resistant, though number matching resists push bombing. A device-bound passkey stored in Microsoft Authenticator uses FIDO2 and is phishing-resistant. Check which method your policy actually requires.
Do passkeys replace passwords?
They can. A FIDO2 passkey unlocked with a PIN or biometric can serve as a passwordless sign-in that also satisfies MFA. Many organizations run both during a transition, then reduce password use as applications and users move over.
Do cyber insurers or CMMC require phishing-resistant MFA?
Requirements vary. NIST SP 800-171 Rev 2 requires MFA for local and network access to privileged accounts and network access to non-privileged accounts, but does not mandate a phishing-resistant method. Insurer questionnaires differ by carrier, so read your application. CISA recommends phishing-resistant MFA regardless.
LAN Service Group plans and deploys phishing-resistant MFA for small and mid-size businesses on Microsoft 365, starting with administrators and high-value users and including recovery and emergency-access procedures.
Talk to LAN Service Group (888) 281-7243