
Most small and midsize businesses turned on multi-factor authentication years ago and moved on. The trouble is that the most common forms of MFA, text message codes, authenticator app codes and push approvals, can now be defeated with off-the-shelf phishing kits and a convincing phone call. Phishing-resistant MFA closes that gap by binding the sign-in to the real website, so a fake page gets nothing it can reuse.
This guide explains how attackers get around ordinary MFA, what counts as phishing-resistant under CISA and NIST guidance as of October 2026, and a rollout plan a business can actually finish. If you want a team to design and run it with you, our identity and access security service specifies phishing-resistant factors for administrators first and then for the rest of the workforce.
Key takeaways
- SMS codes, app codes and push approvals all reduce risk, but none of them are phishing-resistant. Attackers bypass them with adversary-in-the-middle kits, push bombing, SIM swaps and help desk impersonation.
- CISA calls FIDO/WebAuthn the only widely available phishing-resistant authentication. PKI smart cards (PIV and certificate-based authentication) also qualify.
- NIST SP 800-63B-4, final since July 2025, says OTP and out-of-band methods are not phishing-resistant and requires AAL2 services to offer at least one phishing-resistant option.
- Roll out to administrators and break-glass accounts first, then finance, HR, executives and the help desk, then everyone else.
- Enroll two authenticators per person, write the lost-key process before launch, and remove the weak fallback methods once enrollment is done.
Where this guidance comes from. This article is built on primary sources: CISA’s October 2022 MFA fact sheets, NIST SP 800-63B-4 (Digital Identity Guidelines, final July 2025), OMB memorandum M-22-09, the joint CISA and FBI advisory on Scattered Spider (updated July 2025), an FBI IC3 public service announcement on SIM swapping, Microsoft’s threat research on adversary-in-the-middle phishing, and Microsoft Learn documentation for Entra ID. It also reflects our veteran-led team’s field work investigating compromised accounts.
Why ordinary MFA gets bypassed
Ordinary MFA assumes that whoever has the code or taps approve is legitimate. Attackers have built tools around that assumption.
Adversary-in-the-middle phishing kits
An adversary-in-the-middle (AiTM) kit puts a proxy server between the victim and the real login page. Microsoft described the method in July 2022: the proxy runs two separate TLS sessions, one with the victim and one with the real site, and captures both the password and the session cookie issued after MFA succeeds. The victim sees a real MFA prompt, relayed.
In that campaign Microsoft reported attempts against more than 10,000 organizations since September 2021, using open-source kits such as Evilginx2, Modlishka and Muraena. The attackers then read finance mail, hid their activity with inbox rules and replied to payment threads. That is the bridge from a phished login to business email compromise and payment fraud.
MFA fatigue and push bombing
In push bombing, the attacker already has the password and triggers sign-in after sign-in until the user approves out of annoyance or by accident. The joint CISA and FBI advisory on Scattered Spider lists it as one of that group’s methods.
SIM swapping and SMS interception
A text message code is only as strong as your carrier’s account security. In a SIM swap, a criminal gets the carrier to move your number to a SIM they control, and your codes go to them. The FBI’s IC3 reported 1,611 SIM swapping complaints with more than $68 million in adjusted losses in 2021, up from 320 complaints and about $12 million across 2018 through 2020. CISA also lists SS7 exploitation, which intercepts SMS inside the phone network.
Help desk impersonation
The Scattered Spider advisory, updated in July 2025, says the actors posed as employees to convince IT and help desk staff to reset passwords and transfer the employee’s MFA to a device the attacker controls. They also posed as IT staff to talk employees out of their one-time codes. No authenticator survives a recovery process that hands it to whoever asks politely.
What counts as phishing-resistant MFA
NIST SP 800-63B-4 treats cryptographic authentication as phishing-resistant when the response is bound to the verifier, either through channel binding or through audience-restricted assertions. In plain terms, the authenticator checks which website is asking and will only answer the real one.
The same document lists passwords, look-up secrets, OTP and out-of-band authentication (push and SMS) as not phishing-resistant. CISA names two families that do qualify.
FIDO2/WebAuthn security keys
CISA calls FIDO/WebAuthn “the only widely available phishing-resistant authentication.” A security key holds a private key created for one site that never leaves the key. The browser includes the site’s origin in what gets signed, so a look-alike domain gets nothing the real site will accept.
Passkeys: synced and device-bound
Passkeys use the same FIDO standards. The FIDO Alliance describes two kinds: synced passkeys, which are copied between a person’s devices through an end-to-end encrypted cloud service, and device-bound passkeys, which never leave a single device such as a security key. NIST SP 800-63B-4 integrates syncable authenticators and allows them at AAL2, but says they shall not be used at AAL3 because the private key is exportable. A common pattern is synced passkeys for general staff and device-bound keys for administrators.
PIV smart cards and certificate-based authentication
The second family is PKI-based MFA, such as the federal PIV and CAC cards. CISA notes it is less common and requires highly mature identity management. In Microsoft Entra ID, certificate-based authentication (multifactor) is one of three method types in the built-in Phishing-resistant MFA authentication strength, alongside Windows Hello for Business or platform credentials and FIDO2 security keys.
Phishing-resistant MFA vs other methods: comparison table
This table sorts common methods from weakest to strongest, based on CISA’s MFA hierarchy and NIST SP 800-63B-4.
| Method | Phishing-resistant? | Main way it gets bypassed | Where it fits |
|---|---|---|---|
| SMS or voice code | No | SIM swap, SS7 interception, relay through a fake page | CISA calls it a last-resort option; NIST lists the phone network as a restricted authenticator |
| Authenticator app code (TOTP) | No | User types the code into an AiTM page, which relays it | Better than SMS; a stepping stone |
| Push approval without number matching | No | Push bombing; approving a prompt the user did not start | Should be retired; NIST no longer accepts approve-only prompts |
| Push approval with number matching | No | AiTM relay; help desk social engineering | CISA’s recommended interim step |
| Synced passkey | Yes | Weak account recovery; compromise of the sync account | General workforce (allowed at NIST AAL2) |
| FIDO2 security key or device-bound passkey | Yes | Lost key with a weak replacement process | Administrators, finance, executives, break-glass accounts (AAL3-capable) |
| PIV smart card or certificate-based auth | Yes | Card issuance and revocation gaps | Organizations with mature PKI and federal work |
| Windows Hello for Business or platform credential | Yes | Device compromise; weak device enrollment | Managed Windows and Mac fleets |
Not sure where your business sits on this table? Start with our free cyber risk check, or request an identity security review online and we will map every sign-in method in use, including the forgotten ones.
What CISA, NIST and OMB require
CISA fact sheets (October 2022)
CISA released two fact sheets on October 31, 2022. The first lists the threats, ranks MFA types from strongest to weakest and says to start with high-value targets such as system administrators, HR staff and attorneys, and with email and identity servers. The second, on number matching, says number matching “is not as strong as phishing-resistant MFA” but is “one of the best interim mitigation” steps for organizations that cannot move yet.
NIST SP 800-63B-4 (final July 2025)
NIST published SP 800-63B-4 as final on July 31, 2025, replacing Revision 3 from March 2020. Verifiers shall offer at least one phishing-resistant option at AAL2, federal agencies shall require phishing-resistant authentication for staff, contractors and partners, AAL3 requires a non-exportable private key with phishing resistance, and the phone network is a restricted authenticator. For push, NIST now requires the user to transfer a secret between devices, and verifiers to rate-limit push notifications.
OMB M-22-09 (January 2022)
The federal zero trust memorandum, dated January 26, 2022, told agencies to require a phishing-resistant method for staff, contractors and partners, naming PIV and the W3C WebAuthn standard. It directed agencies to stop supporting methods that register phone numbers for SMS or voice, supply one-time codes or receive push notifications, with goals set for the end of fiscal year 2024. It binds federal agencies, not private companies, though contractors who sign in to agency systems fall inside its scope. This is general information, not legal advice; confirm your obligations with counsel or your assessor.
A rollout plan for phishing-resistant MFA
Most stalled projects fail on sequencing, not technology. This order follows CISA’s priorities and Microsoft’s emergency access guidance.
- Inventory identities and methods. List every account, including shared, service and former-employee accounts, the methods registered on each, and apps that cannot do modern authentication.
- Build break-glass accounts first. Create and test emergency access accounts before changing any policy.
- Move administrators. Give every privileged role device-bound FIDO2 keys or certificate-based authentication, on admin accounts that are not used for email or browsing.
- Move high-risk roles. Finance, payroll, HR, executives and the help desk itself, the targets CISA and the Scattered Spider advisory describe.
- Enroll everyone with two authenticators. A primary passkey or key plus a backup, enrolled in person or over a verified video call. Buy keys in pairs and track them like laptops.
- Enforce and remove fallbacks. Require a phishing-resistant authentication strength through conditional access, then remove SMS, voice and app-code methods so attackers cannot downgrade the sign-in.
- Harden recovery. Write the lost-key and new-device process and train the help desk on it before enforcement day.
- Monitor. Alert on new authenticator registrations, break-glass sign-ins and sign-ins from unmanaged devices.
Break-glass accounts done right
Microsoft’s Entra guidance calls for two or more emergency access accounts that are cloud-only on the onmicrosoft.com domain, not federated or synchronized. It recommends passkeys (FIDO2) or certificate-based authentication for them, using methods different from your other admin accounts. Exclude them from blocking conditional access policies, alert on every sign-in, and test them at least every 90 days.
The lost or stolen key process
Decide in advance who can register a new authenticator and how identity is proven. For example, a policy might require a live video check against the employee’s HR photo plus manager confirmation before the help desk issues a temporary access pass. Revoke the lost key at once, review recent sign-ins and log every reset.
What phishing-resistant MFA does not fix
Strong sign-in does not protect a session stolen after login. Infostealer malware on an unmanaged laptop can lift session tokens, and Microsoft’s Token Protection control, which binds tokens to a registered device, currently covers only certain apps and platforms. We cover how intruders use stolen credentials and tokens to move between systems in our guide to credential theft and lateral movement on Windows.
Other gaps to close:
- Legacy protocols that skip MFA.
- OAuth consent grants and third-party apps that hold standing access to mailboxes and files.
- Weak passwords and reuse, which still feed credential stuffing attacks against small businesses.
- Old MFA methods left registered after enforcement, which give attackers a downgrade path.
If your password policy is still the weak link, start with our guide to business credential security.
How much does phishing-resistant MFA cost?
Cost depends on your environment. The main drivers are:
- Hardware. How many people need physical keys, and whether you buy two per person.
- Licensing. Whether your identity platform tier includes conditional access, authentication strengths and token protection.
- Legacy systems. Apps, VPNs and shared workstations that cannot do FIDO2 and need a workaround or replacement.
- Support time. Enrollment sessions, help desk training and the first weeks of lost-key tickets.
How Honeybadger helps with phishing-resistant MFA
Our identity and access security team treats identity as a security function. That covers identity lifecycle across Entra ID, Active Directory, Google and Okta, phishing-resistant factors, conditional access, privileged access, and break-glass accounts that are vaulted, deliberately excluded and monitored for any use. When an account is already compromised, we revoke sessions first, then remove persistence such as inbox rules, app passwords and attacker-registered MFA methods.
Our Microsoft 365 and SaaS security service handles tenant administration and connected-app governance, the OAuth consents and API tokens that survive a password reset. Our security awareness training teaches staff to recognize credential harvesting and help desk pretexts and, most important, to report them within minutes.
Honeybadger Solutions is a veteran-owned, SDVOSB firm based in Casa Grande, Arizona, and we deliver cyber and identity work nationwide by remote. Request an MFA rollout online or book a consultation online to walk through a rollout plan with our team.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
What is phishing-resistant MFA?
Phishing-resistant MFA is a sign-in method that cryptographically ties the login to the real website or service, so a fake look-alike page cannot capture anything it can reuse. In practice that means FIDO2/WebAuthn security keys, passkeys or certificate-based smart cards such as PIV.
Are authenticator app codes and push approvals phishing-resistant?
No. NIST SP 800-63B-4 states that one-time password authentication and out-of-band authentication are not phishing-resistant. Codes can be relayed from a fake page in real time, and push prompts can be approved by a tired or tricked user.
Are passkeys phishing-resistant?
Yes. Passkeys use the same FIDO standards as hardware security keys and are bound to the website they were created for. Under NIST SP 800-63B-4, synced passkeys are allowed at AAL2 but not at AAL3, because the private key can be copied between devices.
Do private businesses have to use phishing-resistant MFA?
OMB M-22-09 applies to federal agencies and covers the staff, contractors and partners who sign in to agency-hosted accounts. NIST guidance is voluntary for most private companies unless a contract or regulator adopts it. This is general information, not legal advice, so confirm your specific obligations with counsel or your assessor.
What happens if an employee loses a security key?
With a sound rollout, very little. Each person enrolls at least two authenticators, so they sign in with the backup while IT revokes the lost key and issues a replacement. The help desk must verify identity carefully before registering any new authenticator.
Should we still turn on number matching if we are moving to passkeys?
Yes. Rollouts take time, and some users will stay on push approvals longer than others. CISA describes number matching as one of the best interim mitigations against push bombing, and NIST SP 800-63B-4 no longer accepts simple approve-or-deny prompts where the user does not transfer a secret.
Sources and further reading
- CISA: Implementing Phishing-Resistant MFA (fact sheet, October 2022) — FIDO/WebAuthn and PKI as phishing-resistant, threat list, MFA hierarchy and prioritization.
- CISA: Implementing Number Matching in MFA Applications (fact sheet, October 2022) — Push bombing and number matching as an interim mitigation.
- CISA: More than a Password (MFA resources) — CISA’s position on phishing-resistant authentication and FIDO.
- NIST SP 800-63B-4 publication record (final, July 2025) — Final date and supersession of Revision 3.
- NIST SP 800-63B-4: Authentication and Authenticator Management — Phishing resistance definition, AAL2/AAL3 rules, syncable authenticators, PSTN and push requirements.
- OMB M-22-09: Moving the U.S. Government Toward Zero Trust (January 2022) — Federal requirement for phishing-resistant sign-in, PIV and WebAuthn.
- Microsoft Security: From cookie theft to BEC (July 2022) — How AiTM kits steal session cookies and lead to payment fraud.
- CISA and FBI: Scattered Spider advisory AA23-320A (updated July 2025) — MFA fatigue, SIM swap and help desk impersonation tactics.
- FBI IC3: Criminals Increasing SIM Swap Schemes (February 2022) — SIM swap complaint counts and losses.
- Microsoft Learn: Manage emergency access accounts in Microsoft Entra ID — Break-glass account design, monitoring and 90-day testing.
- Microsoft Learn: Conditional Access authentication strengths — Methods in Microsoft’s built-in phishing-resistant strength.
- Microsoft Learn: Token Protection in Conditional Access — Device-bound session tokens and current scope limits.
- FIDO Alliance: Passkeys — How passkeys resist phishing; synced vs device-bound passkeys.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services · Private investigations · Cybersecurity · Digital forensics · Financial fraud investigation · Executive protection · All articles