Multi-factor authentication was meant to solve the password problem, and it still does a good job against attacks that rely on stolen or guessed passwords alone. But attackers have adapted. Account takeovers that lead to invoice fraud, data theft and ransomware often start with a user who had MFA switched on and did nothing obviously wrong.
The answer is not to abandon MFA but to move to methods that cannot be phished, and to surround them with sensible access policies. This article explains how ordinary MFA is bypassed, what phishing-resistant sign-in means in practice and how to roll it out without disrupting the business.
How attackers get past MFA
Three techniques come up again and again.
- MFA fatigue (push bombing): The attacker already has the password and triggers sign-in prompts repeatedly, often late at night, until the user approves one just to make them stop. Number matching, where the user has to enter a number shown on the sign-in screen, makes this much harder, but it does not stop every form of social engineering.
- Adversary-in-the-middle phishing: The user is lured to a convincing fake sign-in page that sits between them and the real service. They enter their password and complete MFA as normal, while the proxy captures the session cookie the real service issues. The attacker then replays that cookie and is signed in, with no need for the password or a second factor. Ready-made phishing kits make this cheap to run at scale.
- Service desk and enrolment tricks: Attackers call the service desk posing as an employee who has lost their phone, or persuade users to ‘register’ a new sign-in method on a fake page. Once the attacker’s own device is registered, their access looks legitimate.
Codes sent by SMS or voice call add a further weakness, because phone numbers can be hijacked through SIM swapping.
What makes sign-in phishing-resistant
Phishing-resistant methods are designed so that the credential only works with the genuine service. The most widely available are based on the FIDO2 and WebAuthn standards: hardware security keys, passkeys and platform authenticators such as Windows Hello for Business. Certificate-based authentication with smart cards is another option for organisations with the infrastructure to support it.
The key property is that the credential is cryptographically bound to the real website’s address. A fake page on a look-alike domain cannot request it, so there is nothing for the user to approve by mistake and nothing for a proxy to capture. This is why the US Cybersecurity and Infrastructure Security Agency (CISA) describes FIDO-based authentication as the only widely available phishing-resistant option.
Passkeys come in two forms. Device-bound passkeys, held on a security key or in an authenticator app on a specific device, never leave that device. Synced passkeys are stored in a platform’s password manager and follow the user across devices, which is convenient but means their security depends on that account. For most staff either can work. For administrators and other high-risk roles, device-bound credentials are the safer choice.
Conditional access and privileged accounts
A strong method only helps if it is required where it matters, and if weaker alternatives cannot be used to get round it. That is the job of conditional access: policies that decide, at each sign-in, what level of authentication is needed and from which devices access is allowed.
- Require phishing-resistant methods for administrators, remote access and sensitive applications. In Microsoft Entra ID, authentication strengths let you specify exactly which methods satisfy a policy.
- Require managed, compliant devices for access to email, files and business systems, so that a stolen session used from an unknown machine is far less useful.
- Block legacy authentication and any sign-in flows you do not need, such as the device code flow, which attackers misuse.
- Alert on every new registration of a sign-in method, and treat changes to a user’s authentication methods as a sensitive action.
- Tighten service desk procedures for resetting MFA, with identity checks that a caller cannot easily fake.
Privileged accounts deserve particular attention. A compromised administrator account can disable security controls, delete backups and grant access to everything else. Keep admin accounts separate from everyday accounts, so nobody reads email with administrative rights. Use just-in-time elevation, where rights are granted for a limited time and with approval, instead of standing privileges. Keep a small number of emergency access accounts, well protected and monitored, so that a policy mistake cannot lock everyone out.
A phased rollout plan
Moving a whole organisation to phishing-resistant sign-in is a change programme, not a configuration switch. A phased approach reduces risk steadily without overwhelming the service desk.
- Assess: Review current sign-in methods, conditional access policies, privileged accounts and exceptions. Identify applications that cannot yet support modern authentication.
- Protect administrators: Issue security keys or device-bound passkeys to IT staff and anyone with privileged roles, and enforce phishing-resistant authentication for those roles.
- Harden the basics for everyone: Turn on number matching, block legacy authentication, restrict who can register sign-in methods and from where, and tighten service desk procedures while the wider rollout is prepared.
- Extend to high-risk groups: Executives, finance, HR and anyone who handles payments or sensitive data are frequent targets and should come next.
- Roll out broadly, then remove the fallbacks: Move the rest of the organisation group by group, with clear guidance, simple enrolment and a plan for lost devices. Then retire the weaker methods, because an attacker will always pick the weakest option that is still allowed.
Expect practical issues along the way: shared workstations, staff without company phones, frontline workers and older applications. Each has workable solutions, but they need to be planned rather than discovered on rollout day.
How Altechy can help
Our Identity Security Review, part of our Identity & Access Management service, is a fixed-scope, three-week review of your identity platform, authentication, conditional access and privileged accounts. You get a list of the highest-risk gaps, quick wins you can implement straight away and a prioritised roadmap towards phishing-resistant sign-in. To catch the attacks that still get through, our Security Operations (SOC & MDR) specialists can watch for suspicious sign-ins and act on them.
If you would like to discuss where to begin, book a free 60-minute idea session.
