All Guides
Identity Security

Multi-Factor Authentication: a practical guide for Australian business

Passwords alone no longer hold the line. Microsoft blocked roughly 7,000 password attacks per second across Entra ID over the past year, and phishing-resistant MFA stops more than 99 per cent of identity-based attacks even when the attacker already holds valid credentials. This guide ranks every MFA type, explains which are phishing-resistant, and shows how to roll it out and what still needs defending.

Last updated 4 October 202611 min read

Why MFA Matters

Microsoft Entra ID blocked an average of 7,000 password attacks per second over the past year, and 97 per cent of identity attacks took the form of password spray, where an attacker tests common passwords against thousands of accounts in parallel. Microsoft Digital Defense Report 2025.

Identity-based attacks rose 32 per cent in the first half of 2025 compared with the same period in 2024, according to the Microsoft Digital Defense Report 2025. Phishing, password reuse and credential stuffing give attackers ready-to-use logins every day. Microsoft Digital Defense Report 2025.

Phishing-resistant MFA stops more than 99 per cent of identity-based attacks even when the attacker already possesses the correct username and password. The second factor breaks the password-spray math: even if the attacker guesses right, the login still fails. Microsoft Digital Defense Report 2025.

Credential theft is the single most common entry point for a breach. Phishing, password reuse, credential stuffing, and data leaks give attackers ready-to-use logins every day. MFA is the one control that makes a stolen password almost useless on its own.

New to passkeys? They are the phishing-resistant replacement for passwords and the next step beyond MFA. See our plain-English passkey guide.

7,000

password attacks per second blocked by Microsoft Entra ID (Microsoft 2026)

99.9%

of automated account attacks blocked by MFA (Microsoft)

48%

of all breaches now involve ransomware (Verizon 2026 DBIR)

How MFA Works

MFA requires two or more independent factors: something you know, something you have, or something you are. The strength comes from independence. A password plus a code sent to the same compromised inbox is not real MFA, because both factors fall together. Microsoft phishing-resistant deployment.

MFA requires two or more of these three factors:

Something you know

Password, PIN, passphrase

Weak alone. Can be guessed, phished, or leaked.

Something you have

Phone, hardware key, smart card

Physical possession. Hard to steal remotely.

Something you are

Fingerprint, Face ID, iris

Biometric. Strong but requires device support.

MFA Types: Weakest to Strongest

Microsoft is retiring SMS and voice MFA from Entra ID completely on 1 February 2027, and auto-enabling passkeys for SMS and voice users from 1 September 2026. SMS is not just weak, it is being removed as an option for new Entra deployments. Microsoft Entra passkey guidance.

Okta workforce data shows phishing-resistant authenticator adoption grew 63 per cent year on year, from 8.6 per cent of users to 14.0 per cent. Over the same window low-assurance SMS slipped from 17.5 per cent to 15.3 per cent and overall password usage edged down from 95.1 per cent to 93.0 per cent. Okta Secure Sign-In Trends 2025.

1

SMS / Text Code

Weak

A 6-digit code sent via SMS. Vulnerable to SIM swap, SS7 interception, and real-time phishing.

ACSC: Not recommended for business use.

2

Email Code

Weak

Code sent to a secondary email. Only as secure as that inbox. If mail is compromised, MFA falls with it.

ACSC: Avoid for any privileged account.

3

Authenticator App (TOTP)

Good

Time-based codes from Microsoft Authenticator, Google Authenticator, or Authy. No SIM dependency. Still vulnerable to adversary-in-the-middle phishing.

ACSC: Minimum acceptable for standard accounts.

4

Push with Number Matching

Good

Push notification that requires typing a number shown on the login screen. Blocks simple MFA fatigue attacks.

ACSC: Enable number matching everywhere.

5

FIDO2 / Passkeys / Hardware Keys

Strongest

Cryptographically bound to the domain. Phishing is technically impossible. Works with YubiKey, Windows Hello for Business, Face ID, and synced passkeys.

ACSC: Required for privileged accounts at Maturity Level 3.

SMS is not just weak, it is being retired: Microsoft Entra ID auto-enables passkeys for SMS and voice users from 1 September 2026, and Microsoft-provided SMS and voice MFA retire completely on 1 February 2027. See our Entra passkey transition guide for the full timeline.

Phishing-Resistant MFA (The Only Kind That Really Works)

Passkeys are built on FIDO standards and use origin-bound public key cryptography, so a credential created for one site cannot be replayed on another. Microsoft reports 99 per cent of users successfully register synced passkeys, and they are roughly 14 times faster than a password plus traditional MFA (about 3 seconds instead of 69 seconds). Microsoft Entra passkey guidance.

Adversary-in-the-middle toolkits like Evilginx proxy the real login page, capture credentials, capture MFA codes and steal the session cookie in real time. Codes and push prompts do not stop this. Only cryptographically bound MFA, where the credential is tied to the origin, defeats the proxy. Microsoft phishing-resistant deployment.

Attackers have caught up. Adversary-in-the-middle toolkits like Evilginx proxy the real login page, capture credentials, capture MFA codes, and steal the session cookie in real time. Codes and push prompts do not stop this. Only cryptographically bound MFA does.

FIDO2 Hardware Keys

YubiKey, Feitian, Token2. USB-A, USB-C, or NFC. Tie them to a user in Entra ID. Pair with a backup key kept in a safe.

Passkeys and Platform Authenticators

Windows Hello for Business, Face ID on iPhone, Android platform authenticator. Synced passkeys work across devices. Phishing-resistant by design.

Implementation Plan

The FIDO Alliance State of Passkeys 2026 report records 5 billion active passkeys worldwide, 75 per cent consumer recognition and 68 per cent of surveyed organisations either deployed or actively deploying passkeys for employee sign-in. The technology is now mainstream enough to plan around, not pilot. FIDO Alliance State of Passkeys 2026.

1

Start with Microsoft 365 and identity platform

Enable MFA in Entra ID via Conditional Access. Protects email, Teams, SharePoint, and every federated SaaS app in one place.

2

Cover every cloud service

Xero, HubSpot, Salesforce, AWS, Google Admin, GitHub, your password manager, your RMM. If it has a login, it gets MFA.

3

Enforce MFA on remote access

VPN, RDP, remote desktop gateways, and Bastion. This is an Essential Eight requirement and cyber insurance baseline.

4

Protect privileged accounts with FIDO2

Global admins, domain admins, executives, and finance should use hardware keys or Windows Hello for Business. Phishing-resistant only.

5

Enable number matching and context

Microsoft Authenticator shows the app, location, and a number to match. Blocks prompt bombing.

6

Train staff on safe behaviour

Never approve a prompt you did not start. Report suspicious prompts. Never read codes aloud on the phone.

7

Review break-glass accounts

Keep two emergency accounts excluded from MFA policies, stored in a physical safe. Review access quarterly.

MFA Bypass Attacks to Know

IBM reports breaches initiated through stolen or compromised credentials cost an average of USD 4.67 million and take a mean of 246 days to identify and contain, more than eight months of attacker dwell time. MFA on every privileged and external-facing account closes the entry vector that gives attackers the longest runway. IBM Cost of a Data Breach 2025.

MFA Fatigue / Prompt Bombing

Attacker spams push prompts until the user taps Approve. Fix: enable number matching.

Adversary-in-the-Middle (AiTM)

Proxy captures credentials, codes, and session cookies in real time. Fix: FIDO2 keys or passkeys.

SIM Swap

Attacker ports the phone number and intercepts SMS. Fix: never use SMS MFA.

Session / Token Theft

Malware on the endpoint steals refresh tokens. Fix: Conditional Access, token protection, compliant devices only.

Help Desk Social Engineering

Attacker calls IT and resets MFA. Fix: identity verification scripts, caller-ID proofing, ticket required.

Downgrade Attacks

User is forced back to a weaker method. Fix: block legacy authentication, enforce phishing-resistant methods for admins.

Common Mistakes

MFA fatigue or prompt bombing is mitigated by number matching, which requires the user to type a number shown on the login screen into the authenticator app. Microsoft has made number matching the default for Microsoft Authenticator push, and it should be enforced everywhere the option exists. Microsoft phishing-resistant deployment.

SMS MFA on admin accounts

SIM swap gives an attacker full admin access. Use hardware keys.

No break-glass accounts

If MFA breaks for your tenant, you get locked out. Keep two break-glass accounts excluded and stored safely.

Legacy authentication still enabled

Basic auth bypasses MFA entirely. Block it in Conditional Access.

Mixing personal and work MFA on one phone

Lose the phone, lose both. Separate work authenticator or hardware keys for privileged users.

No session controls

MFA protects the login. Conditional Access sign-in frequency and token protection protect the session.

Related: Passwordless Authentication, Microsoft 365 Security Baseline, Essential Eight.

Common questions

What is the best type of MFA for business?
Phishing-resistant MFA such as FIDO2 hardware keys or passkeys is the best type for business. The ACSC requires it for privileged accounts at Maturity Level 3. Authenticator apps with number matching are the minimum acceptable for standard accounts.
Is SMS MFA safe for business accounts?
No. SMS MFA is vulnerable to SIM swap and SS7 interception and is not suitable for business use. Microsoft is retiring SMS and voice MFA from Entra ID completely on 1 February 2027. Move to passkeys or hardware keys before then.
Does MFA stop all phishing attacks?
MFA blocks 99.9 per cent of automated credential attacks (Microsoft) but does not stop adversary-in-the-middle attacks that proxy the real login page and steal session cookies. Only phishing-resistant MFA such as FIDO2 keys or passkeys blocks those.
How many MFA methods should we enforce?
Enforce phishing-resistant MFA for all privileged accounts and at least authenticator app push with number matching for standard accounts. Keep two break-glass accounts excluded from MFA policies, stored in a physical safe with hardware keys.
What is number matching in Microsoft Authenticator?
Number matching requires the user to type a number shown on the login screen into the authenticator app. It blocks MFA fatigue attacks where an attacker spams push prompts hoping the user taps approve without checking.
Is MFA required for Essential Eight compliance?
Yes. The Essential Eight Maturity Model requires MFA for all users before they access important data, systems, or applications, and for all remote access sessions. At Maturity Level 2 and 3, the ACSC expects phishing-resistant MFA for privileged accounts.

Roll Out MFA Properly

We deploy phishing-resistant MFA across Microsoft 365, Google Workspace, VPN, and SaaS apps, including Conditional Access and hardware keys for privileged accounts.