Why MFA Matters
Microsoft Entra ID blocked an average of 7,000 password attacks per second over the past year, and 97 per cent of identity attacks took the form of password spray, where an attacker tests common passwords against thousands of accounts in parallel. Microsoft Digital Defense Report 2025.
Identity-based attacks rose 32 per cent in the first half of 2025 compared with the same period in 2024, according to the Microsoft Digital Defense Report 2025. Phishing, password reuse and credential stuffing give attackers ready-to-use logins every day. Microsoft Digital Defense Report 2025.
Phishing-resistant MFA stops more than 99 per cent of identity-based attacks even when the attacker already possesses the correct username and password. The second factor breaks the password-spray math: even if the attacker guesses right, the login still fails. Microsoft Digital Defense Report 2025.
Credential theft is the single most common entry point for a breach. Phishing, password reuse, credential stuffing, and data leaks give attackers ready-to-use logins every day. MFA is the one control that makes a stolen password almost useless on its own.
New to passkeys? They are the phishing-resistant replacement for passwords and the next step beyond MFA. See our plain-English passkey guide.
7,000
password attacks per second blocked by Microsoft Entra ID (Microsoft 2026)
99.9%
of automated account attacks blocked by MFA (Microsoft)
48%
of all breaches now involve ransomware (Verizon 2026 DBIR)
How MFA Works
MFA requires two or more independent factors: something you know, something you have, or something you are. The strength comes from independence. A password plus a code sent to the same compromised inbox is not real MFA, because both factors fall together. Microsoft phishing-resistant deployment.
MFA requires two or more of these three factors:
Something you know
Password, PIN, passphrase
Weak alone. Can be guessed, phished, or leaked.
Something you have
Phone, hardware key, smart card
Physical possession. Hard to steal remotely.
Something you are
Fingerprint, Face ID, iris
Biometric. Strong but requires device support.
MFA Types: Weakest to Strongest
Microsoft is retiring SMS and voice MFA from Entra ID completely on 1 February 2027, and auto-enabling passkeys for SMS and voice users from 1 September 2026. SMS is not just weak, it is being removed as an option for new Entra deployments. Microsoft Entra passkey guidance.
Okta workforce data shows phishing-resistant authenticator adoption grew 63 per cent year on year, from 8.6 per cent of users to 14.0 per cent. Over the same window low-assurance SMS slipped from 17.5 per cent to 15.3 per cent and overall password usage edged down from 95.1 per cent to 93.0 per cent. Okta Secure Sign-In Trends 2025.
SMS / Text Code
WeakA 6-digit code sent via SMS. Vulnerable to SIM swap, SS7 interception, and real-time phishing.
ACSC: Not recommended for business use.
Email Code
WeakCode sent to a secondary email. Only as secure as that inbox. If mail is compromised, MFA falls with it.
ACSC: Avoid for any privileged account.
Authenticator App (TOTP)
GoodTime-based codes from Microsoft Authenticator, Google Authenticator, or Authy. No SIM dependency. Still vulnerable to adversary-in-the-middle phishing.
ACSC: Minimum acceptable for standard accounts.
Push with Number Matching
GoodPush notification that requires typing a number shown on the login screen. Blocks simple MFA fatigue attacks.
ACSC: Enable number matching everywhere.
FIDO2 / Passkeys / Hardware Keys
StrongestCryptographically bound to the domain. Phishing is technically impossible. Works with YubiKey, Windows Hello for Business, Face ID, and synced passkeys.
ACSC: Required for privileged accounts at Maturity Level 3.
SMS is not just weak, it is being retired: Microsoft Entra ID auto-enables passkeys for SMS and voice users from 1 September 2026, and Microsoft-provided SMS and voice MFA retire completely on 1 February 2027. See our Entra passkey transition guide for the full timeline.
Phishing-Resistant MFA (The Only Kind That Really Works)
Passkeys are built on FIDO standards and use origin-bound public key cryptography, so a credential created for one site cannot be replayed on another. Microsoft reports 99 per cent of users successfully register synced passkeys, and they are roughly 14 times faster than a password plus traditional MFA (about 3 seconds instead of 69 seconds). Microsoft Entra passkey guidance.
Adversary-in-the-middle toolkits like Evilginx proxy the real login page, capture credentials, capture MFA codes and steal the session cookie in real time. Codes and push prompts do not stop this. Only cryptographically bound MFA, where the credential is tied to the origin, defeats the proxy. Microsoft phishing-resistant deployment.
Attackers have caught up. Adversary-in-the-middle toolkits like Evilginx proxy the real login page, capture credentials, capture MFA codes, and steal the session cookie in real time. Codes and push prompts do not stop this. Only cryptographically bound MFA does.
FIDO2 Hardware Keys
YubiKey, Feitian, Token2. USB-A, USB-C, or NFC. Tie them to a user in Entra ID. Pair with a backup key kept in a safe.
Passkeys and Platform Authenticators
Windows Hello for Business, Face ID on iPhone, Android platform authenticator. Synced passkeys work across devices. Phishing-resistant by design.
Implementation Plan
The FIDO Alliance State of Passkeys 2026 report records 5 billion active passkeys worldwide, 75 per cent consumer recognition and 68 per cent of surveyed organisations either deployed or actively deploying passkeys for employee sign-in. The technology is now mainstream enough to plan around, not pilot. FIDO Alliance State of Passkeys 2026.
Start with Microsoft 365 and identity platform
Enable MFA in Entra ID via Conditional Access. Protects email, Teams, SharePoint, and every federated SaaS app in one place.
Cover every cloud service
Xero, HubSpot, Salesforce, AWS, Google Admin, GitHub, your password manager, your RMM. If it has a login, it gets MFA.
Enforce MFA on remote access
VPN, RDP, remote desktop gateways, and Bastion. This is an Essential Eight requirement and cyber insurance baseline.
Protect privileged accounts with FIDO2
Global admins, domain admins, executives, and finance should use hardware keys or Windows Hello for Business. Phishing-resistant only.
Enable number matching and context
Microsoft Authenticator shows the app, location, and a number to match. Blocks prompt bombing.
Train staff on safe behaviour
Never approve a prompt you did not start. Report suspicious prompts. Never read codes aloud on the phone.
Review break-glass accounts
Keep two emergency accounts excluded from MFA policies, stored in a physical safe. Review access quarterly.
MFA Bypass Attacks to Know
IBM reports breaches initiated through stolen or compromised credentials cost an average of USD 4.67 million and take a mean of 246 days to identify and contain, more than eight months of attacker dwell time. MFA on every privileged and external-facing account closes the entry vector that gives attackers the longest runway. IBM Cost of a Data Breach 2025.
MFA Fatigue / Prompt Bombing
Attacker spams push prompts until the user taps Approve. Fix: enable number matching.
Adversary-in-the-Middle (AiTM)
Proxy captures credentials, codes, and session cookies in real time. Fix: FIDO2 keys or passkeys.
SIM Swap
Attacker ports the phone number and intercepts SMS. Fix: never use SMS MFA.
Session / Token Theft
Malware on the endpoint steals refresh tokens. Fix: Conditional Access, token protection, compliant devices only.
Help Desk Social Engineering
Attacker calls IT and resets MFA. Fix: identity verification scripts, caller-ID proofing, ticket required.
Downgrade Attacks
User is forced back to a weaker method. Fix: block legacy authentication, enforce phishing-resistant methods for admins.
Common Mistakes
MFA fatigue or prompt bombing is mitigated by number matching, which requires the user to type a number shown on the login screen into the authenticator app. Microsoft has made number matching the default for Microsoft Authenticator push, and it should be enforced everywhere the option exists. Microsoft phishing-resistant deployment.
SMS MFA on admin accounts
SIM swap gives an attacker full admin access. Use hardware keys.
No break-glass accounts
If MFA breaks for your tenant, you get locked out. Keep two break-glass accounts excluded and stored safely.
Legacy authentication still enabled
Basic auth bypasses MFA entirely. Block it in Conditional Access.
Mixing personal and work MFA on one phone
Lose the phone, lose both. Separate work authenticator or hardware keys for privileged users.
No session controls
MFA protects the login. Conditional Access sign-in frequency and token protection protect the session.
Related: Passwordless Authentication, Microsoft 365 Security Baseline, Essential Eight.
Common questions
What is the best type of MFA for business?
Is SMS MFA safe for business accounts?
Does MFA stop all phishing attacks?
How many MFA methods should we enforce?
What is number matching in Microsoft Authenticator?
Is MFA required for Essential Eight compliance?
Roll Out MFA Properly
We deploy phishing-resistant MFA across Microsoft 365, Google Workspace, VPN, and SaaS apps, including Conditional Access and hardware keys for privileged accounts.

Remote Support