Not all multi-factor authentication is created equal. The MFA that stopped attackers in 2020 is the same MFA they now defeat routinely, because SMS codes and “approve this sign-in” prompts can be phished, intercepted, or simply fatigued out of a tired user at 4pm. Phishing-resistant MFA closes that gap, and for most Australian SMEs it is now within reach at no extra licence cost.
This is core to the identity work we do. If you want it planned and rolled out against your tenant, talk to us about cybersecurity and identity.
What “phishing-resistant” actually means
A phishing-resistant method binds your login to the real website, cryptographically, so a fake sign-in page cannot relay it. Two methods qualify for most organisations:
- Passkeys (FIDO2/WebAuthn): a private key stored on your phone, laptop, or a hardware key, unlocked by your fingerprint, face, or PIN. The key only works on the genuine domain.
- Certificate-based authentication: useful in specific managed-device scenarios, though heavier to run.
What does not qualify: SMS one-time codes, email codes, and standard push notifications you tap to approve. These all rely on a human relaying a secret, which is exactly what modern phishing kits automate.
Why the old methods fail now
Attackers buy off-the-shelf “adversary-in-the-middle” kits that sit between the user and the real Microsoft login, capturing both the password and the one-time code, then replaying the session token. Number matching in Microsoft Authenticator helped, but determined attackers still socially engineer their way through. The honest summary: any method where a person can be tricked into handing over or approving a code is a method that will eventually be defeated.
Rolling out passkeys in Microsoft 365
You do not need to boil the ocean. A staged rollout in Entra ID works well.
1. Turn on the foundations
- Enable passkey (FIDO2) as an authentication method in the Entra admin centre.
- Allow device-bound passkeys in Microsoft Authenticator, so most staff can enrol with the phone already in their pocket.
- Keep a small stock of hardware security keys for admins and shared or kiosk scenarios.
2. Start with the accounts that matter
- Register passkeys for every administrator first, then finance, executives, and anyone handling sensitive data.
- Move standing admin into Privileged Identity Management at the same time, so a stolen session is worth less.
3. Make it the expected path, then the only path
- Use Conditional Access authentication strengths to require phishing-resistant methods for admin roles and sensitive apps.
- Communicate a date after which weaker methods stop working for those groups, and expand outward from there.
4. Plan for the edge cases
- Have a documented recovery process (a Temporary Access Pass) for lost or replaced devices, so “I cannot get in” does not become “reset it to SMS”.
- Decide the policy for personal versus corporate devices before you flip the switch.
The registration trap
The weakest link is often not the sign-in, it is enrolment. If an attacker can register their own MFA method on a fresh or compromised account, everything downstream is theirs. Protect the registration flow with Conditional Access, require a Temporary Access Pass for new starters, and review recently registered methods as a routine security check.
What to do this quarter
- Enable passkeys in Entra ID and register them for every administrator, backed by Privileged Identity Management.
- Require phishing-resistant authentication strength for admin roles and your most sensitive applications via Conditional Access.
- Write the recovery and enrolment policy, including the Temporary Access Pass, so nobody falls back to SMS.
Phishing-resistant MFA is the highest-value security change most Australian SMEs can make this year, and it pairs directly with the Essential Eight and a solid Microsoft 365 baseline. If you would like help planning the rollout, book a consultation.