RESOURCES · SECURITY & EMAIL

What is
phishing-resistant MFA?

You've got MFA switched on — good. But not all MFA is equally strong. The codes and "approve this sign-in" prompts most of us use every day can still be tricked by a convincing fake login page. "Phishing-resistant" MFA is the newer kind that can't. Here's the difference, in plain English.

Applies to: All accounts Read: ~4 min Level: Non-technical
Quick answer

Ordinary MFA (SMS codes, authenticator codes, "approve this sign-in" prompts) can still be phished — a fake page just asks you for the code too. Phishing-resistant MFA (passkeys, security keys, Windows Hello) is tied to the real website and your device, so it simply won't work on a fake site. Moving your important logins to it is one of the biggest security upgrades you can make.

WHY ORDINARY MFA CAN STILL BE FOOLED

The weak spot in everyday MFA.

The everyday kinds of MFA all share one soft underbelly:

Anything you can read out or type in, an attacker can also ask you for. A convincing fake login page — or a phone call from someone pretending to be "IT support" — simply asks for the code after your password, and you hand it straight over without realising. The code was genuine; it just went to the wrong place.

There's a related trick called "MFA fatigue": the attacker already has your password and spams those "approve this sign-in" prompts to your phone, over and over, hoping a tired or busy person eventually taps "yes" just to make them stop. And with a fake login page, the attacker can even capture the login session itself — so they stay signed in without needing your password or codes again. (We explain that one in our token theft article.)

WHAT MAKES IT PHISHING-RESISTANT

Two simple ideas.

Phishing-resistant MFA closes that gap with two clever tricks working together:

THE EVERYDAY FORMS

What it actually looks like.

You've probably already used at least one of these without thinking of it as "phishing-resistant MFA":

The nice surprise: it's usually easier. People expect stronger security to mean more hassle, but this is the opposite. A fingerprint or a tap is faster than digging your phone out, opening an app and copying a six-digit code before it expires — there's simply nothing to fish out of a text message.
HOW TO MOVE TO IT

Rolling it out without the pain.

  1. Start with your highest-risk accountsEmail, administrator and finance logins are the ones attackers want most, so they're where phishing-resistant MFA pays off first.
  2. Roll it out graduallyBring people across in small groups rather than all at once, so no one is disrupted and any hiccups are easy to sort out.
  3. Keep a backup method registeredAlways leave a second, trusted way to sign in — like a backup security key — so people don't get locked out if a device is lost or broken.
  4. Get help planning itA good IT partner sequences the whole thing so it's smooth, sets sensible defaults, and looks after the people who need a hand.
STRONGER LOGINS, LESS RISK

Ready to make your logins phishing-proof?

Not sure how strong your current MFA really is, or where to start? Our free IT Health Check reviews the MFA across your accounts, flags the logins most worth protecting first, and maps out a smooth, gradual move to phishing-resistant methods like passkeys and security keys — no jargon, no disruption.

KEEP READING

Related resources