You've got MFA switched on — good. But not all MFA is equally strong. The codes and "approve this sign-in" prompts most of us use every day can still be tricked by a convincing fake login page. "Phishing-resistant" MFA is the newer kind that can't. Here's the difference, in plain English.
Ordinary MFA (SMS codes, authenticator codes, "approve this sign-in" prompts) can still be phished — a fake page just asks you for the code too. Phishing-resistant MFA (passkeys, security keys, Windows Hello) is tied to the real website and your device, so it simply won't work on a fake site. Moving your important logins to it is one of the biggest security upgrades you can make.
The everyday kinds of MFA all share one soft underbelly:
Anything you can read out or type in, an attacker can also ask you for. A convincing fake login page — or a phone call from someone pretending to be "IT support" — simply asks for the code after your password, and you hand it straight over without realising. The code was genuine; it just went to the wrong place.
There's a related trick called "MFA fatigue": the attacker already has your password and spams those "approve this sign-in" prompts to your phone, over and over, hoping a tired or busy person eventually taps "yes" just to make them stop. And with a fake login page, the attacker can even capture the login session itself — so they stay signed in without needing your password or codes again. (We explain that one in our token theft article.)
Phishing-resistant MFA closes that gap with two clever tricks working together:
You've probably already used at least one of these without thinking of it as "phishing-resistant MFA":
Not sure how strong your current MFA really is, or where to start? Our free IT Health Check reviews the MFA across your accounts, flags the logins most worth protecting first, and maps out a smooth, gradual move to phishing-resistant methods like passkeys and security keys — no jargon, no disruption.