🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
Phishing-resistant MFA: why passkeys and FIDO2 beat the MFA you have
Defense & Hardening

Phishing-resistant MFA: why passkeys and FIDO2 beat the MFA you have

ERD Research TeamJul 8, 20267 min read

Key takeaways

  • Push-notification and one-time-code MFA are routinely defeated by fatigue prompts and adversary-in-the-middle phishing kits.
  • FIDO2 security keys and passkeys are phishing-resistant because the credential is cryptographically bound to the real domain and can't be relayed.
  • You don't have to boil the ocean — start with admins, remote access, and email, which is where the leverage is.

The MFA you have was built for a different attack

Most organizations turned on MFA and considered the problem solved. But the common forms — a push approval on your phone, a six-digit code from an app or SMS — were designed to stop credential stuffing and password reuse, not the phishing that dominates today. Attackers have adapted: push-notification fatigue (spamming approvals until someone taps 'yes'), real-time phishing proxies that relay codes as you type them, and SIM-swap attacks against SMS all bypass this generation of MFA routinely.

Why phishing-resistant is a different category

FIDO2 security keys and passkeys close these gaps by design. The credential is a private key that never leaves the device and is cryptographically bound to the specific website domain it was registered for. An adversary-in-the-middle proxy sitting on a look-alike domain simply can't complete the handshake — there's no code to phish and no approval to fatigue, because the browser refuses to release the credential to the wrong origin. That's the difference between 'harder to phish' and 'phishing-resistant.'

Where to start without a two-year project

You don't need to migrate every account on day one. Prioritize by leverage: administrative and privileged accounts first, then remote access (VPN, VDI, and the identity provider itself), then email. These are the accounts an attacker most wants and the ones an initial access broker most wants to sell. Rolling out hardware keys or platform passkeys to that population removes the highest-value phishing targets while you plan the broader migration.

Close the bypass doors too

Strong MFA on the front door means nothing if a side door skips it. Disable legacy authentication protocols that don't support MFA, remove SMS and voice as fallback factors for privileged accounts, and audit the account-recovery flow — attackers increasingly target the help desk and self-service reset, because social-engineering a password reset is easier than defeating a security key. Phishing-resistant auth is only as strong as the weakest way to get around it.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy