Phishing-Resistant MFA
Phishing-resistant MFA is multi-factor authentication that cannot be captured or relayed by a fake login page — in practice, FIDO2 security keys and passkeys bound cryptographically to the legitimate domain.
Phishing-resistant MFA is multi-factor authentication designed so that there is nothing a phishing site can steal or replay. Codes, push approvals and SMS all produce a secret or a decision the user can be tricked into handing over; phishing-resistant methods — FIDO2 security keys and passkeys — replace that with a cryptographic exchange bound to the real website's domain, so a fake login page simply cannot complete it.
How it works
With FIDO2/WebAuthn, the user's device holds a private key and the service holds the matching public key. At login, the browser signs a challenge that includes the site's origin. A proxy site on a lookalike domain receives a signature that is invalid for the real service, and there is no code to read, type, or approve — the human is no longer carrying a secret between two screens.
Contrast that with the methods attackers have learned to beat. Adversary-in-the-middle kits relay a victim's password and one-time code to the real site in real time and steal the authenticated session cookie. MFA fatigue bombards a user with push prompts until one is approved. SIM swapping intercepts SMS codes. Each of these defeats possession-based MFA by exploiting the human step; none of them works against an origin-bound credential. Agencies including CISA and NIST now explicitly distinguish phishing-resistant methods from the rest, and recommend them for high-risk accounts first.
How to defend
- Prioritize by blast radius. Move administrators, executives, finance and help-desk staff to FIDO2 keys or passkeys first — the accounts attackers target with MFA bypass techniques.
- Close the fallback hole. A phishing-resistant front door means little if account recovery still accepts an SMS code or a help-desk password reset; attackers go where the weak factor remains. Our MFA fatigue guide and enterprise passkey migration guide cover the rollout sequence.
- Pair the control with training. Users should understand why the prompt disappeared — and that any login flow asking them to read a code to a caller is an attack, not a recovery process.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo