Direct naar inhoud
Back to Insights
Security

Phishing-resistant MFA: which two-step verification is still safe?

29 September 2026Robin DamenRobin Damen

Robin Damen โ€” managing director of Virtual Computing, 20+ years of MSP experience

Phishingbestendige MFA: de ladder van sms-code en pushmelding tot passkey en YubiKey

For years MFA (multi-factor authentication), also known as two-step verification or two-factor authentication, was the answer to stolen passwords: on top of your password you need a second proof, such as a code on your phone. That still makes sense, because any form of MFA is better than none. But attackers now get past SMS codes, app codes and push notifications with fake sign-in pages. One kind of MFA does stop this trick: phishing-resistant MFA. Below you can read which kinds of MFA exist, which ones are still good enough, where our own MFA options stand and what to do now. For the basics, read cybersecurity for SMEs.

Microsoft is ending its own SMS and voice codes in Microsoft Entra ID, the account system behind Microsoft 365. Since 1 September 2026 passkeys are the default. From 1 February 2027 Microsoft no longer sends SMS and voice codes, and from 1 July 2027 that also applies to Global Administrators and users from outside your organisation. Anyone who only has SMS or voice by then must create a passkey at sign-in first, unless the organisation connects an external SMS service itself. See Microsoft's announcement.

How attackers get around MFA

A fake sign-in page that relays everything

The most common trick is called adversary-in-the-middle, or AiTM: an attacker who sits between you and the real website. You click a link and see a sign-in page that looks exactly like Microsoft 365. That is no accident: the fake site forwards everything to the real one and shows you what comes back. According to Microsoft, the web address is the only visible difference. You type your password and your code, or approve the push notification. The attacker passes it straight on and captures the proof that you are signed in, the session cookie. With that the attacker is in your mailbox and can, for example, reply to an ongoing invoice thread with a "new" bank account number. Microsoft saw this happen within five minutes of the break-in in some cases.

It happens at scale. The best-known ready-made phishing kit, Tycoon2FA, could be rented from 120 dollars for ten days and, according to Microsoft, bypassed nearly all commonly deployed MFA methods, including SMS codes, one-time passcodes and push notifications. By mid-2025 that single kit accounted for about 62% of all phishing attempts Microsoft blocked (Microsoft, March 2026).

Prompt after prompt until you give in

If an attacker already has your password, for instance from a data breach, they can simply keep trying to sign in. You get prompt after prompt until you tap Approve by accident or out of irritation. This is called MFA fatigue or push bombing. The Dutch National Cyber Security Centre (NCSC) describes a software company in Haarlem where sign-ins were confirmed by an automated phone call and a single key press. After eight attempts the user pressed the hash key, assuming the laptop needed it. Customers with open invoices then received a "new" bank account number.

Intercepted texts and SIM swapping

An SMS is not encrypted and can be intercepted, the NCSC warns. In a SIM swap, an attacker talks your mobile provider into moving your number to a SIM card the attacker controls. From that moment on, your codes go to the attacker.

The MFA ladder: which kinds of MFA exist

Put the kinds of MFA in order from weak to strong and you get a ladder with five steps. For each step you can see whether it stops push bombing and whether it stops a fake sign-in page.

StepMethodHow it worksStops push bombingStops a fake sign-in page
1SMS code or voice callA code by text message that you type in, or a call where you press a keySMS yes, voice call noNo, and SMS can also be intercepted
2Push notificationYou tap Approve in an app on your phoneNoNo
3Code from an app or key fob (OTP: one-time password)An app or key fob keeps generating a new six-digit code that you type inYesNo
4Push with number matchingYou type the number shown on the sign-in screen into the appYesNo
5Passkey, security key, Windows Hello for Business or certificateYour device creates a digital signature, only for the real web address, after your PIN, fingerprint or faceYesYes

Windows Hello for Business means signing in to your work Windows laptop with a PIN, fingerprint or face; the key is locked inside that laptop. A certificate is a digital proof of identity, for example on a smart card. The top step is called phishing-resistant MFA, and the US cybersecurity agency CISA calls it the gold standard.

Why codes and push notifications are no longer enough

You type a code yourself, so you will type it on a fake site too. The US standards body NIST therefore states that a method where you manually copy something over is never phishing-resistant. You approve a push notification on your phone, but your phone cannot see that you are on a fake page. Number matching does not change that: the fake site simply shows you the real number. So number matching protects against push bombing, not against a fake sign-in page.

Why the top step does work

With a passkey, a security key or Windows Hello for Business there is nothing to type over. When you register, your device creates a key pair that is bound to the real web address of the service. The private half is never sent to the website. It stays on your device or, for a passkey that syncs across your devices, encrypted in your password manager. When you sign in, your device signs a random challenge from the service, after you have used your PIN, fingerprint or face. On a fake site your device sees that the address is wrong and refuses. As the NCSC puts it, a passkey knows which key belongs to which account and therefore fills in nothing on a fake website. Think of a key that only turns in the lock of your own front door. So it does not depend on how alert you are: even if you land on a fake site, your device hands it nothing.

Even phishing-resistant MFA does not cover everything. In device code phishing, an abuse of the sign-in method for devices without a keyboard, you enter a code on the real Microsoft page and, without knowing it, approve the attacker's session. A kit that works this way has compromised more than 12,000 mailboxes since February 2026. Microsoft advises blocking this sign-in route with Conditional Access, the access rules in Microsoft Entra ID. And if you leave SMS open next to a passkey, an attacker will simply take that weaker route.

Hardware security keys explained: the YubiKey

A security key is a passkey on a separate piece of hardware. The best known is the YubiKey from Yubico. You plug it into a USB port or hold it against your phone (NFC, short-range wireless contact), touch it and enter the key's PIN. The secret key is created on the YubiKey and cannot be copied. CISA calls hardware keys the most effective option, with passkeys as an acceptable alternative. One thing to note: a YubiKey 5 can also generate codes, but it is only phishing-resistant when used as a passkey (FIDO2, the open standard behind passkeys) or as a smart card.

A key is especially useful for:

  • Administrators, the most attractive target. Microsoft recommends security keys for users with elevated privileges.
  • Finance staff and management, the target of invoice fraud.
  • People without a company phone or managed laptop. According to the NCSC, that is exactly when a hardware key is useful.
  • Shared workstations, such as a reception desk. Windows Hello for Business is tied to one PC, a key goes with you.

Always register a spare key. Because a passkey cannot be copied, you register the spare separately with every service. If you lose a key, sign in with the spare and remove the lost key at the service. In Microsoft Entra ID an administrator can also issue a Temporary Access Pass, a temporary access code to register a new key. Whoever finds your key cannot use it without your PIN. At Yubico the simplest key, from the Security Key series that only does passkeys, costs from around โ‚ฌ35 including VAT. A YubiKey 5, which also works as a smart card, costs from around โ‚ฌ70 including VAT (checked on 29 September 2026). Passkeys need no extra licence in Microsoft Entra ID; enforcing them with Conditional Access requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium.

What the official advice says

The Dutch NCSC is clear: choose passkeys wherever you can, and use regular MFA where passkeys do not work yet. The NCSC strongly advises against SMS. CISA calls app codes and push with number matching the best interim option for SMEs that cannot move to phishing-resistant MFA straight away. And Microsoft writes that traditional MFA is no longer enough. For a small business, that comes down to this:

  • Everyone: MFA on every account, without SMS. At least an app code or push with number matching.
  • Administrators, management, finance and HR: first in line for phishing-resistant MFA. CISA and Microsoft both start with administrators.
  • Then everyone else: step by step to passkeys, starting with the account everyone signs in with, usually Microsoft 365. Once everyone has moved, switch off the old methods.

Where our MFA options sit on the ladder

By default we handle MFA through Microsoft Entra. We also use privacyIDEA and, as an option, Duo. For each one you can see which step it is on, even when that is not the top.

Microsoft Entra ID: from number matching to phishing-resistant

The online workspace we have been delivering since 1 September 2026 opens with your Microsoft 365 account and MFA through Microsoft Entra. Microsoft Authenticator always uses number matching for push notifications: step 4. Microsoft Entra ID can also do the top step, with passkeys in Microsoft Authenticator, security keys such as the YubiKey, Windows Hello for Business and certificates. With Conditional Access you enforce that an account only gets in that way. Passwordless sign-in to the workspace itself, with a passkey or Windows Hello for Business, builds on single sign-on: you sign in once and Outlook, Word and Teams recognise you. That is why we always set up single sign-on first and passwordless after that. Also read how signing in once with your Microsoft 365 account works.

privacyIDEA: included free of charge, steps 2 and 3

For the Windows sign-in to the Online Workspace we use privacyIDEA: open source two-step verification software that we run ourselves on our own platform in the Netherlands. You link the privacyIDEA Authenticator app to your account through an email invitation and confirm your sign-in with a push notification in the app or with a time-based code. After repeated failed attempts your sign-in is temporarily blocked. privacyIDEA is included free of charge with the Online Workspace.

Push and codes sit on steps 2 and 3: much stronger than a password alone, but not phishing-resistant. With a push notification where you only tap Approve, it is up to you to spot a strange prompt. If you get a prompt you did not expect, deny it and let us know. The large phishing kits target web sign-ins such as Microsoft 365, but according to CISA and NIST a code or approval can in principle be relayed anywhere.

Duo (Cisco Duo): optional, for several systems at once

With Duo (Cisco Duo) you protect the Windows sign-in, Microsoft 365 and other business applications in one go. Duo can work with a push notification where you type a verification code from the sign-in screen into the app (Verified Duo Push): step 4. If you sign in through the browser, Duo can also work with a security key or Windows Hello, the top step. For the Windows sign-in, step 4 remains the highest. Duo is optional; ask us about it in a consultation.

What to do now

  1. Have administrators move first to a passkey or security key, and have it set up so that this is the only way they can still get in. Microsoft provides a ready-made template for this. Test it first and keep a separate emergency access account outside the rule, so you do not lock yourself out.
  2. Have SMS and voice switched off, including as a fallback. According to CISA, adding an app does not remove SMS until someone switches it off, and that is the route an attacker will take.
  3. Where possible, only allow push notifications with number matching and agree with your staff: a prompt you did not expect, you deny and report. According to CISA, such a prompt can mean your password has already leaked.
  4. List who needs a key, count on two per person and agree what happens when one is lost.
  5. Have it checked. In our free Microsoft 365 security check we look at MFA, Conditional Access, admin accounts and legacy sign-in protocols.

How we help

We set up MFA and Conditional Access for SMEs, as part of cybersecurity and Microsoft 365 management. Which step suits which employee, and how to get there without locking anyone out, is something we discuss in a consultation. Virtual Computing is ISO 27001 and ISO 9001 certified. You can also call us on 085 013 4500.

Frequently asked questions

Written by

Questions about this topic?

Contact our team for personal advice.

    Phishing-resistant MFA: from SMS code to YubiKey