Phishing-Resistant MFA
Multi-factor authentication cryptographically bound to the legitimate website's origin, such as FIDO2 security keys and passkeys, that cannot be phished or relayed the way SMS codes and push approvals can.
Definition
Phishing-resistant MFA refers to multi-factor authentication methods, primarily FIDO2 security keys and passkeys, where the login credential is cryptographically bound to the exact website origin during registration, so it simply cannot produce a valid response on a fake or lookalike domain. This distinguishes it from weaker MFA methods such as SMS one-time codes or push notification approvals, which can be intercepted in real time by an adversary-in-the-middle proxy or approved by a tired user targeted with MFA fatigue.
When a user registers a FIDO2 security key or passkey with a website, the device generates a unique cryptographic key pair and binds it to that site's exact domain. At login, the site sends a cryptographic challenge that only the correct private key, which never leaves the user's device or hardware, can answer, and the user simply confirms with a fingerprint, face scan, or PIN to authorize the response. Because the credential is bound to the real domain, a login attempt on a lookalike phishing page fails outright: the browser checks the origin before offering a response, so there is no code to read aloud, no shared secret to type, and nothing that a fake site can capture or relay to the real one.
This matters because attackers have adapted specifically to defeat weaker MFA: real-time adversary-in-the-middle phishing kits proxy a live login session and capture both the password and a one-time code the instant it is entered, while MFA fatigue attacks simply spam push approval requests until an exhausted user taps accept. Neither technique works against phishing-resistant MFA, since there is no code to relay and no push prompt to approve out of habit, only a cryptographic exchange the fake site cannot participate in. For regulated organizations in Indonesia, privileged accounts, administrators, executives, and finance staff who approve payments, are the highest-value targets for exactly these bypass techniques, making phishing-resistant MFA a priority control rather than a nice-to-have.
Rolling this out is typically phased: organizations start with their most sensitive and highest-privilege accounts, provide clear device backup and recovery guidance so a lost security key does not lock someone out, and pair the rollout with single sign-on where possible so fewer separate logins need to be protected individually. Retiring SMS-based MFA entirely is not always immediate, since some legacy systems or partner integrations may not yet support FIDO2 or passkeys, but every account moved off SMS and push in favor of a phishing-resistant method meaningfully shrinks the paths an attacker can exploit.
At a glance
- Type
- Authentication control
- Also known as
- FIDO2 MFA, WebAuthn MFA
How it works
- 1
Origin binding: during registration, the security key or passkey cryptographically binds the credential to the exact website domain.
- 2
Challenge-response: at login, the site sends a cryptographic challenge that only the correct private key can answer.
- 3
Local key storage: the private key never leaves the user's device or hardware security key.
- 4
Local unlock: the user approves the response with a fingerprint, face scan, or PIN, confirming physical presence.
- 5
Origin check blocks phishing: if the login attempt happens on a lookalike domain, the origin mismatch means no valid response is produced at all.
- 6
No relayable secret: unlike an SMS or app-based code, there is nothing a user could read aloud or paste into a fake page.
Key points
- The credential is cryptographically bound to the legitimate site's exact origin, not just its appearance
- The private key never leaves the user's device, so there is nothing an attacker can steal remotely
- There is no code or shared secret to phish, relay, or read aloud, unlike SMS or authenticator app codes
- It resists both real-time adversary-in-the-middle relay and MFA-fatigue push-spamming attacks
- FIDO2 security keys and passkeys are the current industry standard for phishing-resistant authentication
- Privileged accounts, administrators, executives, and finance staff, are the priority targets for rollout
Best practices
- Prioritize privileged accounts, administrators, executives, IT, and finance staff, for the first rollout phase
- Offer FIDO2 hardware security keys as a backup alongside device-bound passkeys for flexibility
- Pair the rollout with single sign-on so fewer individual logins need separate protection
- Establish clear device loss and recovery procedures before requiring phishing-resistant MFA broadly
- Phase the transition with employee guidance so the new sign-in flow does not create support friction
- Retire SMS and email one-time codes for high-value accounts once a phishing-resistant option is adopted
Real-world example
An IT administrator's login attempt is intercepted by an adversary-in-the-middle proxy hosting a fake Microsoft 365 portal. With SMS-based MFA, the attacker captures and relays the one-time code within seconds, gaining a fully authenticated session. After the organization switches the same administrator to a FIDO2 security key, the identical attack fails outright: the key checks the site's origin before responding, and because the fake portal's domain does not match, no valid signature is produced regardless of how convincing the page looks.
How Claro helps
Claro's phishing simulations include adversary-in-the-middle and MFA-fatigue scenarios that reveal exactly which employees would relay a one-time code to a fake login page or approve an unsolicited push prompt, giving security teams a risk-ranked list to prioritize phishing-resistant MFA rollout by account and department rather than guessing where the exposure is highest.
Frequently asked questions
What actually makes an MFA method "phishing-resistant"?
The credential is cryptographically bound to the legitimate website's exact domain during setup, so it produces no valid response on a lookalike phishing page. There is also no code or shared secret for a user to read aloud or type, unlike SMS or authenticator app codes.
Is a passkey the same thing as phishing-resistant MFA?
Passkeys are one of the two current implementations of phishing-resistant MFA, alongside FIDO2 hardware security keys. Both are built on the same WebAuthn standard and origin-binding mechanism.
Can SMS or push-based MFA be made phishing-resistant?
Not in their current form. SMS codes can be intercepted or relayed, and push approvals can be spammed until a user accepts one out of fatigue. Only methods that cryptographically bind the credential to the site's origin, like FIDO2 and passkeys, close this gap.
Where should an organization start rolling out phishing-resistant MFA?
Start with the accounts that would cause the most damage if compromised, administrators, executives, and finance staff who approve payments, then expand outward as device support and employee familiarity grow.
Related terms
Passkey
A passwordless sign-in method using cryptographic key pairs, tied to a device and biometric or PIN unlock, that resists phishing by design.
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
MFA Fatigue
An attack that bombards a victim with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
Adversary-in-the-Middle (AiTM) Phishing
A real-time phishing technique that uses a proxy server to relay a victim's login between them and the real website, stealing the session cookie and bypassing most multi-factor authentication.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo