---
title: "Phishing-Resistant MFA — Identity Glossary | IDSync"
description: "Phishing-resistant MFA is multi-factor authentication that cannot be intercepted, replayed, or socially engineered around — in practice today this means…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Phishing-Resistant MFA",
          "item": "https://idsync.com/glossary/phishing-resistant-mfa"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/phishing-resistant-mfa",
      "name": "Phishing-Resistant MFA",
      "alternateName": [
        "Phishing-Resistant MFA",
        "FIDO2 MFA",
        "WebAuthn MFA"
      ],
      "description": "Phishing-resistant MFA is multi-factor authentication that cannot be intercepted, replayed, or socially engineered around — in practice today this means FIDO2/WebAuthn (security keys and passkeys) or PIV / CAC smart cards. SMS, TOTP, and push-approve MFA are *not* phishing-resistant.",
      "url": "https://idsync.com/glossary/phishing-resistant-mfa",
      "inDefinedTermSet": "https://idsync.com/glossary"
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  Phishing-Resistant MFA 

MFA

# Phishing-Resistant MFA

Phishing-resistant MFA is multi-factor authentication that cannot be intercepted, replayed, or socially engineered around — in practice today this means FIDO2/WebAuthn (security keys and passkeys) or PIV / CAC smart cards. SMS, TOTP, and push-approve MFA are \*not\* phishing-resistant.

Last reviewed 3 months ago

Key points

-   CISA, NIST 800-63B, and Microsoft all recommend phishing-resistant MFA as the gold standard.
-   Phishing-resistant = origin-bound cryptographic proof: a fake site can't get a signature for the real site's domain.
-   SMS, TOTP, voice, and push notifications are bypassable via AiTM proxies (Evilginx), push bombing, SIM swap, and social engineering.
-   Implement at minimum for: admins, finance, executives, IT/security staff, and anyone with access to source code or production.
-   US Executive Order 14028 and OMB M-22-09 require phishing-resistant MFA for all federal employees and contractors.

## What is phishing-resistant MFA?

**Phishing-resistant MFA** is the subset of multi-factor authentication that cannot be defeated by a convincing fake login page, an adversary-in-the-middle proxy, push fatigue, or social engineering. In practice today, this is:

-   **FIDO2 / WebAuthn** security keys (YubiKey, Titan, Feitian, SoloKey)
-   **Passkeys** (FIDO2 credentials, synced or device-bound)
-   **PIV / CAC smart cards** (mostly government)
-   **Windows Hello for Business** (certificate-backed)

What makes them phishing-resistant: the credential is **cryptographically bound to the real site's origin**. When a user lands on a phishing site at `acrne.com`, the browser refuses to sign anything for `acme.com` because the rp\_id doesn't match. There is no human-decision step that can be fooled.

## What is _not_ phishing-resistant

-   **SMS / voice OTP** — interceptable, SIM-swap-vulnerable.
-   **TOTP authenticator apps** — phishable through AiTM proxies (Evilginx, Modlishka) that relay the OTP in real-time.
-   **Push notifications** — push-bombing (spam approvals until the user taps), social engineering ("IT needs you to approve"), and AiTM defeat these.
-   **Email magic links** — phishable; the link can be stolen at the inbox.
-   **Knowledge-based questions** — defeated by data breaches.

The reality is grim: every major MFA-bypass breach of the last three years (Uber, Twilio, Cisco, Cloudflare, Microsoft midnight blizzard) defeated push or TOTP-based MFA.

## Who needs it first

CISA and most ITDR guidance recommend a tiered rollout:

1.  **Privileged users** — IT, security, domain admins, cloud admins, source code owners, finance executives.
2.  **High-target roles** — anyone in support / sales who handles customer data and gets phished daily.
3.  **All employees**, eventually.

## Implementation reality

-   Most major IdPs (Entra ID, Okta, Google, Auth0, Duo, Ping) support FIDO2.
-   Hardware keys cost $25–70/user; passkeys cost nothing extra.
-   The harder problems are _enrollment_ (getting keys to remote employees), _recovery_ (lost keys), and _coverage_ (legacy apps that don't support FIDO2).

## Editorial note

If your security budget can fund only one initiative this year, replacing push/TOTP MFA with FIDO2 for privileged users is almost certainly the highest-ROI option.

## Standards & references

-   [CISA — Phishing-Resistant MFA Implementation Guide](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf)
-   [OMB M-22-09](https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[mfa](/directory/category/mfa)[passwordless](/directory/category/passwordless)

### Related terms

[multi factor authentication](/glossary/multi-factor-authentication)[passkeys](/glossary/passkeys)[fido2](/glossary/fido2)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the mfa category.

[Explore tools](/directory/category/mfa)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.