Install our extension to search inside any video instantly.

SMS Gets Hacked, FIDO2 Doesn't: Why Your MFA Isn't Good Enough

Added:
166 views12likes16:55CiraltosOriginal Release: 2026-07-22

Not all MFA methods provide equal security protection; SMS and voice calls are vulnerable to SIM swapping and real-time phishing attacks, while OATH software tokens can be replayed on fake login pages, and push notifications can be approved under pressure. Phishing-resistant MFA methods like FIDO2 security keys and Windows Hello for Business are cryptographically tied to the exact domain being signed into, making them immune to phishing attacks. Organizations should enforce phishing-resistant MFA for high-value accounts like Global Administrators using Entra ID's authentication strength policies, which allow requiring specific MFA combinations rather than accepting any MFA method.