Glossary »

Phishing-Resistant MFA


Pishing-resistant MFA

Phishing-resistant MFA is a stronger form of multifactor authentication designed to prevent attackers from stealing login credentials through fake websites, malicious prompts, or other phishing techniques. Unlike weaker MFA methods such as SMS codes or basic push notifications, Phishing-Resistant MFA uses cryptographic authentication that is tied to the legitimate website or application, making it much harder for criminals to intercept or reuse credentials. Common examples include FIDO2 security keys, passkeys, smart cards, and certain certificate-based authentication methods. For businesses, phishing-resistant MFA helps reduce the risk of account compromise, business email compromise, and unauthorized access to cloud services and sensitive data.