Managed IT · 6 min read

Phishing-resistant MFA: a passkey rollout plan for Microsoft 365

Text-message codes and push approvals are no longer enough against modern phishing kits. How to move your organisation to passkeys and phishing-resistant sign-in, step by step.

· Bhargava Group

Multi-factor authentication stopped a generation of password attacks. Attackers adapted. Today’s phishing kits sit between the user and the real sign-in page, capture the password and the one-time code, and steal the session token as it is issued. Push-notification fatigue attacks, where a user is bombarded until they approve, work for the same reason: the second factor is not bound to the real site.

Phishing-resistant methods fix this. Passkeys (FIDO2), Windows Hello for Business and certificate-based authentication are cryptographically tied to the genuine sign-in domain, so a look-alike page receives nothing it can reuse.

Step 1: Know where you stand

Report on the authentication methods registered and used across your tenant. Identify users still relying on SMS or voice, shared accounts, and service accounts that cannot use MFA at all.

Step 2: Protect administrators first

Global and privileged administrators are the highest-value targets. Require phishing-resistant methods for every admin role now, using hardware security keys or passkeys, and separate admin accounts from daily email accounts.

Step 3: Choose methods per population

  • Office staff on managed Windows devices: Windows Hello for Business.
  • Mobile and hybrid staff: passkeys in the Microsoft Authenticator app or in the device’s platform authenticator.
  • Shared workstations and shop floors: FIDO2 security keys or NFC badges.
  • Executives and finance: hardware keys plus a backup key.

Step 4: Roll out in waves

Enable the methods, then use Conditional Access authentication strengths to require phishing-resistant MFA for one group at a time, starting with IT, then finance and executives, then everyone. Communicate early, run short registration sessions, and keep a help-desk runbook for lost keys and new phones.

Step 5: Close the side doors

  • Block legacy authentication protocols that cannot do modern MFA.
  • Restrict or remove SMS and voice as sign-in methods once users have alternatives.
  • Protect account recovery. A strong sign-in is undone by a weak reset process, so verify identity before resetting any method.
  • Require compliant or managed devices for sensitive applications.

Step 6: Measure

Track the share of sign-ins using phishing-resistant methods, and the number of users still registered on weak methods. Aim for every privileged account at 100% immediately, and the whole organisation within a quarter.

Our Managed IT & Cybersecurity practice plans and runs passkey rollouts, including device readiness, Conditional Access design and user onboarding.

All insights

Talk to us

Talk to Managed IT & Cybersecurity.

A 30-minute consultation with a senior consultant. You leave with a clear next step — whether or not it involves us.

Privacy choices

Choose which optional technologies we may use. You can change this at any time from “Privacy choices” in the footer.

Strictly necessary

Security, spam protection (Cloudflare Turnstile) and remembering these choices. Always on.

Always on