The MFA Level-Up: Why SMS Codes Are No Longer Enough (and What to Use Instead)
If your business uses multi-factor authentication, good. If the second factor is an SMS code sent by text message, you have a start, but not the best protection available. Attackers have learned to get around text codes, and the stronger options are easier to use than most people expect.
Why SMS codes fall short
A text message code proves that someone can read a message sent to a phone number. That sounds safe, but there are several ways around it:
- Fake login pages. A convincing copy of a sign-in page collects the password and the code at the same moment and passes both to the real site before the code expires.
- SIM swapping. A criminal convinces a mobile carrier to move your number to a different SIM card, and the codes start arriving on their phone.
- Tricked users. An attacker posing as support asks you to read out the code you just received.
CISA, the US cybersecurity agency, describes text message and voice codes as weaker forms of multi-factor authentication that should be used only as a last resort, and encourages organizations to move to phishing-resistant methods where they can. Any multi-factor authentication is still far better than none, so do not turn off text codes before something stronger is in place.
The options, from good to best
Authenticator apps. An app such as Microsoft Authenticator generates a code on your phone, or asks you to approve a sign-in. This avoids the phone number problem. Look for apps that ask you to match a number shown on the screen, which prevents accidental approvals and “approval fatigue” attacks where a user is pestered with prompts until they tap yes.
Passkeys. A passkey uses your device’s fingerprint, face or PIN to sign you in, and the secret never leaves the device. Because it is tied to the real website, a fake page cannot use it. Our post on what passkeys are and whether your business should use them covers the details.
Hardware security keys. A small USB or tap-to-connect key that you touch to sign in. These are also phishing-resistant and well suited to administrators and people who handle money, since they cannot be tricked into approving a fake request.
Microsoft’s own guidance recommends phishing-resistant methods such as passkeys, FIDO2 security keys and Windows Hello for the best protection of sign-ins.
Balance protection and convenience
The strongest method on paper is useless if people work around it. Good rollouts match the method to the risk:
- Everyone: authenticator app with number matching, or passkeys where supported.
- Administrators, finance staff and executives: passkeys or hardware keys, since their accounts are the best targets.
- Everyone: a backup way in, such as a second registered key or a recovery process handled by your IT provider, so that a lost phone does not lock someone out for days.
Allow some time for a rollout. Explain why you are changing it, show people the new steps in a short session and keep the old method available briefly while everyone moves.
What doing nothing costs
Many business email takeovers, fraudulent payments and ransomware incidents begin with a stolen password. Multi-factor authentication stops most of them, and phishing-resistant methods stop most of the rest. Insurance applications now ask detailed questions about where multi-factor authentication is used and what kind. See how to answer cyber insurance renewal questions.
A simple plan
- Turn on multi-factor authentication for every account that supports it, starting with email, administrator accounts, banking and anything with customer data.
- Move from text codes to an authenticator app with number matching.
- Add passkeys or hardware keys for administrators and finance, then expand.
- Disable text and voice methods where you can, once everyone has a stronger one.
- Make sure each person has a recovery method.
Our Microsoft 365 support covers multi-factor authentication and access policies, and our cybersecurity services cover strong sign-in protection more broadly. A free security review looks at how your accounts and passwords are protected today.
Frequently asked questions
Is SMS multi-factor authentication still worth using?
Yes, if it is all you have. It blocks many simple password attacks. But it can be bypassed, so treat it as a starting point and move to an authenticator app or passkey.
What is phishing-resistant MFA?
A sign-in method that cannot be handed to a fake website, because it is bound to the real site. Passkeys and FIDO2 security keys are the common examples.
Are authenticator apps safe?
They are a clear improvement over text codes, especially with number matching. They can still be fooled by a fake login page that relays the code, which is why passkeys and security keys are stronger.
What happens if an employee loses their phone?
With a planned recovery method, such as a second registered key or an identity check by your IT provider, they are back in quickly. Without one, a lost phone can lock them out. Set up recovery before it is needed.
Does Microsoft 365 support these options?
Yes. Microsoft 365 and Microsoft Entra ID support authenticator apps, passkeys and security keys, and administrators can require them. Settings and licensing differ, so ask your IT provider to review your tenant.
