Passwords and weak MFA remain the easiest path for credential stuffing, proxy phishing, and MFA fatigue.
Preface
SMS, voice, and basic push approvals are widely bypassed by modern proxy kits. High-assurance environments need phishing-resistant passwordless authentication.
Problem
Standard MFA is not cryptographically bound to the IdP domain, so AiTM proxies can capture successful authentication. Push fatigue can also produce accidental approvals without advanced tooling.
Solution
Align with NIST SP 800-63B AAL3 and CIS Microsoft 365 Foundations Benchmark:
- Deploy FIDO2 / passkeys (hardware keys or Windows Hello for Business).
- Enforce Entra CBA with smart cards or hardware tokens.
- Require phishing-resistant authentication strengths in Conditional Access for admins and high-risk sessions.
PowerShell: Configure FIDO2 Method Policy
Connect-MgGraph -Scopes "Policy.ReadWrite.AuthenticationMethod"
$params = @{
IsSelfServiceRegistrationAllowed = $true
EnforceKeyRestrictions = $true
}
Update-MgPolicyAuthenticationMethodFido2Configuration -BodyParameter $params