Keep the authenticator app for most staff, and put hardware security keys on administrators and other privileged accounts first. The whole difference comes down to one property. A security key will not give its credential to a fake login page. An authenticator app relies on a person noticing that the page is fake.
That property is what CISA means by "phishing-resistant," and it is why the agency puts security keys in a different class from app codes and push prompts. Whether keys are worth the cost for everyone is a narrower question. For many general staff, a phone-based passkey gets the same protection without buying hardware.
The two side by side
| Feature | Hardware security key (FIDO2/WebAuthn) | Authenticator app (TOTP codes or push) |
|---|---|---|
| Classification, CISA | Phishing-resistant | Not phishing-resistant |
| Credential bound to the real site's domain, CISA | Yes, cannot be replayed on a spoofed site | No, the user relays a code or approves a prompt |
| Highest assurance level, NIST SP 800-63-4 | Meets AAL3 with a PIN or biometric | Below AAL3, which requires phishing resistance |
| Push bombing (MFA fatigue), CISA | Not susceptible | Push variants susceptible; number matching is CISA's interim fix |
| Targeted by the Tycoon2FA AitM kit, Microsoft | No, the kit targets non-phishing-resistant MFA | Yes |
None of the sources we rely on publish a per-key price or a per-seat app cost, so price is not in the table. Check current pricing before you build a budget.
Hardware security keys
A hardware security key is a small USB or NFC device that holds a private key that never leaves it. When you sign in, the key checks which website is asking and signs a challenge only for that site. A look-alike domain gets nothing, because the key never produces anything for it.
That check is the reason keys sit at the top of the federal hierarchy. NIST SP 800-63-4 requires a public-key authenticator with a non-exportable private key for AAL3, its highest assurance level. It names a FIDO2 security key used with a PIN or biometric as an example. The same revision lists FIDO2 keys as a recommended authenticator at AAL2, the level most business sign-ins fall under.
The outcome figures are strong but come secondhand. A roundup by StingRAI quotes Microsoft's Digital Defense Report 2025 as saying phishing-resistant MFA blocks over 99% of identity-based attacks. Treat that as Microsoft's figure, relayed by a secondary source.
Keys have limits. They protect the sign-in, not what happens after it. The same roundup cites SpyCloud as recapturing 8.6 billion stolen session cookies and tokens in 2025, and a stolen session skips MFA entirely. Keys also add logistics that apps do not have:
- buying the hardware
- shipping it to remote staff
- registering a backup key
- replacing lost ones
Buy them for the accounts whose compromise would be a company-wide incident: domain and cloud admins, finance approvers and help desk staff who can reset other people's MFA.
- Classified by CISA as phishing-resistant; credential is bound to the real domain
- Meets NIST AAL3 when used with a PIN or biometric
- Not susceptible to push bombing or SIM swapping, per CISA
- Physical logistics: purchase, distribution, spares and replacement
- Does not stop theft of a session token after sign-in
- Enrollment and recovery processes can still be attacked
Authenticator apps
An authenticator app does one of two things. It shows a six-digit code that changes every 30 seconds (TOTP, for time-based one-time password), or it sends a push prompt that the user approves. Either way, a person types or taps something on the attacker's behalf if they have been fooled.
That is the opening that adversary-in-the-middle (AitM) kits exploit. An AitM kit is a fake login page that silently passes everything to the real one. The victim enters a password and code, the kit forwards them live, and the attacker keeps the resulting session. Microsoft's Q1 2026 email threat report describes Tycoon2FA, run by Storm-1747 since August 2023, as built for exactly this. It aims to "defeat non-phishing-resistant multifactor authentication." Push prompts carry a second risk: an attacker can send prompts repeatedly until a tired user taps Approve.
The app still beats SMS and still stops attacks that use only a password. It costs nothing extra in hardware, and your staff already know how to use it. But it is not the end state. StingRAI cites Proofpoint as finding that 59% of accounts compromised in 2025 had MFA enabled at the time.
One caveat changes the picture. Microsoft Authenticator can also store a device-bound passkey. Used that way, the app is no longer doing TOTP or push. It counts as FIDO, which is phishing-resistant. Keep the app for general staff, and plan to move those users onto passkeys.
Three things that separate them
Who does the checking. NIST defines phishing resistance as preventing disclosure of secrets to an impostor "without reliance on the vigilance of the claimant." Put simply, the protocol notices the fake site so the user does not have to. Think of a front-door key against a door code. A key does not open the house next door. A code works anywhere someone types it in, including a fake keypad. That matters more as phishing gets better. Microsoft says AI-generated campaigns have reached click-through rates of up to 54%, against about 12% for traditional phishing.
How cheap the attack is. AitM is sold as a service. Microsoft and Europol disrupted Tycoon2FA in March 2026. ThreatsEye reports that its volume had fallen 92% from late-2025 levels by June. The kit's operators moved to .RU domains rather than shutting down, and attackers are moving toward Microsoft Teams. One takedown lowers the volume for a while. It does not change the fact that app-based MFA can be relayed.
What neither one fixes. Both depend on enrollment and recovery. CISA's Scattered Spider case studies show attackers talking help desks into resetting MFA. Security Magazine describes a Microsoft investigation dated September 9, 2026 in which attackers added their own authentication methods to accounts they had already compromised. A key protects a privileged account only if issuing and replacing that key is at least as strict as the key itself. Of all three, this is where rollouts tend to fail.
Which to buy
If you already run an authenticator app rollout, do not rip it out. Do these four things:
- Buy hardware keys, two per person, for global and cloud admins, finance approvers and help desk staff who can reset MFA. These are the accounts where one relayed code costs the most. NIST and Microsoft both point device-bound credentials at these roles.
- Turn on number matching for anyone still using push. It is CISA's interim fix for push bombing. It is still weaker than phishing-resistant MFA.
- Move general staff from TOTP and push to passkeys in the app or the platform they already use. Microsoft says switching to passkeys in Entra ID has no cost. The FIDO Alliance workforce survey found that organizations with completed rollouts reported 35% fewer password-reset tickets and 32% fewer phishing-related incidents.
- Buy keys for all staff only if your general staff lack a suitable phone or computer for passkeys, or a contract or regulator requires hardware-bound credentials across the workforce.
Whichever you choose, the method has to be one that CISA counts as phishing-resistant. Then lock down the help desk reset path before you hand out a single key.
Decided some of your workforce needs hardware keys?
The pillar guide walks through choosing keys, enrolling users, issuing spares and handling recovery.
Read the security key deployment guide
Comments
No comments yet. Be the first to comment!
Leave a Comment