CISA counts exactly two kinds of authentication as phishing resistant. The first is FIDO/WebAuthn, the standard behind security keys and passkeys. The second is PKI-based smart cards, such as the federal PIV and CAC cards. Text message codes, voice calls, authenticator app codes and push approval prompts all fall outside that line, according to the agency's fact sheet Implementing Phishing-Resistant MFA.
That line matters before you spend money. A compliance dashboard that says "MFA enabled" can describe a product on either side of it. Only one side stops the real-time phishing kits that relay a password and a code as fast as the user types them. Knowing which side a product sits on tells you whether it closes that attack or only slows it down.
What makes a login phishing resistant
Every method CISA excludes has the same weakness. It produces something a person reads, retypes or approves: a six-digit code, a voice message, a tap on a prompt. A fake login page can ask for that thing and pass it to the real site within seconds. The user has no reliable way to tell the difference, and neither does the code.
The two accepted methods use public-key cryptography, a system in which a device holds a private key that never leaves it and the website holds only the matching public key. There is no shared secret to steal. FIDO2 pairs the W3C WebAuthn standard in the browser with the Client-to-Authenticator Protocol (CTAP), which lets the browser talk to the key or the phone. According to the federal Phishing-Resistant Authenticator Playbook, the private key sits in the device's TPM or secure enclave, the tamper-resistant chip built for that job.
The property that does the work is origin binding. When the credential is created, it is tied to the website's domain. At login, the browser checks which domain is asking before the key signs anything. A lookalike domain or a proxy sitting in the middle fails that check automatically, so there is nothing for it to relay. PIV and CAC cards, defined under FIPS 201 and the Defense Department's equivalent program, rely on the same public-key principle through certificates on the card.
Where NIST's assurance levels fit. NIST SP 800-63B grades authenticators by Authenticator Assurance Level (AAL), a scale of how much confidence a login gives. That is a separate question from phishing resistance. CISA's Hybrid Identity Solutions Guidance, finalized March 12, 2024, states that FIDO2 meets AAL2 and that CISA has assessed it as phishing resistant. The sources behind this page do not set out how specific authenticators map to AAL3. If a contract or regulator requires AAL3, check that requirement against SP 800-63B itself before you choose a key.
The playbook does say what a qualifying key should look like for federal use. The device should be validated at FIPS 140 Level 1 or 2. Registration should be protected by MFA. The key should require a PIN of at least six digits at issuance. It also separates two kinds of authenticator. Platform authenticators are built into the device, such as Windows Hello, Face ID and Touch ID. Roaming authenticators are portable keys, such as YubiKey or RSA DS-100. Passkeys synced across devices need attestation validation to be acceptable in enterprise and government settings.
Three places the line shows up
In the federal mandate. OMB Memorandum M-22-09, issued January 26, 2022, says agencies "must require users to use phishing-resistant methods to access agency resources." That rules out SMS codes, app codes and push prompts. A FIDO2 pilot run across eight agencies on Azure Active Directory, Okta and ForgeRock deployed between roughly 5,000 and 130,000 users per agency, and most of those pilots moved into production. An executive order signed June 6, 2025 dropped a separate Biden-era requirement to test phishing-resistant technologies. Cybersecurity Dive reports that the M-22-09 mandate itself was left intact.
In Microsoft Entra ID. Passkeys became the default sign-in method on September 1, 2026, and users set up for SMS or voice are being prompted to register one. Microsoft says it will stop delivering SMS and voice codes natively on February 1, 2027. Organizations that still need those methods will have to use a third-party carrier at their own cost, with configuration opening October 30, 2026. Microsoft gives AI-generated phishing as its reason, citing click-through rates as high as 54%, against about 12% for traditional lures.
In a downgrade attack. A phishing kit called BigBear 2.0, built on the open-source Evilginx2 proxy, does not try to break FIDO2. Its script switches off WebAuthn on the fake page so the login falls back to a weaker method. That only works where the account still has a push or code method enabled alongside the key. Researchers reported to BleepingComputer, as summarized by Paubox, that the kit completed 474 MFA-bypassed sign-ins and confirmed bypasses at 258 organizations. They also reported that it captured 4,148 session cookies. These figures come from that reporting and have not been independently confirmed here.
What phishing resistance does not cover
| Method | Phishing resistant per CISA? | Why |
|---|---|---|
| FIDO2 security key or passkey | Yes | Public-key credential bound to the site's origin |
| Windows Hello, Face ID, Touch ID | Yes | Platform authenticators running FIDO2 |
| PIV or CAC smart card | Yes | PKI certificate on the card, no shared secret |
| SMS or voice code | No | Code can be relayed by a proxy or redirected by a SIM swap |
| Authenticator app code (TOTP) | No | User retypes a code a fake page can capture |
| Push approve or deny | No | Open to MFA fatigue, repeated prompts until someone taps yes |
Phishing resistant does not mean "MFA enabled." CSO Online cites Uber in 2022 and MGM Resorts as cases where MFA was present and still failed.
It also does not protect a session after login. A stolen session cookie skips authentication entirely. A correctly issued credential in the wrong hands looks legitimate. Writing in Security Magazine, Mouhamad Mbacke puts the limit plainly: "Phishing-resistant authentication still depends on the enterprise assigning the authenticator to the right person."
Before you buy or switch anything
Ask every vendor one question: is this method FIDO2/WebAuthn or PKI? Anything else is not phishing resistant by CISA's definition, however it is marketed.
Once users are enrolled, remove the fallback methods. BigBear 2.0 shows that a key only protects an account where push and codes have been switched off. Buy keys that meet the playbook's baseline of FIPS 140 validation and a six-digit PIN, and give each user a backup key. The playbook's target is 99% of accounts carrying more than one phishing-resistant authenticator, with policy exceptions below 1%.
If you run Entra ID, February 1, 2027 is the date that forces the decision. CSO Online's suggested order is administrators first, then identity-provider access and the accounts that can reset credentials, then finance and engineering.
Which keys should you buy, and how do you roll them out?
The full path from choosing FIDO2 hardware to enrolling, replacing and recovering keys across a company.
Read the hardware key guide
Comments
No comments yet. Be the first to comment!
Leave a Comment