Switch on multi-factor authentication everywhere, then go back and upgrade the accounts that matter to a method a phishing page cannot copy. That second half is the part most businesses skip, and it is the part that decides whether your MFA holds up against the attacks people are actually running in 2026. A code from an app is a big step up from a password alone. It is not the same thing as a passkey or a hardware key.

What the evidence says MFA is worth
The headline evidence is unusually strong for a security control. Microsoft researchers measured compromise rates across Azure Active Directory accounts and found that MFA reduced the risk of compromise by 99.22% across the whole population, and by 98.56% in cases where the password had already leaked. More than 99.99% of MFA-enabled accounts stayed secure over the study period. Microsoft’s own Entra documentation now rounds that to blocking more than 99.2% of account compromise attacks, and the platform has moved to mandatory MFA for administrative sign-ins.
Credential abuse has slipped down the rankings for exactly this reason. Verizon’s 2026 Data Breach Investigations Report found exploitation of software vulnerabilities overtook stolen credentials as the top initial access vector for the first time in 19 years, reaching 31% of breaches. That is partly attackers adapting and partly MFA closing the easy door. The report’s own advice on the subject is short: stop postponing the rollout.
There is still a long tail of gaps, including in the suppliers you depend on. The same report found that only 23% of third-party organisations had fully remediated missing or improperly configured MFA on their cloud accounts, and that half of all such findings were resolved within a month while weak passwords and over-broad permissions took closer to eight months to clear. Your own tenant is not the only one holding your data.
Four kinds of second factor, and which survive a fake login page
The practical split is between factors that can be replayed and factors that cannot. A code or an approval can be relayed by a page sitting between you and the real service. A FIDO2 credential cannot, because it is bound to the origin and simply refuses to answer a look-alike domain.
That distinction stopped being theoretical some time ago. In May 2026 Microsoft’s security team published an analysis of a multi-stage attacker-in-the-middle campaign that posed as a code-of-conduct notice, intercepted the authentication traffic live and walked away with tokens from accounts that had MFA switched on. In September 2026 the same team documented passkey-themed social engineering, where the lure was the passkey enrolment flow itself. The method you choose changes which of those you are exposed to.
| Method | Phishing-resistant | Cost | Recovery story | Best for |
|---|---|---|---|---|
| SMS or email one-time code | No | Usually free, sometimes per-message | Easy, and that is the problem | A stopgap on consumer services with no better option |
| Authenticator app code (TOTP) | No | Free | Needs a backup code or a second enrolled device | Broad coverage of everyday staff accounts |
| Push approval with number matching | No, but much harder to abuse | Included in most identity platforms | Tied to the enrolled device | Large user bases where keys are impractical |
| Platform passkey (phone, laptop, browser) | Yes | Free on hardware you already own | Syncs through the platform account | The default for most staff in 2026 |
| Hardware security key (FIDO2) | Yes | From USD 29 per key | Register a spare key per person | Admins, finance, anyone who can move money |
CISA’s guidance is direct about the hierarchy: phishing-resistant MFA is the most secure form and should be the target, with app-based codes as an interim step where keys are not yet practical. OWASP’s multi-factor authentication cheat sheet and the UK NCSC’s MFA guidance for online services reach the same conclusion from different directions.

Passkeys crossed into the mainstream in 2026
Passkeys stopped being an early-adopter curiosity. The FIDO Alliance’s State of Passkeys 2026 report, published on 7 May 2026, estimated 5 billion passkeys in active use worldwide. Its consumer survey of 11,000 adults across ten countries found 90% were familiar with passkeys and 75% had enabled them on at least some accounts. A parallel survey of 1,400 decision-makers at organisations with 500 or more employees found 68% were deploying, piloting or rolling out passkeys for workforce sign-in. Both surveys were run by Sapio Research in April 2026.
For a small business the practical read is that your staff already know what a passkey is, the devices they carry already support one, and the main platforms you use already accept them. The barrier is no longer technology or familiarity. It is whoever has to decide what happens when somebody drops their phone in a canal.
What the hardware actually costs
Hardware keys are the one line item with a real invoice attached, so it helps to see the actual list prices rather than the ones people remember from a few years ago.
| Model | Protocols | List price (USD) |
|---|---|---|
| Security Key NFC / Security Key C NFC | FIDO only | 29 |
| YubiKey 5 NFC / YubiKey 5C NFC | Multi-protocol | 58 |
| YubiKey 5C | Multi-protocol | 65 |
| YubiKey 5 Nano / 5C Nano | Multi-protocol | 68 |
| YubiKey 5Ci (USB-C and Lightning) | Multi-protocol | 85 |
| YubiKey 5 FIPS series | Multi-protocol, FIPS validated | from 88 |
The FIDO-only Security Key at USD 29 is the right answer for most people. You pay more for the YubiKey 5 series because it also does smart card, OTP and OpenPGP, which matters if you have legacy systems in the mix and does not if you do not. Two FIDO-only keys per person costs less than one of the multi-protocol models, and two keys is the configuration that actually survives real life.
Buy two cheap keys per person rather than one expensive one. The spare is the feature.
Recovery is where rollouts go wrong
Almost every failed MFA rollout fails at recovery, not at enrolment. Someone loses a phone on a Friday, the help desk has no safe way to re-enrol them, and the workaround that gets invented under pressure becomes the permanent back door. Attackers know this, which is why help-desk pretexting has become a favoured route in.
Decide three things before you enrol a single person. First, every account gets at least two registered factors, and for key accounts that means two physical keys. Second, break-glass administrator accounts exist, are excluded from conditional access policies that could lock everyone out, and their credentials live somewhere offline with a documented check-out process. Third, re-enrolment requires identity verification that does not rely on information an attacker could look up, and ideally involves a second person.
- Two factors registered per account, minimum, before the old method is removed.
- Two break-glass admin accounts, excluded from conditional access, stored offline.
- A written re-enrolment procedure that does not depend on knowledge questions.
- A quarterly check that the break-glass credentials still work.
Conditional access does the other half of the job
MFA answers the question of who is signing in. Conditional access answers whether that sign-in should be allowed at all. The two together are what people usually mean when they say zero trust, and the second half is often sitting unused in a licence you already pay for.
Start with three policies. Require MFA for every administrative role, with no exceptions beyond the break-glass accounts. Block or step up authentication for legacy protocols that cannot enforce modern policy. And require a managed or compliant device for access to the data that would hurt most if it left, which is usually the mail store and the finance system.
NIST’s SP 800-63B-4 is the reference worth reading if you need to justify the design to an auditor or an insurer. It sets the authentication assurance levels, and it is also the document that allows a shorter password when it is only one part of a multi-factor process: a minimum of eight characters there, against fifteen when a password stands alone. Our guide to current password rules covers what that means for the policy you publish to staff.

Which accounts to cover first
Work outward from damage, not from headcount. The accounts that need phishing-resistant MFA first are rarely the ones with the most logins.
- Identity platform administrators. Whoever can create accounts or change MFA policy can undo everything else on this list.
- The domain registrar and DNS. Losing control of DNS means losing control of email, which means losing control of every password reset you own.
- Finance, payroll and the banking portal. This is where business email compromise cashes out.
- The main mailbox of anyone client-facing. A compromised mailbox is a credible pretext generator for everyone in the thread.
- Remote access and the hosting control panel. Including the panel your website lives in, which people forget until it is used.
Everything after that is a volume exercise, and platform passkeys handle it well. If you are also working through the phishing controls and the ransomware basics, note how much overlap there is: the same five account groups appear at the top of all three lists.
Rolling it out without a revolt
Announce the reason, not the policy. People accept a change they understand the point of, and the point here is easy to state: a stolen password should not be enough, and your finance team should not be one convincing email away from a bad day.
Run it in waves. IT first, so the help desk has felt every rough edge before anyone else meets it. Then finance and leadership. Then everyone, with enrolment at a time people are at their desks rather than on a Monday morning. Keep the old method active alongside the new one for a week so a failed enrolment is an inconvenience rather than an outage, and only then remove it.
Expect the complaints to be about the first week and nothing after it. In our experience the single best predictor of a smooth rollout is whether a spare factor was registered on day one. Everything else is detail.
Frequently asked questions
Is MFA enough on its own?
No, and the honest version is that it never was. MFA closes the credential-stuffing and password-spray routes almost completely, which is why Verizon’s 2026 DBIR saw vulnerability exploitation overtake stolen credentials as the top way in. You still need patching, backups and a payment-verification rule. MFA is the highest-value single control, not a complete programme.
Can attackers get past MFA?
Past app codes and push approvals, yes, with a relay page or by wearing the user down with repeated prompts. Microsoft documented a working example in May 2026. Phishing-resistant methods such as passkeys and FIDO2 keys do not fall to that attack because the credential is bound to the real domain and will not respond to a look-alike.
What about staff who refuse to use a personal phone?
That is a fair objection and it has a clean answer: hand them a hardware key. At USD 29 for a FIDO-only model it is cheaper than the argument, it needs no apps or phone number, and it is the stronger method anyway. Keep a small stock so a new starter is never the reason a policy gets an exception.
Do passkeys work if we use both Apple and Microsoft accounts?
Yes. Passkeys are a FIDO standard rather than a vendor feature, and the major platforms sync them through their own accounts while still presenting a standard credential to the service. Mixed fleets are normal. Where it gets fiddly is shared accounts, which is a good prompt to stop having shared accounts.
How long does a rollout take for a 40-person business?
Two to four weeks of calendar time and a few days of actual work, assuming your identity platform is Microsoft 365 or Google Workspace and you already own the licences. Most of the elapsed time is waiting for people to enrol. The parts worth not rushing are the break-glass accounts and the re-enrolment procedure.
We plan and run MFA and passkey rollouts remotely for clients worldwide as part of our cybersecurity services, including conditional access policy, break-glass design and the recovery runbook your help desk will actually use. Get in touch with Eudora Technology to talk about your project.
Sources
- How effective is multifactor authentication at deterring cyberattacks?
- The State of Passkeys 2026: Global Consumer and Workforce Report
- Implementing Phishing-Resistant MFA (fact sheet)
- 2026 Data Breach Investigations Report (19th edition)
- SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management
- Hardware security key price list



