Skip to content
Eudora Technology
Home  / Insights
Cybersecurity

Multi-Factor Authentication: The One Upgrade Everyone Needs

Experiment using a better lens and manual focus with mirror lock-up. IR converted Canon Rebel XTi. AEB +/-2 total of 3 exposures processed with Photomatix. High Dynamic Range (HDR)
Photo: IR HDR by David from Colorado Springs, United States, CC BY 2.0, via Wikimedia Commons

Switch on multi-factor authentication everywhere, then go back and upgrade the accounts that matter to a method a phishing page cannot copy. That second half is the part most businesses skip, and it is the part that decides whether your MFA holds up against the attacks people are actually running in 2026. A code from an app is a big step up from a password alone. It is not the same thing as a passkey or a hardware key.

Infrared HDR on the hiking trail above the river. I used an IR converted Canon Rebel XTi. Conversion done by Life Pixel. I got the enhanced filter which allows more color. AEB +/-2
The question is never whether you have a second factor. It is whether that factor can be handed to somebody who asked nicely.Photo: Infrared HDR Buena Vista Colorado by David from Colorado Springs, United States, CC BY 2.0, via Wikimedia Commons

What the evidence says MFA is worth

The headline evidence is unusually strong for a security control. Microsoft researchers measured compromise rates across Azure Active Directory accounts and found that MFA reduced the risk of compromise by 99.22% across the whole population, and by 98.56% in cases where the password had already leaked. More than 99.99% of MFA-enabled accounts stayed secure over the study period. Microsoft’s own Entra documentation now rounds that to blocking more than 99.2% of account compromise attacks, and the platform has moved to mandatory MFA for administrative sign-ins.

Microsoft’s measurement of MFA effectiveness
Reduction in compromise risk, whole population99.22%
Reduction where the password had already leaked98.56%
MFA-enabled accounts that stayed secureover 99.99%
Source: Microsoft Research, ‘How effective is multifactor authentication at deterring cyberattacks?’

Credential abuse has slipped down the rankings for exactly this reason. Verizon’s 2026 Data Breach Investigations Report found exploitation of software vulnerabilities overtook stolen credentials as the top initial access vector for the first time in 19 years, reaching 31% of breaches. That is partly attackers adapting and partly MFA closing the easy door. The report’s own advice on the subject is short: stop postponing the rollout.

There is still a long tail of gaps, including in the suppliers you depend on. The same report found that only 23% of third-party organisations had fully remediated missing or improperly configured MFA on their cloud accounts, and that half of all such findings were resolved within a month while weak passwords and over-broad permissions took closer to eight months to clear. Your own tenant is not the only one holding your data.

Four kinds of second factor, and which survive a fake login page

The practical split is between factors that can be replayed and factors that cannot. A code or an approval can be relayed by a page sitting between you and the real service. A FIDO2 credential cannot, because it is bound to the origin and simply refuses to answer a look-alike domain.

That distinction stopped being theoretical some time ago. In May 2026 Microsoft’s security team published an analysis of a multi-stage attacker-in-the-middle campaign that posed as a code-of-conduct notice, intercepted the authentication traffic live and walked away with tokens from accounts that had MFA switched on. In September 2026 the same team documented passkey-themed social engineering, where the lure was the passkey enrolment flow itself. The method you choose changes which of those you are exposed to.

MethodPhishing-resistantCostRecovery storyBest for
SMS or email one-time codeNoUsually free, sometimes per-messageEasy, and that is the problemA stopgap on consumer services with no better option
Authenticator app code (TOTP)NoFreeNeeds a backup code or a second enrolled deviceBroad coverage of everyday staff accounts
Push approval with number matchingNo, but much harder to abuseIncluded in most identity platformsTied to the enrolled deviceLarge user bases where keys are impractical
Platform passkey (phone, laptop, browser)YesFree on hardware you already ownSyncs through the platform accountThe default for most staff in 2026
Hardware security key (FIDO2)YesFrom USD 29 per keyRegister a spare key per personAdmins, finance, anyone who can move money
Costs from Yubico’s published price list, retrieved 1 October 2026. Phishing resistance as defined in CISA’s phishing-resistant MFA fact sheet.

CISA’s guidance is direct about the hierarchy: phishing-resistant MFA is the most secure form and should be the target, with app-based codes as an interim step where keys are not yet practical. OWASP’s multi-factor authentication cheat sheet and the UK NCSC’s MFA guidance for online services reach the same conclusion from different directions.

IR HDR. IR converted Canon Rebel XTi. AEB +/-2 total of 3 exposures processed with Photomatix. Levels adjusted in PSE. High Dynamic Range (HDR) High-dynamic-range imaging (HDRI) is
Forensics work tends to answer the same question every time: which credential was replayed, and how long did the attacker have it.Photo: Infrared HDR Crested Butte Colorado. by David from Colorado Springs, United States, CC BY 2.0, via Wikimedia Commons

Passkeys crossed into the mainstream in 2026

Passkeys stopped being an early-adopter curiosity. The FIDO Alliance’s State of Passkeys 2026 report, published on 7 May 2026, estimated 5 billion passkeys in active use worldwide. Its consumer survey of 11,000 adults across ten countries found 90% were familiar with passkeys and 75% had enabled them on at least some accounts. A parallel survey of 1,400 decision-makers at organisations with 500 or more employees found 68% were deploying, piloting or rolling out passkeys for workforce sign-in. Both surveys were run by Sapio Research in April 2026.

FIDO Alliance State of Passkeys 2026
Consumers familiar with passkeys90%
Consumers who have enabled one75%
Organisations deploying or piloting for staff68%
Consumer n=11,000 across ten countries; workforce n=1,400 decision-makers at organisations of 500+ employees. Source: FIDO Alliance, May 2026.

For a small business the practical read is that your staff already know what a passkey is, the devices they carry already support one, and the main platforms you use already accept them. The barrier is no longer technology or familiarity. It is whoever has to decide what happens when somebody drops their phone in a canal.

What the hardware actually costs

Hardware keys are the one line item with a real invoice attached, so it helps to see the actual list prices rather than the ones people remember from a few years ago.

ModelProtocolsList price (USD)
Security Key NFC / Security Key C NFCFIDO only29
YubiKey 5 NFC / YubiKey 5C NFCMulti-protocol58
YubiKey 5CMulti-protocol65
YubiKey 5 Nano / 5C NanoMulti-protocol68
YubiKey 5Ci (USB-C and Lightning)Multi-protocol85
YubiKey 5 FIPS seriesMulti-protocol, FIPS validatedfrom 88
List prices from Yubico’s own store, retrieved 1 October 2026. Prices move, so check before you budget.

The FIDO-only Security Key at USD 29 is the right answer for most people. You pay more for the YubiKey 5 series because it also does smart card, OTP and OpenPGP, which matters if you have legacy systems in the mix and does not if you do not. Two FIDO-only keys per person costs less than one of the multi-protocol models, and two keys is the configuration that actually survives real life.

Buy two cheap keys per person rather than one expensive one. The spare is the feature.

Recovery is where rollouts go wrong

Almost every failed MFA rollout fails at recovery, not at enrolment. Someone loses a phone on a Friday, the help desk has no safe way to re-enrol them, and the workaround that gets invented under pressure becomes the permanent back door. Attackers know this, which is why help-desk pretexting has become a favoured route in.

Decide three things before you enrol a single person. First, every account gets at least two registered factors, and for key accounts that means two physical keys. Second, break-glass administrator accounts exist, are excluded from conditional access policies that could lock everyone out, and their credentials live somewhere offline with a documented check-out process. Third, re-enrolment requires identity verification that does not rely on information an attacker could look up, and ideally involves a second person.

The recovery checklist that prevents the Friday-afternoon problem
  • Two factors registered per account, minimum, before the old method is removed.
  • Two break-glass admin accounts, excluded from conditional access, stored offline.
  • A written re-enrolment procedure that does not depend on knowledge questions.
  • A quarterly check that the break-glass credentials still work.

Conditional access does the other half of the job

MFA answers the question of who is signing in. Conditional access answers whether that sign-in should be allowed at all. The two together are what people usually mean when they say zero trust, and the second half is often sitting unused in a licence you already pay for.

Start with three policies. Require MFA for every administrative role, with no exceptions beyond the break-glass accounts. Block or step up authentication for legacy protocols that cannot enforce modern policy. And require a managed or compliant device for access to the data that would hurt most if it left, which is usually the mail store and the finance system.

NIST’s SP 800-63B-4 is the reference worth reading if you need to justify the design to an auditor or an insurer. It sets the authentication assurance levels, and it is also the document that allows a shorter password when it is only one part of a multi-factor process: a minimum of eight characters there, against fifteen when a password stands alone. Our guide to current password rules covers what that means for the policy you publish to staff.

IR converted Canon Rebel XTi. AEB +/-2 total of 3 exposures processed with Photomatix. High Dynamic Range (HDR) High-dynamic-range imaging (HDRI) is a high dynamic range (HDR) tech
A password manager and MFA solve different problems. You want both, and in that order if you can only do one thing this quarter.Photo: Infrared HDR Garden of the Gods Colorado by David from Colorado Springs, United States, CC BY 2.0, via Wikimedia Commons

Which accounts to cover first

Work outward from damage, not from headcount. The accounts that need phishing-resistant MFA first are rarely the ones with the most logins.

  1. Identity platform administrators. Whoever can create accounts or change MFA policy can undo everything else on this list.
  2. The domain registrar and DNS. Losing control of DNS means losing control of email, which means losing control of every password reset you own.
  3. Finance, payroll and the banking portal. This is where business email compromise cashes out.
  4. The main mailbox of anyone client-facing. A compromised mailbox is a credible pretext generator for everyone in the thread.
  5. Remote access and the hosting control panel. Including the panel your website lives in, which people forget until it is used.

Everything after that is a volume exercise, and platform passkeys handle it well. If you are also working through the phishing controls and the ransomware basics, note how much overlap there is: the same five account groups appear at the top of all three lists.

Rolling it out without a revolt

Announce the reason, not the policy. People accept a change they understand the point of, and the point here is easy to state: a stolen password should not be enough, and your finance team should not be one convincing email away from a bad day.

Run it in waves. IT first, so the help desk has felt every rough edge before anyone else meets it. Then finance and leadership. Then everyone, with enrolment at a time people are at their desks rather than on a Monday morning. Keep the old method active alongside the new one for a week so a failed enrolment is an inconvenience rather than an outage, and only then remove it.

Expect the complaints to be about the first week and nothing after it. In our experience the single best predictor of a smooth rollout is whether a spare factor was registered on day one. Everything else is detail.

Frequently asked questions

Is MFA enough on its own?

No, and the honest version is that it never was. MFA closes the credential-stuffing and password-spray routes almost completely, which is why Verizon’s 2026 DBIR saw vulnerability exploitation overtake stolen credentials as the top way in. You still need patching, backups and a payment-verification rule. MFA is the highest-value single control, not a complete programme.

Can attackers get past MFA?

Past app codes and push approvals, yes, with a relay page or by wearing the user down with repeated prompts. Microsoft documented a working example in May 2026. Phishing-resistant methods such as passkeys and FIDO2 keys do not fall to that attack because the credential is bound to the real domain and will not respond to a look-alike.

What about staff who refuse to use a personal phone?

That is a fair objection and it has a clean answer: hand them a hardware key. At USD 29 for a FIDO-only model it is cheaper than the argument, it needs no apps or phone number, and it is the stronger method anyway. Keep a small stock so a new starter is never the reason a policy gets an exception.

Do passkeys work if we use both Apple and Microsoft accounts?

Yes. Passkeys are a FIDO standard rather than a vendor feature, and the major platforms sync them through their own accounts while still presenting a standard credential to the service. Mixed fleets are normal. Where it gets fiddly is shared accounts, which is a good prompt to stop having shared accounts.

How long does a rollout take for a 40-person business?

Two to four weeks of calendar time and a few days of actual work, assuming your identity platform is Microsoft 365 or Google Workspace and you already own the licences. Most of the elapsed time is waiting for people to enrol. The parts worth not rushing are the break-glass accounts and the re-enrolment procedure.

We plan and run MFA and passkey rollouts remotely for clients worldwide as part of our cybersecurity services, including conditional access policy, break-glass design and the recovery runbook your help desk will actually use. Get in touch with Eudora Technology to talk about your project.

Sources

  1. How effective is multifactor authentication at deterring cyberattacks? Microsoft Research · 2023
  2. The State of Passkeys 2026: Global Consumer and Workforce Report FIDO Alliance · 7 May 2026
  3. Implementing Phishing-Resistant MFA (fact sheet) CISA · retrieved October 2026
  4. 2026 Data Breach Investigations Report (19th edition) Verizon Business · 19 May 2026
  5. SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management NIST · August 2025
  6. Hardware security key price list Yubico · retrieved 1 October 2026
Keep reading

Related insights