06/22/2026
🔐 Honest question: if every user in your tenant passed MFA tomorrow, how many would survive a real phishing page? "MFA is on" and "phishing-resistant" are not the same sentence, and NIST's July 2025 revision made that official.
Your factor count was never the bar. Phishing resistance is. That rule sorts every Entra method into three tiers: enable, restrict, or turn off.
✅ FIDO2 keys, Windows Hello, and CBA clear AAL3 (non-exportable)
✅ Device-bound passkeys in Authenticator sit in the phone's secure chip (non-synced)
✅ Synced passkeys are phishing-resistant but cap at AAL2
⚠️ Push and TOTP are still relayable through a proxy
⚠️ SMS and voice are SIM-swappable and being phased out
⚠️ Email OTP and security questions fail outright
Breakdown is in the first comment. Open your Authentication Methods policy and check: is anything in the DISABLE column still on for privileged users? Tell me what you find, and a like helps another defender catch theirs.
🔔 Subscribe to my LinkedIn security articles for the next one: https://lnkd.in/eSxv_ZzK