Authentication that is tied to the real website and the user's device, so a fake site cannot capture and replay it. Examples include passkeys (FIDO2), Windows Hello for Business and certificate-based authentication used as multifactor; Conditional Access can demand these through a built-in authentication strength.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Phishing-resistant MFA in context, with comparison tables and the common traps.
Terms in this definition
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
- FIDO2
An open standard, used together with WebAuthn, that underpins passkeys and hardware security keys. Sign-in relies on a private key kept on the device in place of a password, so it resists phishing.
- Windows Hello for Business
Sign-in for Windows that needs no password and resists phishing, provided the device has suitable hardware.
- Certificate-based authentication
Lets people authenticate to Microsoft Entra by presenting an X.509 certificate from your organisation's PKI. Scoped to a group, it becomes an extra option, can count as passwordless MFA and doesn't stop anyone using other methods.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Authentication strength
Grant control in Conditional Access that restricts which combinations of methods meet a policy, for example the built-in Phishing-resistant MFA. It narrows methods without enabling them; enabling is done in the authentication methods policy.
Related terms
- Require authentication strength
Rather than just asking for MFA, this grant control insists on a defined mix of methods: one of Microsoft's built-in strengths, such as Phishing-resistant MFA, or a custom one you create.