Home › Glossary › Phishing-resistant MFA

Phishing-resistant MFA

Authentication that is tied to the real website and the user's device, so a fake site cannot capture and replay it. Examples include passkeys (FIDO2), Windows Hello for Business and certificate-based authentication used as multifactor; Conditional Access can demand these through a built-in authentication strength.

Read more: Microsoft Learn

In the Ultra Transcenders books

SC-900AB-900SC-300ALZ

Each book explains Phishing-resistant MFA in context, with comparison tables and the common traps.

Terms in this definition

Related terms

See Phishing-resistant MFA in the full glossary