Join our Newsletter — 33% off our NHI Course

How should security teams reduce phishing risk when employees use SSO or VPN links from text messages?

Security teams should treat texted login links as high risk and require users to navigate directly to the approved portal instead. The safest pattern is to verify the full URL, use bookmarks or a trusted launcher, and pair that with phishing-resistant MFA. This reduces the chance that a convincing fake page can capture credentials and one-time codes.

Text messages compress trust into a tiny screen, and that makes it easier for attackers to impersonate a real login flow. When the goal is SSO or VPN access, the safest assumption is that the message itself is untrusted and the destination must be reached through a known-good path, not the link the sender provided.

That matters because the user is not just being asked to click a page, they are being asked to hand over a session entry point. If the page is fake, the attacker can capture credentials, MFA codes, or session tokens in one step, especially when the user expects to be prompted for a routine re-authentication.

The practical control is to route users to the approved portal by a method they can verify, such as a bookmark, trusted launcher, or manually entered corporate URL. A login page should be treated as authentic only when the user has independently reached it, and the full domain is visible and recognized before any secret is entered.

That pattern should be paired with phishing-resistant MFA so the approval step cannot be replayed from a fake page. OpenID Connect Core 1.0 is useful here because it underpins modern SSO flows, but the operational point is simpler: do not let a texted link become the trust anchor for authentication.

For remote access specifically, teams should make sure the same rule applies to VPN entry points and not just to web SSO. The approved portal, device posture checks, and MFA should all sit behind a single, predictable access path rather than a collection of ad hoc text links that are hard for employees to validate under pressure.

How to make the habit stick in day-to-day operations

Security teams reduce exposure fastest when they standardize the acceptable login path and remove ambiguity. If employees are told to “always use the portal,” then the portal must be easy to find, easy to bookmark, and consistent across SSO, VPN, and any other remote-access entry point they use regularly.

Training should focus on a small number of verification behaviors that people can actually repeat: inspect the domain, ignore unexpected texted login prompts, and start from a trusted location instead. NHIMG’s Identity Provider and SSO Security Guide and Remote Access Identity Guide both reinforce that remote access should be protected at the portal, not improvised through inbound links.

For the same reason, the weakest control is allowing users to make exception-driven choices during a suspicious login flow. Once a texted link is accepted as normal, the user has already lost the most important security decision point, which is whether the session should have been initiated at all.

Risk and Threat Considerations

Texted login links are attractive to attackers because they collapse urgency, familiarity, and credential entry into one interaction. If a user is conditioned to expect a prompt from IT, a fake SSO or VPN page can harvest both the password and the second factor, then hand the attacker a live session before the fraud is obvious.

Failure mechanism: The user follows an untrusted link to a lookalike portal, then enters credentials or MFA data into an attacker-controlled page that relays or reuses the authentication result.

Impact: The attacker can obtain account access, establish persistent session footholds, and use the trusted remote access path to move into corporate systems or sensitive data.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS, NIST SP 800-63, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP ASVS V10 — OAuth and OIDC SSO login links rely on OAuth/OIDC authentication flows.
Recommendation — Require users to start OIDC login from trusted portals and validate redirect destinations.
NIST SP 800-63 Digital Identity Guidelines Phishing-resistant authentication and verifier binding directly address texted login-link attacks.
Recommendation — Enforce phishing-resistant authenticators and restrict login initiation to trusted channels.
CIS Controls v8 CIS-6 — Access Control Management Reducing link-driven login exposure depends on controlling approved access paths.
Recommendation — Limit access to approved portals and remove ad hoc remote-login entry points.
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Employee SSO and VPN access depend on strong user authentication at the real entry point.
IA-5 — Authenticator Management Phishing risk drops when authenticators and codes are managed to resist replay and theft.
Recommendation — Enforce strong user authentication at the approved portal before granting session access. Use authenticator controls that resist capture and replay from fake login pages.

Practitioner Guidance

What to prioritise: Protect the highest-value entry points first, meaning the portal users should already know, not the link they receive in a message. If SSO and VPN both exist, make the approved path obvious and uniform so employees are never forced to guess which message is legitimate.

What to verify: Confirm that phishing-resistant MFA is enforced on the real entry points, that bookmarked URLs resolve to the expected domain, and that help desk or recovery processes do not reintroduce text-message trust. Workforce Identity Security Guide is a useful companion for the broader control pattern around SSO, federation, and MFA hardening.

Practitioner takeaway: The best defense is not teaching people to detect every fake link, it is designing access so a text message can never be the trusted starting point for authentication.