By NHI Mgmt Group Editorial TeamBased on Axiad: “How to Adopt Phishing-Resistant MFA” (June 11, 2025)

TL;DR: Phishing remains the most likely attack for 49% of respondents, while 64% cite fear of change as the main reason they keep passwords and non-phishing-resistant MFA, according to Axiad’s 2023 State of Authentication Survey. Removing the human step is only part of the answer; authentication strategy still has to align with real IAM, rollout, and lifecycle constraints.


At a glance

What this is: This is an analysis of why phishing-resistant MFA adoption stalls when organisations try to fit it into fragmented IAM environments and change-averse operating models.

Why it matters: It matters because IAM teams cannot treat phishing resistance as a point control; they have to align authentication, lifecycle, and rollout decisions across human and non-human access paths.

By the numbers:

  • 49% of respondents said phishing is the most likely attack to happen.
  • 64% of respondents said fear of change is the top reason for holding onto passwords and non-phishing-resistant MFA.

Context

Phishing-resistant MFA is an authentication approach that removes the user-entered secret or approval step that attackers usually exploit. The governance problem is not the concept itself, but whether the identity estate, rollout model, and recovery paths can support it without breaking operations.

Axiad argues that organisations often understand the threat but still defer adoption because existing IAM estates are fragmented and change is hard to absorb. That makes this an identity design problem as much as an authentication problem, especially where different user groups and environments need different rollout paths.

The article’s core point is that removing a weak human step only works when authentication is designed to fit real lifecycle and operating constraints. For most enterprises, that means aligning phishing resistance with current IAM architecture rather than treating it as a standalone security project.


Key questions

Q: How should organisations implement phishing-resistant MFA for regulated access?

A: Start by mapping each protected system to the identity type that uses it, then choose a phishing-resistant method that fits that subject. Use passkeys for human login where appropriate, certificate-based authentication for machine or enterprise trust, and verify that enrollment, recovery, and revocation are part of the control, not afterthoughts.

Q: Why does slow adoption of phishing-resistant MFA keep organisations exposed to credential attacks?

A: Phishing-resistant MFA reduces the value of stolen passwords because the attacker still cannot complete authentication with a replayed secret. When organisations keep relying on weaker factors, they leave a large share of their access paths open to phishing and credential theft. That creates a gap between policy intent and real-world resistance, especially for high-value users and remote access.

Q: What breaks when phishing-resistant MFA is not in place for regulated systems?

A: When phishing-resistant MFA is missing, a single phishing message can expose authenticated access paths that regulators expect to be stronger. In NYDFS environments, that weak link can convert an email compromise into a compliance failure because the control is meant to reduce credential replay and prove access assurance on sensitive systems.

Q: What is the difference between certificate-based authentication and FIDO in practice?

A: Certificate-based authentication is strongest where device-bound trust and managed issuance are needed, while FIDO is often better where supported applications and user experience matter most. Many enterprises need both. The decision is less about which method is better overall and more about which one fits the access path, platform, and assurance requirement.


Technical breakdown

Why human-in-the-loop MFA remains phishable

Traditional MFA often still depends on a human action such as typing a code, approving a prompt, or entering a password plus second factor. That creates an interception point, because the attacker does not need to break the factor itself if they can manipulate the person using it. In identity terms, the control still contains a user-mediated trust event, which is where phishing succeeds. True phishing resistance therefore depends on authentication that does not ask the user to reveal or re-enter a reusable secret during the transaction.

Practical implication: map every authentication flow that still relies on user-mediated verification and treat it as phishing-exposed.

Certificate-based authentication and FIDO as control models

The article identifies two phishing-resistant patterns: certificate-based authentication backed by public key infrastructure and FIDO passkeys. Both shift trust from user-entered secrets to cryptographic proof bound to the device or authenticator, which changes the attack surface materially. Certificate-based authentication often fits established enterprise environments, while FIDO passkeys reduce friction by using hardware or built-in device capabilities. The important governance point is that both approaches must still be integrated with existing identity systems, recovery processes, and user populations.

Practical implication: choose an authentication pattern that can be operationalised across the identities you already govern, not one that only works in a greenfield model.

How identity design determines adoption speed

Adoption stalls when organisations try to treat phishing-resistant MFA as a simple replacement for passwords instead of a design change across categories of users, privilege levels, and onboarding flows. The article recommends grouping users, mapping authentication levels to those groups, and starting with higher-risk populations such as IT, finance, and executives. That is an identity governance pattern, not just a rollout tactic, because it ties authentication strength to risk and lifecycle handling. Without that mapping, the deployment becomes too broad, too slow, or too disruptive to finish.

Practical implication: sequence deployment by user category and privilege exposure so the strongest controls land where the risk is highest.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Phishing-resistant MFA fails as a point solution when identity architecture is fragmented. The article is right to push beyond technology choice and into operating model, because authentication strength cannot be separated from how identities are grouped, recovered, and administered. In most enterprises, the blocker is not cryptography but the mismatch between a stronger authenticator and a fragmented IAM estate. The practitioner lesson is that phishing resistance is an identity programme decision, not a checkbox upgrade.

Removing the human step is necessary, but the control still has to fit lifecycle reality. Certificate-based authentication and passkeys both change the trust model, but neither removes the need to provision, recover, revoke, and transition identities cleanly. That matters across human IAM and broader identity governance, because the best authenticator still fails if onboarding, device replacement, or offboarding is poorly designed. The implication is that authentication strategy has to be built alongside lifecycle governance, not after it.

Fear of change is itself an identity risk signal. When 64% of respondents say change is the main barrier, the issue is usually not user reluctance alone but the absence of a migration path that fits real operations. That means the programme lacks a credible bridge between legacy MFA, higher-risk groups, and new authenticator classes. Practitioners should read resistance as evidence that the current authentication model has not been translated into workable identity operations.

Phishing-resistant MFA only becomes durable when it is mapped to risk-tiered user groups. The article’s sequencing advice reflects a broader governance truth: stronger authentication succeeds when it is scoped to the populations that create the most exposure first. IT, finance, and executive access are not just high-value targets, they are the places where identity design decisions have the largest blast radius. The practical conclusion is to anchor rollout in privilege and business criticality, not in equal treatment across all users.

Phishing-resistant MFA is now a baseline expectation for modern IAM strategy. The article shows that the question is no longer whether the technology exists, but whether organisations are willing to align process, policy, and user experience around it. That shifts the conversation from product selection to programme design. For practitioners, the real work is consolidating fragmented authentication patterns into a governed model that can survive scale.

From our research library:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

What this signals

Identity design is the gating factor for phishing-resistant MFA. Organisations that focus only on the authenticator miss the real dependency: group design, lifecycle support, and recovery handling. Once those controls are weak, the strongest phishing-resistant method still becomes difficult to deploy at scale.

Risk-tiered rollout is the most practical adoption pattern. Starting with privileged groups gives teams the clearest security return while exposing support, onboarding, and exception handling issues early. That sequencing also avoids the common failure mode where a broad rollout creates operational resistance before the control proves itself.

Authentication modernisation should be treated as an IAM consolidation exercise. Phishing-resistant MFA becomes more durable when the organisation uses it to rationalise fragmented identity systems rather than simply layering another factor onto them. For practitioners, that makes this a programme design decision as much as a security one.


For practitioners

  • Define user cohorts by risk and function Split identities into operationally meaningful groups such as IT, finance, executives, and standard staff, then assign stronger authentication first to the groups with the highest exposure and privilege.
  • Inventory every human-mediated MFA flow Locate any login path that still depends on a typed code, push approval, or reusable secret, because those flows remain susceptible to phishing and should be prioritised for replacement.
  • Extend existing IAM instead of replacing it Plan phishing-resistant MFA as an overlay to current IAM and identity provider architecture so rollout does not require a rip-and-replace migration.
  • Sequence rollout by privilege exposure Start with administrators, finance, and executive access, then move outward once recovery, support, and user training are stable enough to sustain the change.
  • Prepare onboarding and recovery before cutover Document device replacement, authentication recovery, and day-one user education before enforcing phishing-resistant methods so support does not become the failure point.

Key takeaways

  • Phishing-resistant MFA is not blocked by the technology alone. It is blocked when authentication strategy does not fit the organisation’s existing identity design and operating model.
  • A strong authenticator still fails if rollout, recovery, and user grouping are not aligned to privilege and risk.
  • The practical path is to phase deployment by high-risk cohorts and treat authentication modernisation as part of IAM governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article is about replacing phishable authentication with resistant methods.
NHI-10 — Human Use of NHIThe article focuses on removing human interaction from the authentication step.
Recommendation — Replace user-mediated login steps with phishing-resistant authentication patterns and phase out phishable MFA. Design authentication flows so users do not expose secrets or approval actions to attackers.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article centres on authenticator choice, rollout, and lifecycle support.
Recommendation — Use IA-5 to govern authenticator issuance, replacement, and recovery for phishing-resistant MFA.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPhishing-resistant MFA is part of how access is authorised and controlled.
Recommendation — Align authentication strength with access entitlements and privilege tiers under PR.AA-05.
NIST SP 800-63SP 800-63B — AuthenticationThe article is about authentication methods and phishing-resistant assurance.
Recommendation — Use SP 800-63B to evaluate whether authentication methods are resistant to phishing.

Key terms

  • Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
  • Certificate-based authentication: A method of proving identity using a cryptographic certificate and the associated private key rather than a reusable password. In identity programmes, it raises the bar for theft and replay because the secret is bound to lifecycle, issuance, and revocation control.
  • FIDO passkey: A passwordless authentication credential based on the FIDO standard. It uses cryptographic keys stored on a user device and often biometric confirmation to verify the user, reducing dependence on secrets that can be phished, reused, or guessed.
  • Identity Fragmentation: Identity fragmentation is the condition where different parts of an infrastructure estate use separate trust models, credentials, and policy systems. In hybrid environments, this breaks unified governance because access, logging, and revocation no longer line up across cloud, data center, and colocated resources.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org