TL;DR: Legacy MFA is increasingly vulnerable to phishing and MFA fatigue, and Axiad argues organisations should adopt a pragmatic, grouped rollout that combines certificate-based authentication and FIDO for different user populations, while aligning with the White House OMB zero-trust memo and NIST AAL3 expectations. The practical issue is no longer whether phishing-resistant MFA is needed, but how to deploy it without creating new operational silos.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Phishing-Resistant Authentication for Everyone”.
Key questions
Q: What should teams do when phishing-resistant MFA is in place but fraud still occurs?
A: Teams should inspect the identity journey around the MFA control, especially recovery, enrolment, help desk intervention, and account takeover escalation.
Q: Why do legacy MFA methods still leave organisations exposed to phishing?
A: Legacy MFA often depends on transferable factors such as SMS codes or push approvals, which attackers can intercept through SIM swapping or man-in-the-middle techniques.
Q: What do teams get wrong about phishing-resistant MFA?
A: They often measure success by the presence of a strong factor instead of the absence of weaker bypasses.
Practitioner guidance
- Define user risk cohorts Group end users by role and exposure before selecting authenticators so baseline, knowledge, compliance, IT and security, and executive populations can follow different assurance paths.
- Map assurance to use case Assign certificate-based authentication, FIDO, or a combined path to each cohort based on the systems they access and the devices they use most often.
- Run authentication as a lifecycle programme Track rollout status, renewals, and expiry handling so credentials move cleanly from old methods to new ones without creating unmanaged overlap.
Bottom line: Phishing-resistant MFA is now a practical rollout challenge, not a theoretical control choice, because legacy MFA is increasingly exposed to phishing and fatigue attacks.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phishing-resistant MFA is now a governance sequencing problem, not a technology preference. The article is right to move the discussion away from whether phishing-resistant authentication is needed and toward how to deploy it across real user populations. The hard part is not the control itself but the operational model that lets different groups move at different speeds without lowering assurance. Practitioners should treat rollout design as part of identity governance, not an afterthought.
A few things that frame the scale:
- Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.
A question worth separating out:
Q: Why do organisations still need certificate-based authentication when FIDO exists?
A: Because FIDO is not designed to cover every identity context. Certificate-based authentication still matters for device identity, workload authentication, and environments that depend on PKI and certificate lifecycle control. In practice, CBA fills gaps where user-centric passwordless methods do not reach, especially across managed endpoints and integrated enterprise platforms.
👉 Read our full editorial: Phishing-resistant MFA needs a pragmatic rollout model now