TL;DR: Axiad says phishing resistance is now a top priority because IDSA reported 84% of organisations had an identity-related breach in the past year, with phishing the most common breach type at 59%; legacy MFA and siloed IAM leave exploitable inconsistencies.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Why Phishing-Resistant MFA is Critical in 2023, And How CBA Can Help”.
Key questions
Q: What breaks when phishing-resistant MFA is not in place for regulated systems?
A: When phishing-resistant MFA is missing, a single phishing message can expose authenticated access paths that regulators expect to be stronger.
Q: Why do phishing-resistant MFA methods reduce account takeover risk more than codes or SMS?
A: They bind the credential to the legitimate domain, so a fake login page cannot capture a reusable secret.
Q: How can security teams tell whether their phishing-resistant MFA model is actually compliant?
A: They need to test whether the authenticators, directories, and policy services remain available without external cloud access and still support the required user and admin flows.
Practitioner guidance
- Map every authentication path Inventory primary login, step-up, recovery, reset, and admin access flows so you can see where phishable methods still exist.
- Eliminate phishable MFA methods on sensitive access Remove SMS and other interceptable factors from privileged and high-risk user journeys before attackers can target them.
- Standardise phishing-resistant controls across IAM systems Apply the same authentication policy across legacy and modern identity platforms so one weaker system does not undermine the rest.
Bottom line: Phishing-resistant MFA is only as strong as the weakest identity path, and legacy recovery flows often remain the real exposure.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phishing resistance fails as a programme if it is only partially deployed. The article’s central warning is not that MFA is obsolete, but that inconsistent MFA creates false assurance. Legacy IAM estates often mix phishable factors, modern authenticators, and recovery exceptions, which means the weakest path defines the control outcome. Practitioners should treat authentication consistency as an identity governance requirement, not an implementation detail.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: How should IAM teams govern certificates for both users and machines?
A: They should use separate policy logic for human users, devices, servers, and service identities, even if all of them authenticate with certificates. Each class has a different lifecycle, different trust boundary, and different revocation urgency. Without that separation, a single certificate policy can create mismatched access duration and hidden standing trust.
👉 Read our full editorial: Phishing-resistant MFA exposes the gaps in legacy IAM design