Agencies should make a phishing-resistant option available in the same citizen login flow, not as a separate special process. FIDO2 security keys and passkeys can satisfy this need while SMS OTP remains an alternate factor for some users. The key is to preserve usability while ensuring the stronger method is actually available to users at the required assurance level.
Why This Matters for Security Teams
Phishing-resistant MFA at AAL2 is not just a stronger login method, it is a design constraint on the entire citizen authentication journey. Agencies have to protect against real-world credential theft while keeping access simple enough that people do not abandon the service. NIST’s identity guidance makes the baseline clear in NIST SP 800-63 Digital Identity Guidelines, while agency programs also need to account for the operational realities documented in Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs.
The main mistake is treating phishing-resistant MFA as a separate “secure users only” lane. That creates friction, increases help desk volume, and can push citizens back toward weaker recovery paths. A better pattern is to keep one login journey and offer a phishing-resistant option inside it, with clear fallbacks where policy permits. This aligns with broader resilience expectations in the NIST Cybersecurity Framework 2.0 and with the reality that identity abuse often follows convenience gaps rather than technical impossibility. In practice, many agencies discover login failure and abandonment only after rollout, rather than through intentional usability testing.
How It Works in Practice
The most reliable implementation pattern is to present one citizen login entry point and let the user choose an assurance-appropriate method without changing the service journey. At AAL2, that usually means supporting FIDO2 security keys and passkeys as phishing-resistant options, while preserving alternate approved factors for users who cannot complete registration or device binding immediately. The key is that phishing resistance is built into the same identity proofing and authentication flow, not bolted on as an exception.
Operationally, agencies should map the login path to assurance outcomes first, then map factors to those outcomes. A strong pattern is:
- Use passkeys or FIDO2 authenticators wherever supported, with clear enrollment guidance.
- Keep recovery and fallback options available, but restrict them to the minimum assurance path allowed by policy.
- Do not force a separate “high security” portal unless there is a legal or technical reason.
- Test mobile, desktop, kiosk, and low-bandwidth access paths before launch.
- Track abandonment, failed enrollment, and recovery rates as identity metrics, not just security metrics.
That approach is consistent with the control intent in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where authentication strength and account recovery have to be balanced against service availability. It also reflects the governance lessons in Top 10 NHI Issues: weak lifecycle handling and overly permissive fallback paths create exposure even when the primary control is sound. These controls tend to break down when legacy identity providers cannot support modern authenticators or when account recovery is still tied to SMS-only workflows.
Common Variations and Edge Cases
Tighter phishing-resistant controls often increase enrollment and support overhead, requiring agencies to balance assurance against accessibility and service continuity. Current guidance suggests that this tradeoff is best managed through phased rollout, not by weakening the control objective.
There is no universal standard for every citizen population yet, so agencies may need multiple approved factors during transition. Passkeys are usually the easiest phishing-resistant option for most users, but some populations still rely on shared devices, older phones, assistive technologies, or intermittent connectivity. In those cases, the login flow should remain familiar, with the strongest available method offered first and alternate paths presented only when needed.
Agencies should also treat exception handling as a governance issue, not a UX afterthought. If a user cannot register a phishing-resistant factor, the system should route them to a clearly defined alternate process, not an ad hoc manual bypass. The risk is greatest where account recovery, help desk verification, and identity proofing are handled inconsistently across programs. NHIMG’s analysis in Indian Government Breach and Microsoft Midnight Blizzard breach shows how identity weaknesses become exploitation paths when policy and execution drift apart.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | AAL2 | Defines authentication assurance and phishing-resistant authenticator expectations. |
| NIST CSF 2.0 | PR.AA | Identity authentication outcomes depend on access control and verifier strength. |
| NIST AI RMF | Supports governance of identity-related risk decisions and user impact. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Highlights identity lifecycle weaknesses and insecure fallback handling. |
| CSA MAESTRO | GOV-02 | Governance of dynamic access paths mirrors strong assurance workflow control. |
Review authentication lifecycle steps and eliminate weak bypasses, especially around recovery and enrollment.
Related resources from NHI Mgmt Group
- How should banks implement phishing-resistant authentication without breaking recovery flows?
- How should financial institutions roll out phishing-resistant MFA without breaking legacy systems?
- How should security teams implement phishing-resistant MFA for privileged SaaS access?
- How should security teams implement phishing-resistant MFA for CMMC-scoped systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org