Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› How should organisations choose between SMS-based MFA and…
Authentication, Authorisation & Trust

How should organisations choose between SMS-based MFA and phishing-resistant authentication methods?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Authentication, Authorisation & Trust

Organisations should treat SMS-based MFA as a lower assurance option, not a final destination. It can still help reduce risk compared with passwords alone, but SIM swap attacks, interception, and phishing make it unsuitable for high-risk access. For stronger protection, prioritise phishing-resistant methods such as FIDO2 hardware keys or biometric authentication for critical users and sensitive systems.

Why SMS MFA is a stepping stone, not the end state

SMS can still raise the bar above passwords alone, but it remains vulnerable to adversary-in-the-middle phishing, SIM swap fraud, and code interception. That makes it a weaker fit for privileged users, remote admin paths, and any workflow where a stolen second factor could immediately expose sensitive systems or data. Stronger methods reduce both takeover risk and reliance on recoverable phone numbers.

For organisations that are still using SMS, the practical question is not whether it has value at all, but where its residual risk is acceptable. For low-sensitivity use cases it may be a transitional control, but for high-value access it should be treated as an interim measure while phishing-resistant methods are deployed.

What makes phishing-resistant authentication different

Phishing-resistant methods bind the authentication event to the intended site or device so the user is not simply typing or relaying a reusable code. FIDO2 security keys and passkeys are the clearest examples because they are designed to resist credential replay and code theft. In practice, that changes the attacker problem from “steal a code” to “compromise the actual authenticator or the enrolled device.”

Biometric authentication can also be part of a stronger sign-in experience, but it is best understood as a local unlock factor rather than a stand-alone guarantee of phishing resistance. What matters operationally is the full method chain, including device binding, recovery paths, and whether the method still works when the user is pushed through a fake login page.

How to choose the right method for each access tier

The cleanest decision rule is to align the method with the value of the access. SMS may be acceptable for temporary or lower-risk populations where a rapid rollout matters more than maximum assurance. Phishing-resistant methods should be the default for administrators, executives, finance teams, and any account that can change security settings, access sensitive records, or approve transactions.

Rollout should also account for recovery. If the fallback path to reset a passkey or hardware key relies on weak help desk processes or SMS again, the overall assurance drops back to the weakest step. Organisations get better results when they pair strong primary authentication with tight enrollment, recovery, and exception handling.

Risk and Threat Considerations

SMS MFA fails when the defender assumes a one-time code is equivalent to possession of a secure second factor. Attackers can phish the code in real time, redirect a phone number through SIM swap, or intercept messages through device compromise and carrier abuse. The result is that the second factor still protects against some bulk attacks, but it does not reliably stop targeted account takeover.

Failure mechanism: The attacker captures or reroutes the SMS challenge, then reuses the code or session before it expires. If the account also has weak recovery, the attacker may convert a single intercepted sign-in into persistent access.

Impact: High-value accounts can be taken over even when MFA is “enabled,” which creates a false sense of security and leaves privileged access, sensitive data, and downstream systems exposed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesPhishing-resistant authenticators and assurance levels directly govern MFA choice.
Recommendation — Use phishing-resistant authenticators for high-risk access and map sign-in strength to assurance level.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Employee and admin sign-in assurance is central to choosing stronger MFA.
IA-5 — Authenticator ManagementSMS codes, hardware keys, and passkeys all depend on authenticator lifecycle and recovery.
Recommendation — Require stronger authentication for organizational users with elevated access. Manage enrollment, rotation, revocation, and recovery for all authenticators.
ISO/IEC 27001:2022A.5.17 — Authentication informationThe topic concerns protecting and using authentication material and recovery paths.
Recommendation — Protect authentication information and limit weak fallback recovery paths.
OWASP ASVSV6 — AuthenticationThe question compares authentication methods and their assurance properties.
Recommendation — Set higher authentication requirements for sensitive users and privileged actions.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationWeak second factors and phishing-eligible sign-in flows are authentication weaknesses.
Recommendation — Prefer phishing-resistant authenticators over SMS for critical access.

Practitioner Guidance

What to prioritise: Use phishing-resistant authentication first for privileged, remote, and high-impact access, then phase SMS out where the blast radius justifies the migration cost. A good transition plan starts with the highest-risk accounts, not the easiest ones.

What to verify: Check that the chosen method is truly bound to the user’s intended device or authenticator, and that recovery does not silently downgrade assurance. If a help desk reset or fallback SMS path can re-enable access on its own, the control is weaker than the login method suggests.

Common mistake: Treating “MFA enabled” as a complete answer. Assurance depends on the specific factor, the recovery route, and the phishing resistance of the end-to-end flow, not just the presence of a second prompt.

Practitioner takeaway: SMS is better than passwords alone, but it is a compromise control, not a durable security destination; reserve it for lower-risk cases and move critical access to phishing-resistant methods as soon as practical.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org