Join our Newsletter — 33% off our NHI Course
Home FAQ Authentication, Authorisation & Trust How should security teams reduce identity risk when…
Authentication, Authorisation & Trust

How should security teams reduce identity risk when MFA still relies on passwords and SMS codes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Authentication, Authorisation & Trust

Security teams should treat passwords and SMS codes as weak proof of identity, especially where phishing, social engineering, and device compromise are common. Stronger MFA binds authentication to a trusted device and a biometric factor, so the user proves who they are instead of just proving knowledge or possession. For sensitive access, add liveness checks to reduce replay and impersonation risk.

Why This Matters for Security Teams

When MFA still depends on passwords and SMS codes, identity assurance remains anchored to factors that are easy to phish, intercept, or social-engineer. That leaves a gap between policy and real-world resistance to takeover. NIST Cybersecurity Framework 2.0 treats identity assurance as part of a broader risk posture, not a checkbox, which is why stronger methods need device binding and phishing-resistant factors.

This matters most where access protects admin consoles, CI/CD, cloud control planes, and sensitive customer data. SMS-based flows can fail through SIM swap, message forwarding, malware, or number recycling, while passwords are still reused, guessed, and captured in credential stuffing campaigns. NHIMG research on the Ultimate Guide to NHIs shows how weak credential handling and poor rotation quickly expand exposure across modern environments.

In practice, many security teams discover the weakness only after an account takeover, not during MFA design.

How It Works in Practice

The most effective response is to move from “something the user knows or receives” toward authentication that is tied to a trusted device and a stronger proof of presence. That usually means phishing-resistant MFA, such as passkeys or hardware-backed authenticators, plus biometric or local unlock where appropriate. The goal is not simply more factors, but stronger binding between the session and the legitimate user.

Security teams should also reduce reliance on passwords as the primary gate. If passwords remain in the flow, they should be treated as a fallback rather than the core assurance layer. For high-value access, add liveness checks, step-up authentication, and risk-based prompts when the request comes from a new device, unusual location, or sensitive workflow. NIST guidance on identity and access assurance supports this direction, but implementation detail varies by environment. The NIST Cybersecurity Framework 2.0 is useful here because it frames identity controls as ongoing risk management, not a one-time enrollment task.

  • Prefer phishing-resistant authenticators over SMS codes for privileged and remote access.
  • Bind sessions to managed devices where possible, especially for administrators and developers.
  • Use biometrics or device-local unlock to strengthen user presence without exposing a reusable secret.
  • Apply step-up checks for sensitive actions instead of forcing every request through the same friction.
  • Monitor for replay, token theft, SIM swap, and impossible-travel patterns as part of identity telemetry.

NHIMG guidance in the Ultimate Guide to NHIs also underscores a broader point: once credentials are easy to copy or replay, the control loses value quickly. These controls tend to break down in bring-your-own-device environments with weak device attestation because the organisation cannot reliably tie the factor to a trusted endpoint.

Common Variations and Edge Cases

Tighter authentication often increases user friction, help desk load, and device management overhead, so organisations have to balance assurance against operational disruption. That tradeoff is real, especially for mixed workforces, contractors, and legacy applications that cannot yet support modern authenticators.

Current guidance suggests prioritising phishing-resistant MFA first for administrators, finance, developers, and remote access, then expanding to the rest of the estate in phases. There is no universal standard for every application path yet, so organisations often need a hybrid model: strong MFA for privileged actions, conditional access for routine use, and exception handling for systems that only support SMS or password-based flows today. In those cases, compensation is essential, including tighter session lifetimes, stronger monitoring, and rapid account recovery controls.

One NHIMG pattern worth noting is that weak identity controls often coexist with poor secrets hygiene, which amplifies the blast radius when MFA is bypassed. The 2024 ESG Report: Managing Non-Human Identities found that 72% of organisations have experienced or suspect a breach of non-human identities, a reminder that identity risk rarely stays isolated. The same lesson applies to human access: if MFA is weak at the edge, attackers often move quickly to higher-value accounts and long-lived secrets.

For teams with legacy constraints, the practical endpoint is not perfect purity. It is reducing the number of accounts that still depend on passwords and SMS, then making every remaining exception visible, time-bound, and reviewable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AAIdentity assurance and strong auth are core to reducing takeover risk.
NIST SP 800-63AAL2AAL guidance explains why SMS and passwords are weak for higher-risk access.
NIST Zero Trust (SP 800-207)§3.1Zero Trust requires stronger verification before granting access.
OWASP Non-Human Identity Top 10NHI-03Weak credential patterns and reuse increase identity compromise exposure.
NIST AI RMFRisk framing helps teams choose stronger identity controls for sensitive workflows.

Use phishing-resistant authenticators for elevated assurance and reserve SMS for fallback only.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org