Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response How should security teams reduce MFA risk when…
Threats, Abuse & Incident Response

How should security teams reduce MFA risk when SMS or VoIP delivery depends on third-party providers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 10, 2026 Domain: Threats, Abuse & Incident Response

Security teams should treat SMS and VoIP delivery as a weaker trust boundary, not a primary control. Use phishing-resistant authentication where possible, such as hardware security keys or other possession factors that do not depend on intercepted communications. Also review third-party exposure, limit what metadata is retained, and ensure incident playbooks cover credential revocation and customer notification.

Why SMS and VoIP MFA Are a Weaker Trust Boundary

When MFA depends on SMS or VoIP, the security decision is only as strong as the telecom path that delivers the code. That path can be redirected, delayed, intercepted, or undermined by account takeover at the provider layer, number porting abuse, call forwarding changes, or service outages. For that reason, these factors should be treated as a fallback, not the primary safeguard for high-value access.

The practical issue is not that SMS or VoIP is always broken; it is that the trust boundary sits outside the organisation’s direct control. If a third-party carrier, messaging service, or virtual number platform is the delivery mechanism, the organisation inherits dependency risk, visibility gaps, and inconsistent recovery timing. Security teams should also assume that phone-based factors may be weaker for privileged users, administrators, and any workflow where account recovery can unlock broader access. OWASP Non-Human Identity Top 10 is useful here because it frames why dependency on external authentication pathways deserves control scrutiny, even when the user is human.

In practice, teams usually discover the weakness after a provider-side event, not during design review.

How Teams Should Reduce the Dependency in Practice

The cleanest reduction strategy is to move from delivery-dependent factors to phishing-resistant authentication for the accounts that matter most. Hardware security keys, device-bound credentials, and other possession factors that do not rely on a text message or voice call give you a stronger control surface because the proof of possession stays with the authenticating device rather than the telecom route. That matters most for administrators, help desk flows, finance systems, and any account that can reset other credentials.

Where SMS or VoIP must remain available, security teams should narrow its role and reduce blast radius. That means limiting it to low-risk recovery paths, restricting which users can enroll it, and making sure enrollment changes are themselves protected by stronger assurance. It also means reviewing what the provider can see or retain, because metadata such as phone numbers, routing information, and delivery logs can become an exposure point even when the message content is minimal. The strongest programmes also monitor provider changes and unusual recovery requests as security events, not just support tickets.

A useful operating model is to align this control with broader identity governance rather than treating it as a messaging problem. Current guidance suggests that organisations should pair stronger authentication with lifecycle discipline: remove stale factors, rotate recovery options when risk changes, and ensure incident playbooks can revoke access quickly when a phone number or voice channel is suspected to be compromised. 52 NHI Breaches Analysis is relevant because it reinforces the broader pattern that weak lifecycle control and insufficient visibility often turn an access dependency into an incident path.

  • Prefer phishing-resistant factors for privileged and high-impact accounts.
  • Keep SMS or VoIP only as a limited fallback where business need is explicit.
  • Protect factor enrollment and recovery with stronger verification than the factor itself.
  • Review telecom and identity-provider logs for number changes, reroutes, and recovery abuse.

These controls tend to break down in environments with heavy contractor turnover, shared support workflows, or outsourced recovery processes because the organisation cannot reliably verify who changed the factor or why.

Where SMS MFA Breaks Down Most Often

Tighter MFA policy often increases user friction and support load, so teams need to balance account recovery convenience against assurance. The hardest edge cases are not ordinary logins; they are password resets, SIM swaps, delegated admin access, and any workflow where a phone number becomes the recovery anchor for multiple systems. In those scenarios, a weak factor can silently become the highest-value factor in the stack.

There is also a real trade-off between resilience and assurance. VoIP and SMS can look operationally convenient because they are familiar and widely available, but that convenience disappears quickly when the provider has an outage, the user is roaming, or the number is repurposed. Best practice is evolving toward treating phone-based delivery as a temporary compatibility bridge rather than a long-term security design. For teams looking at the broader governance picture, the State of Non-Human Identity Security report is a reminder that visibility gaps and third-party dependency are recurring causes of identity compromise, even outside classic human login flows.

Security teams should be especially cautious when recovery mechanisms can bypass the strongest login factor. That is where the actual control failure usually sits.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementPhone-based MFA depends on credential and recovery-path trust boundaries.
NHI-03 — Identity Lifecycle and OffboardingNumber changes and recovery paths need lifecycle control and revocation.
Recommendation — Replace weak delivery factors with phishing-resistant authentication for sensitive accounts. Revoke stale recovery factors quickly and re-verify factor enrollment after risk changes.
NIST CSF 2.0PR.AA-03 — Identity Management and AuthenticationStrong authentication should protect access with appropriate assurance strength.
DE.CM-08 — Monitoring for Unauthorized AccessProvider-side changes and recovery abuse require detection and logging.
Recommendation — Apply stronger authentication methods for high-impact accounts and restrict fallback factors. Monitor number-change and recovery events for suspicious authentication activity.
CIS Controls v86.3 — Require MFA for Externally Exposed ApplicationsExternally reachable authentication should use stronger MFA than SMS or VoIP.
Recommendation — Use stronger MFA for exposed access paths and avoid SMS as the primary factor.
NIST Zero Trust (SP 800-207)AC-6 — Least PrivilegeWeak factors become more dangerous when they protect privileged access.
Recommendation — Limit privileged access so a compromised phone factor cannot unlock broad control.

Practitioner Guidance

What to prioritise: Start with the accounts that can reset credentials, approve payments, or administer other users. If SMS or VoIP is still required for them, treat that as a temporary exception and require a stronger second factor for enrollment and recovery.

What to verify: Confirm who controls the phone-number lifecycle, how number changes are authenticated, and whether your support process can detect porting, forwarding, or provider compromise before access is granted. If you cannot explain that chain end to end, the factor is not trustworthy enough for sensitive access.

Decision rule: If the phone factor is the only thing standing between an attacker and a privileged or recoverable account, replace it first rather than layering more monitoring around it. Monitoring helps, but it does not restore trust in the delivery path.

Practitioner takeaway: The key judgement is to design for the loss of the telecom channel in advance, because the safest MFA programme is the one that still holds when the number, carrier, or recovery path does not.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org