Usually yes, when phishing resistance and device binding matter most. Passkeys offer stronger assurance, while OTPs and magic links can still be useful as transitional methods or lower-assurance alternatives in a phased customer IAM rollout.
Why passkeys are the stronger default for sign-in
Passkeys change the assurance model. They bind authentication to a device and use public-key cryptography, so the user is not typing a shared secret that can be phished, replayed, or relayed. That makes them a better default when the goal is to reduce account takeover rather than simply add a second step to login.
OTPs and magic links still solve real problems, especially in staged rollouts, but they are weaker as primary assurance methods because they usually depend on a channel that can be intercepted, forwarded, or socially engineered. If the main objective is phishing resistance, passkeys are the cleaner control choice.
For the underlying assurance model, NIST SP 800-63 Digital Identity Guidelines are the most direct external reference for phishing-resistant authentication and authenticator assurance. If you are designing a customer journey around stronger sign-in, Passwordless and Passkeys Guide is the most relevant internal explainer for rollout and recovery choices.
Where OTPs and magic links still fit
OTPs and magic links are usually best treated as transitional or fallback methods, not the target state. They can reduce friction when a population is not yet ready for passkeys, when device support is inconsistent, or when a product needs a lower-assurance recovery path while a stronger method is being introduced.
The trade-off is that convenience comes with a narrower trust margin. OTPs rely on the security of the delivery channel and the user’s ability to recognise a fraudulent prompt. Magic links also shift risk into email or link-handling workflows, which are often less resistant to phishing, mailbox compromise, forwarding, and session hijack scenarios.
When teams need a broader comparison across MFA methods, MFA Guide is the best internal starting point because it places passkeys, OTPs, SMS, and other methods on the same assurance spectrum. For workforce contexts, Workforce Identity Security Guide adds the practical link between phishing resistance, help-desk recovery, and session theft.
How to decide what should be primary, fallback, or temporary
The right decision is usually not “passkeys or nothing.” It is “what should carry the highest assurance in this journey, and what should remain available only for recovery or transition?” In a phased customer IAM rollout, passkeys can become the preferred sign-in method while OTPs or magic links stay available for onboarding exceptions, account recovery, or users whose devices cannot yet support them.
That sequencing matters because authentication strength is only useful if recovery is not the weakest part of the system. A strong primary method paired with a weak reset path can still be defeated through help-desk abuse, mailbox compromise, or takeover of a recovery channel. The control decision is therefore about the whole authentication path, not just the first login.
For deployment guidance, Identity Provider and SSO Security Guide is useful where passkeys sit alongside federation, session controls, and recovery processes. For standards-based sign-in strength, the NIST guidance above is the clearest external anchor for deciding when a method is genuinely phishing-resistant.
Risk and Threat Considerations
Using OTPs or magic links as the primary method leaves more room for phishing, relay attacks, channel interception, and mailbox compromise. Those risks become more material when the account protects money movement, support workflows, sensitive personal data, or administrative access.
Failure mechanism: An attacker captures or redirects the one-time code or magic link, then reuses it before it expires or exploits a weak recovery path to complete account takeover.
Impact: The organisation gets a login method that appears simple for users but still permits credential theft, session abuse, and avoidable support-channel compromise at scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authenticators and assurance levels directly govern passkey-vs-OTP choice. |
| Recommendation — Use phishing-resistant assurance requirements to prefer passkeys over shared-code login methods. | ||
| NIST CSF 2.0 | PR.AA-05 — Authenticator Management | Authentication strength and authenticator choice are central to this sign-in method decision. |
| Recommendation — Adopt phishing-resistant authenticators and retire weaker login methods where risk is material. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | OTP and passkey handling both depend on authenticator lifecycle and protection. |
| Recommendation — Manage authenticator issuance, rotation, and recovery so fallback methods do not weaken assurance. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is fundamentally about choosing stronger access controls for sign-in. |
| A.8.5 — Secure authentication | Passkeys, OTPs, and magic links are all authentication mechanisms covered by this control area. | |
| Recommendation — Set access-control policy to favour phishing-resistant authentication for sensitive accounts. Specify secure authentication methods and limit weaker methods to transitional or exception cases. | ||
Practitioner Guidance
What to prioritise: Make passkeys the preferred path for any population where phishing resistance and device binding materially reduce account-takeover risk. Keep OTPs and magic links as migration aids or exception paths, not as the long-term assurance baseline.
What to verify: Confirm that recovery, reset, and help-desk workflows are at least as strong as the primary sign-in method. If users can bypass a passkey through a weak recovery channel, the overall assurance level is still low.
Decision rule: If the account can trigger financial, administrative, or high-trust actions, choose the strongest phishing-resistant option first and then constrain fallback methods to the narrowest possible scope.
Practitioner takeaway: Passkeys are the better default when security matters, but the real test is whether your recovery and fallback paths preserve the same security intent instead of undoing it.
Related resources from NHI Mgmt Group
- When should organisations prioritise passkeys over legacy second-factor methods?
- How should organisations decide whether to prioritise passkeys over passwords?
- Should organisations prioritise reducing secret reuse over faster scanning?
- When should organisations prioritise entitlement reduction over secret rotation?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org