Password and SMS combinations still depend on secrets that can be stolen, intercepted, or redirected. If an attacker controls a mailbox, phone number, or session, they can capture second-factor codes and bypass the intended control. Security teams should treat those methods as stronger than passwords alone, but not as sufficient protection for sensitive or privileged access.
Why This Matters for Security Teams
Password and SMS-based factors reduce risk compared with passwords alone, but they still anchor authentication to secrets and channels that are routinely targeted. A password can be phished, reused, or recovered from a breach, while SMS codes can be intercepted through SIM swap, call forwarding abuse, malware, or compromised device access. That means the control can be bypassed without breaking cryptography or defeating policy.
This matters most when the protected asset is a privileged dashboard, admin console, mailbox, or identity provider session. In those cases, the attacker does not need every account on the network. They only need the one factor path that is easiest to redirect. NIST guidance on authentication controls in NIST SP 800-53 Rev 5 Security and Privacy Controls makes clear that stronger assurance depends on the authenticator type, not just the presence of a second step.
NHI Management Group research shows why this still matters in real environments: Ultimate Guide to NHIs — Why NHI Security Matters Now reports that 79% of organisations have experienced secrets leaks, and 77% of those incidents caused tangible damage. In practice, many security teams discover the weakness only after a mailbox takeover, SIM swap, or session hijack has already turned “MFA-enabled” into “still exploitable.”
How It Works in Practice
The practical issue is that SMS and password combinations authenticate possession of a recoverable secret or a redirectable channel, not the strength of the user session itself. If an attacker can reset the password, enroll a new device, or take control of the phone number, the second factor becomes another step in the attack path rather than a barrier. That is why current guidance increasingly prefers phishing-resistant authenticators for sensitive access, and why ISO/IEC 27001:2022 Information Security Management implementations often pair MFA with device trust, conditional access, and session monitoring.
For organisations, the implementation pattern usually looks like this:
- Use SMS only for low-risk recovery or low-impact workflows, not privileged access.
- Prefer phishing-resistant methods where the factor is bound to the origin or device, not just the phone number.
- Require step-up controls for admin actions, high-value data, and session re-authentication.
- Reduce reliance on shared recovery paths such as email reset links and help-desk overrides.
- Monitor for identity events that indicate takeover, including SIM change, mailbox forwarding rules, and anomalous session replay.
NHIMG research reinforces the operational reality: the 52 NHI Breaches Analysis shows how credential abuse often succeeds through weak lifecycle controls and over-trusted identity paths, not through one dramatic exploit. The lesson for human authentication is similar. When the second factor is delivered through a channel an attacker can intercept or redirect, the organisation is relying on reachability rather than assurance.
These controls tend to break down in environments with weak telecom governance, unmanaged BYOD devices, and broad help-desk reset authority because attackers can pivot from recovery to full session takeover without triggering a clear challenge failure.
Common Variations and Edge Cases
Tighter authentication often increases user friction and support overhead, requiring organisations to balance stronger assurance against account recovery complexity and adoption risk. That tradeoff is why some teams keep SMS in place for legacy users or low-risk populations while reserving stronger methods for admins and finance systems.
There is no universal standard for this yet, but best practice is evolving toward risk-based and phishing-resistant authentication. For high-value access, current guidance suggests treating SMS as a transitional control rather than a destination state. Passwordless or hardware-backed methods usually outperform password plus SMS because they reduce secret replay and channel hijack risk. However, they still need lifecycle discipline, device recovery planning, and session revocation when a phone, token, or enrollment path is lost.
One edge case is emergency access. Break-glass accounts may still require fallback methods, but those paths should be tightly monitored, heavily logged, and isolated from normal operations. Another is consumer-facing services, where SMS can remain acceptable for convenience if the impact of compromise is low and the organisation has strong fraud detection. For sensitive internal systems, though, password plus SMS often gives a false sense of safety. The control is present, but the assurance is weaker than teams assume.
For security leaders, the question is not whether MFA exists, but whether the factor can resist phishing, interception, and recovery abuse in the real attack path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-1 | Authentication assurance must match the risk of the protected session. |
| NIST SP 800-63 | AAL2 | SMS and passwords often fail to meet stronger authenticator assurance needs. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Secret-based access patterns mirror the same weakness seen in NHI compromise. |
| CSA MAESTRO | IAM-03 | Agent and identity governance both require stronger control over credential replay. |
| NIST AI RMF | Risk governance should account for identity compromise pathways and recovery abuse. |
Assume any reusable secret path can be intercepted and rotate toward stronger trust signals.
Related resources from NHI Mgmt Group
- When does multi-factor authentication still leave organisations exposed to account takeover?
- Why do passwordless logins still leave organisations exposed to impersonation risk?
- How should organisations move away from password-based authentication without hurting user productivity?
- Why do password-based attacks still succeed even when organisations think they are prepared?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org