Call NowFree Quote
Cybersecurity

Passkeys and Phishing-Resistant MFA: What Perth Businesses Should Know

Multi-factor authentication is one of the most effective security controls a business can put in place - but not every form of MFA offers the same protection. Attackers have adapted, and some of the most common MFA methods can now be bypassed with the right phishing technique. Passkeys and other phishing-resistant methods close that gap.

Quick Recap: Why MFA Matters

MFA requires a second proof of identity beyond a password - something you have or something you are, not just something you know. It's widely cited as one of the single most effective controls against account takeover, which is why it's a baseline expectation from insurers, clients, and frameworks like the Essential Eight.

Not All MFA Is Equal

SMS codes

A one-time code sent by text message. It's better than nothing, but it's the weakest common form of MFA - vulnerable to SIM-swapping and, more relevantly today, to real-time phishing pages that simply ask the victim to type the code into a fake login screen as it arrives.

App-based authenticator codes

A code generated by an app like Microsoft Authenticator. More secure than SMS, but still vulnerable to the same real-time phishing technique - if a victim is tricked into entering the code on a fake site, the attacker can use it within the short validity window.

Push notification approval

A prompt sent to your phone to approve or deny a login. Convenient, but vulnerable to "MFA fatigue" attacks, where an attacker sends repeated prompts hoping the user eventually taps approve out of frustration or habit.

Phishing-resistant MFA (FIDO2 / passkeys)

This is a different category entirely. Rather than a code that can be intercepted or a prompt that can be approved by mistake, phishing-resistant MFA uses cryptographic keys tied to the specific website or service being logged into. Even if a user is tricked into visiting a perfect fake login page, the credential simply won't work there - it's bound to the real site, not just to the user.

Passkeys are the most common consumer-facing implementation of this - stored on a device or a hardware security key, and increasingly supported by Microsoft 365, Google Workspace, and major business platforms.

Is This Realistic for a Small Business?

For most Perth SMBs, a full move to passkeys everywhere isn't a same-week project, but it's increasingly practical to roll out in stages:

  • Start with the highest-value accounts - admin and finance accounts, email administrators, and anyone with access to sensitive client data.
  • Use what's already available in your existing platform - Microsoft 365 and Google Workspace both support passkeys natively now, so for many businesses it's a configuration change rather than a new purchase.
  • Move away from SMS where it's the only option today - even shifting from SMS to app-based MFA is a meaningful improvement if passkeys aren't yet practical everywhere.
  • Train staff on what to expect - passkeys feel different to use (often a device PIN, fingerprint, or face scan instead of typing a code), so a short walkthrough avoids confusion at rollout.

Where to Start

If your business still relies mainly on SMS codes or hasn't reviewed MFA methods in a while, the practical first step is identifying which accounts carry the most risk and moving those to a stronger method first, rather than treating MFA as a single one-size-fits-all setting.

Frequently Asked Questions

Is app-based MFA (like Microsoft Authenticator) enough, or do we need passkeys?

App-based codes are more secure than SMS, but they're still vulnerable to real-time phishing where a fake login page tricks someone into typing the code in as it arrives. Passkeys close that gap because the credential is tied to the real website and simply won't work on a fake one, even if someone is fooled by the page itself.

What's 'MFA fatigue' and should we be worried about it?

It's when an attacker who already has a stolen password sends repeated push notification prompts, hoping the user eventually taps approve out of frustration or habit rather than suspicion. It's a real risk with push-based MFA specifically, and it's one of the reasons phishing-resistant methods like passkeys are gaining ground.

Do we need to switch every account to passkeys at once?

No, and trying to do that in one go usually isn't realistic for a small business anyway. Start with the highest-value accounts, admins, finance, and anyone with access to sensitive client data, and expand from there once staff are comfortable with how passkeys work.

Does moving to passkeys mean buying new hardware?

Not necessarily, Microsoft 365 and Google Workspace both support passkeys natively now, so for many businesses it's a configuration change rather than a purchase. Passkeys can be stored on a device staff already have or on a hardware security key if you want an extra physical layer.

We help Perth businesses roll out stronger, phishing-resistant MFA - prioritised by risk, not a disruptive all-at-once switch.

Cybersecurity Services →

Still relying on SMS codes for MFA?

Call 0433 087 091 for a free, no-obligation conversation about upgrading your authentication.

Book a Free Consultation

For related reading, see our guides to Phishing & Staff Security Training for Perth Businesses and Common Phishing Email Tactics Targeting Perth Businesses.

Share this article