Pro User
Zeitspanne
explore our new search
​
Microsoft Entra ID: Use FIDO2 Keys Now
Microsoft Entra
14. Aug 2026 20:28

Microsoft Entra ID: Use FIDO2 Keys Now

von HubSite 365 ĂĽber Jonathan Edwards

No-Faffing Managed IT Support & Cyber Security Support. Made in Yorkshire, built for the UK.

Microsoft expert: device code phishing bypasses MFA and passkeys on tenants; Entra Conditional Access is the fix

Key insights

  • Device code phishing
    Attackers use a real-time proxy to relay sign-ins and capture authenticated sessions even after the user completes MFA.
    That lets attackers access accounts without stealing passwords or creating a fake login page.
  • MFA limits
    Traditional MFA methods (SMS, TOTP codes, push approvals) can be relayed and bypassed by these proxy attacks.
    MFA still helps, but it is not enough alone against modern phishing methods.
  • FIDO2 and passkeys
    FIDO2 security keys, device-bound passkeys, and Windows Hello for Business use cryptographic proofs tied to the real site, making relay attacks much harder.
    Prefer these phishing-resistant authenticators wherever possible.
  • Conditional Access
    Use Conditional Access to require compliant or hybrid‑joined devices and evaluate device state, location, and risk before granting access.
    Device-based checks limit what a stolen session or relayed token can do.
  • MFA fatigue and number matching
    Attackers also exploit repeated push prompts and user fatigue to gain approvals.
    Number matching and clearer prompts reduce blind approvals, but cryptographic methods remain the stronger defense.
  • Practical steps
    Avoid relying on SMS or push-only MFA; deploy FIDO2 or device-bound passkeys and enforce Conditional Access and device compliance.
    If you see suspicious prompts, check recent activity, remove unknown security info, revoke sessions, and change credentials.

Microsoft Entra - Microsoft Entra ID: Use FIDO2 Keys Now

Keywords

phishing-resistant authentication, passkeys vs MFA, FIDO2 security keys, hardware security keys, MFA bypass protection, passwordless authentication solutions, conditional access policies, preventing account takeover