You Have MFA. But Is It the Right MFA?
For years, one of the most important pieces of cybersecurity advice has been simple:
Turn on Multi-Factor Authentication.
That advice still stands. But attackers have adapted, and simply saying “we have MFA” is no longer quite enough.
Microsoft is changing authentication
Microsoft is moving away from SMS and voice-based MFA and towards stronger methods such as passkeys, Windows Hello and FIDO2 security keys.
From 1 February 2027, Microsoft will stop providing SMS and voice authentication for most users.
For many businesses, that may not be a major issue. Most well-managed Microsoft 365 environments already use the Microsoft Authenticator app.
But there is still an important question:
What type of authentication are you actually using?
Not all MFA is equal
A Microsoft Authenticator approval is far better than relying on a password alone.
However, modern phishing attacks can sometimes trick users into completing an MFA request on a fake login page, allowing an attacker to capture an authenticated session.
That is why Microsoft is increasingly pushing phishing-resistant authentication.
Passkeys and Windows Hello work differently. They are tied to the genuine service being accessed, making them much harder to steal or replay through a fake website.
Does Microsoft Authenticator need replacing?
No.
Microsoft Authenticator remains a strong and widely used security tool.
However, the same app can now be used in different ways. A conventional approval prompt is not the same as using a passkey.
The direction of travel is clear: Microsoft wants businesses to move towards stronger, phishing-resistant authentication.
What should businesses do?
There is no need to panic or replace everything overnight.
But now is a good time to check:
- whether anyone is still using SMS or telephone MFA
- whether administrator accounts have stronger protection
- whether older authentication methods are still enabled unnecessarily
- whether Windows Hello or passkeys could be introduced
Cybersecurity does not stand still.
A few years ago, simply enabling MFA was a major step forward. Today, attackers increasingly expect MFA to be present and have developed ways to work around weaker forms of it.
The next step is not abandoning MFA.
It is making MFA harder to phish.
Unsure?
If you’re unsure which MFA methods are currently being used across your Microsoft 365 environment, Weald IT can review your authentication setup and advise on sensible next steps.
Contact Weald IT for help with Microsoft 365 security and authentication.
- You Have MFA. But Is It the Right MFA?
- IT Support Pricing Changes from 1 January 2027
- Lessons We’ve Learned: Why We Don’t Chase Rapid Growth
- Lessons We’ve Learned Using AI in a Real Business
- Microsoft 365 Price Changes from 1 July 2026
- How to Choose an IT Support Company in Sussex
- Christmas & New Year Opening Times
- Cyber Security Made Simple
- How to get Teams to dial from a web page
- Weald becomes a Fortinet partner