Phishing-Resistant Multi-Factor Authentication
A password is like a house key that anyone can copy if they trick you into handing it over. Phishing-resistant MFA uses a physical security key or your face/fingerprint that is tied to the real login page, so a fake website can't steal it. Even if a hacker knows your password, they can't get in without the key that's physically with you.
Stolen passwords are the number-one way attackers break into cloud accounts, and text-message or app-tap codes can still be phished; without phishing-resistant MFA an admin account takeover can expose the whole tenant.
- 1List admins
- 2Enable FIDO2 keys
- 3Enroll admins
- 4Report-only test
- 5Enforce policy
- 6Block legacy auth
Always exclude two break-glass accounts before you enforce, or a bad policy can lock every admin out of the tenant.
Commercial (Entra ID) tenants are generally NOT authorized to store CUI; for ITAR/CUI you typically need GCC High, where these same phishing-resistant MFA controls exist and are required for DFARS 252.204-7012 compliance.