The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A sound multi-factor authentication (MFA) solution uses distinct authentication factors, protects the exchange, resists replay, and offers a phishing-resistant method. The required strength depends on the assurance level and the rules that apply to your organization. Under NIST SP 800-63B Revision 4, AAL2 requires a phishing-resistant option; AAL3 requires phishing-resistant cryptographic authentication with a non-exportable private key.
What makes authentication multi-factor?
For an authentication event to count as multi-factor, it must use either a multi-factor authenticator or two separate factors. A password and a browser cookie do not become two factors merely because both are involved in a login. The factors must be distinct in the authentication event.
NIST SP 800-63B Revision 4 is a U.S. federal digital identity standard. Its assurance levels offer a useful way to organize security requirements, but they do not automatically impose the same obligations on every private-sector service. Organizations must separately identify applicable laws, contracts, sector rules, and internal risk policies.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →How AAL2 and AAL3 differ
NIST sets different requirements for each assurance level. AAL2 and AAL3 are not interchangeable; choose controls according to the assurance level the system must meet.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Requirement | AAL2 | AAL3 |
|---|---|---|
| Authentication | A multi-factor authenticator or two separate factors | Phishing-resistant cryptographic authentication |
| Replay resistance | At least one authenticator must be replay-resistant | Required |
| Phishing resistance | The verifier must offer at least one phishing-resistant option | Required |
| Private-key protection | No non-exportable-key requirement stated for AAL2 | Cryptographic authenticator must use a non-exportable private key; syncable authenticators must not be used |
| Authentication intent | No AAL2 requirement stated here | Required |
| Overall session timeout | No more than 24 hours | No more than 12 hours |
| Inactivity timeout | No more than one hour | No more than 15 minutes |
These requirements are from NIST SP 800-63B Revision 4. NIST distinguishes mandatory requirements from recommendations; confirm the exact normative language for the control you are implementing.
Biometrics are not a factor on their own
Under NIST, a biometric is not an authenticator by itself. It is used with a physical authenticator or to activate one, such as when a fingerprint unlocks a device-bound credential.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What phishing resistance means in practice
Phishing resistance is a property of the authentication protocol, not simply a claim that a method is secure. NIST defines it by whether an impostor verifier can obtain secrets or valid outputs without relying on the user to spot the deception. Manually entered one-time passwords (OTPs) and out-of-band codes can be relayed to an impostor and do not qualify as phishing-resistant under this definition.
WebAuthn and FIDO2 can provide phishing resistance through verifier name binding: the authenticator uses the authenticated domain name to select the credential, preventing it from being used at an impostor domain. NIST describes this mechanism in SP 800-63B, Section 3.2.5.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How the main MFA options compare
| Method | Phishing resistance | Operational fit | Important caveat |
|---|---|---|---|
| FIDO2/WebAuthn security key or platform authenticator | High when correctly supported and configured; verifier name binding protects against credential use at an impostor domain | Roaming keys connect by USB or NFC; platform authenticators are built into supported devices | Check service, device, and recovery support before rollout |
| Enterprise PKI smart card | Can be phishing-resistant through cryptographic authentication and channel binding in applicable implementations | Fits organizations with mature identity and PKI operations; may require card provisioning and readers | Less widely available and depends on mature identity management |
| App-based number matching | Not equivalent to a phishing-resistant cryptographic protocol | Uses a phone app and user interaction | A stronger interim option than simple approve-or-deny push prompts when phishing-resistant MFA is not yet available |
| OTP or text/email code | Not phishing-resistant when a user manually enters the code | Often familiar and broadly usable | Codes can be phished or relayed; CISA ranks text and email among weaker options |
CISA discusses roaming and platform authenticators, PKI, and migration planning in its phishing-resistant MFA guidance. Its business MFA guidance also describes a relative hierarchy of methods. A physical security key is not a universal fit: verify FIDO2/WebAuthn support for each account, device, and operating system, and plan how users will recover access.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to prioritize an MFA rollout
- Inventory systems and accounts. Record current MFA coverage, enforcement gaps, and systems that cannot support MFA. Assign each unsupported system an upgrade, integration, migration, or risk-escalation path.
- Protect high-value access first. Prioritize administrators, remote access, email, systems containing sensitive data, and critical services. CISA recommends broad coverage across business systems, with priority for administrators and people handling sensitive data.
- Offer a phishing-resistant method and plan the transition. Where immediate migration is not feasible, number matching is a stronger interim choice than simple push approval. Keep appropriate compensating controls in place while moving toward phishing-resistant authentication.
- Test the full authenticator lifecycle. Exercise enrollment and binding, lost-device handling, recovery, revocation, replacement, and help-desk procedures. Recovery needs vary by assurance level and deployment; a single recovery pattern is not appropriate for every system.
- Check user and platform compatibility. Account for accessibility, multiple-device needs, fallback risks, and vendor dependencies. A successful login on one service does not establish compatibility with every account.
- Set session and reauthentication rules. Align timeouts with the assurance level and system risk, using the NIST limits in the table when those requirements apply.
CISA recommends requiring MFA broadly and planning upgrades or migration for systems that cannot support it. Its general guidance also recommends number matching as an interim measure when phishing-resistant MFA cannot yet be implemented: More than a Password.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

