Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

“MFA enabled” does not tell you how well an account resists a fake login page, a stolen phone number, or a barrage of approval prompts. The method matters: CISA identifies FIDO/WebAuthn—used by passkeys and compatible security keys—as the phishing-resistant option to prioritize. Check not only what you use to sign in, but also which recovery and fallback methods remain enabled.

Why “MFA enabled” is not a complete security answer

Multifactor authentication (MFA) asks for more than one kind of proof that you are who you claim to be. That additional check can make a stolen password less useful, but MFA is a broad label, not a guarantee that every second factor withstands the same attacks. CISA’s guidance distinguishes methods by the threats they address, rather than treating them as interchangeable. See CISA’s overview of multifactor authentication and its MFA guidance for small and medium businesses.

A useful way to assess an account is to ask four questions: Can a fake website capture and relay the factor? Does it depend on a phone number that could be intercepted or taken over? Can repeated prompts lead to an accidental approval? And can a weaker method still be used for recovery or as a fallback?

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the common MFA methods compare

This is a qualitative, threat-based ranking based on CISA guidance—not a measured comparison of real-world compromise rates. No comparative statistic establishing how often each method is defeated is available in the cited material.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Method What it helps with Key limitation
FIDO/WebAuthn passkey or security key CISA describes FIDO/WebAuthn as phishing-resistant; prioritize it where the account and device support it. Check device and account compatibility, as well as recovery options.
Authenticator app or token code Offers advantages over SMS in relevant threat dimensions. A fake site can trick you into entering a code that an attacker captures and relays.
Push approval with number matching Reduces the risk of approving a bombardment of ordinary prompts. It is not phishing-resistant FIDO authentication.
Push approval without number matching Provides an additional approval step. Repeated prompts and accidental or annoyed approvals make it vulnerable to push fatigue.
SMS or voice code Can add a check when stronger methods are unavailable. Vulnerable to phishing and phone-number attacks; review it especially carefully as a fallback.

CISA calls FIDO/WebAuthn “the only widely available phishing-resistant authentication” in More than a Password. Its Mobile Communications Best Practice Guidance, dated December 18, 2024, states: “Only FIDO authentication is phishing-resistant.” This describes resistance to phishing; it does not mean every other risk, including account recovery, disappears.

Why SMS codes and authenticator codes are not equivalent

SMS and voice codes

SMS is weaker than app-based codes and phishing-resistant methods in the threat dimensions covered by CISA guidance. Messages are not encrypted, and phone-number-based authentication can be exposed to network interception, SIM-swap attacks, and phishing. CISA recommends moving away from SMS for targeted accounts in its mobile communications guidance and phishing-resistant MFA fact sheet.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Authenticator codes

A code from an authenticator app or token avoids relying on SMS delivery, but it is still something you can be persuaded to type into a fake sign-in page. An attacker may relay that code during a live login attempt. CISA discusses this limitation in its mobile communications guidance and its Identity and Access Management best practices for administrators, published in December 2023.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What MFA fatigue and number matching do—and do not—mean

MFA fatigue, also called push bombing, is an attempt to wear down a user with repeated sign-in approval requests. CISA describes it as a threat actor sending push notifications until the user approves by accident or out of annoyance. An unexpected prompt is not a reason to tap approve; repeated prompts can be a sign that someone is trying to sign in with your credentials.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Number matching makes a push approval harder to accept blindly by requiring the user to match a number shown during sign-in. CISA’s October 2022 number-matching fact sheet explains this mitigation. It is a useful improvement over a simple approve-or-deny notification, but it does not turn push authentication into phishing-resistant FIDO/WebAuthn.

What to do for each important account

Start with accounts whose compromise could expose other accounts or valuable data: email, financial services, cloud storage, social accounts, and administrative or work accounts. Provider menus differ, so look in each service’s security or sign-in settings rather than assuming that one account’s setup applies everywhere.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Identify the actual factor. In the account’s security settings, determine whether sign-in uses SMS or voice, a one-time code, push approval, number matching, a passkey, or a security key. “MFA enabled” alone does not identify the method.
  2. Choose FIDO/WebAuthn where supported. Enroll a passkey or compatible hardware security key if the service and your device support it. A physical security key is one way to use FIDO/WebAuthn; verify compatibility and recovery options before relying on it.
  3. Inspect recovery and fallback routes. Check whether SMS or another weaker method can still be used to regain access or complete sign-in. Remove SMS fallback when the service allows it and you have a safe alternative in place. A stronger primary method does not by itself establish that weaker routes are gone.
  4. If FIDO is unavailable, use the stronger option the service offers. Number matching improves ordinary push approval against prompt fatigue. An authenticator code can avoid SMS delivery risks, but it remains phishable; neither is equivalent to phishing-resistant FIDO/WebAuthn.
  5. Handle unexpected prompts as suspicious. Do not approve a request you did not initiate. Treat repeated prompts as a possible attack and report them to the service or, for a work account, your IT team.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What MFA can and cannot promise

MFA is still valuable: it adds a check beyond the password. But its protection depends on the factor used, the way it can be recovered, and whether a weaker fallback remains available. CISA’s recommendations support a practical hierarchy—FIDO/WebAuthn first where available, stronger alternatives when it is not, and careful review of phone-based and recovery routes—without implying that any single setting makes an account invulnerable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.