Identity

Multi-factor authentication, passkeys and phishing resistance

A risk-led guide to authentication methods, recovery and rollout for important business accounts.

Multi-factor authentication (MFA) methods provide different levels of resistance to phishing. For high-value and administrative access, prefer methods that bind authentication to the legitimate service, such as suitable passkeys or hardware-backed methods, while maintaining a safe recovery route. Roll out by account consequence and test real devices, travel and support scenarios.

Design choices that matter

  • Multi-factor authentication remains one of the Australian Signals Directorate's most important controls.
  • Text-message codes and one-time codes can improve security but may still be captured or socially engineered.
  • Recovery methods can undermine strong sign-in if they are poorly controlled.
  • A second protected method prevents one lost device from becoming a business-wide administrator outage.

How to approach the work

  1. 01

    Rank accounts

    Start with administrators, email, banking, payroll, domain, remote access and systems containing sensitive data.

  2. 02

    Choose supported methods

    Check service capability, device support, shared or frontline use, accessibility and recovery needs.

  3. 03

    Pilot and enrol more than one method

    Avoid one lost device becoming a business outage; secure backup methods and emergency access.

  4. 04

    Remove weaker paths

    After successful rollout, disable unnecessary legacy and recovery paths that bypass the intended control.

  5. 05

    Monitor and rehearse

    Review MFA changes, failed sign-ins and recovery events, and rehearse a lost-device scenario.

What to test before handover

  • Critical accounts ranked
  • Methods selected by risk
  • Backup method controlled
  • Legacy access reviewed
  • Recovery tested
  • MFA changes monitored
  • Admin accounts strengthened

Problems to catch early

  • Assuming an authenticator prompt cannot be phished or abused through fatigue
  • Leaving password-only legacy access enabled
  • Using personal recovery details for shared business administration

Useful technical references

  1. Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
  2. Australian Signals Directorate, Australian Cyber Security Centre — Essential Eight explained
  3. Australian Signals Directorate, Australian Cyber Security Centre — Small business cloud security guides

Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.

A practical next step

Apply the guidance to the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.