Identity
Multi-factor authentication, passkeys and phishing resistance
A risk-led guide to authentication methods, recovery and rollout for important business accounts.
Multi-factor authentication (MFA) methods provide different levels of resistance to phishing. For high-value and administrative access, prefer methods that bind authentication to the legitimate service, such as suitable passkeys or hardware-backed methods, while maintaining a safe recovery route. Roll out by account consequence and test real devices, travel and support scenarios.
Design choices that matter
- Multi-factor authentication remains one of the Australian Signals Directorate's most important controls.
- Text-message codes and one-time codes can improve security but may still be captured or socially engineered.
- Recovery methods can undermine strong sign-in if they are poorly controlled.
- A second protected method prevents one lost device from becoming a business-wide administrator outage.
How to approach the work
- 01
Rank accounts
Start with administrators, email, banking, payroll, domain, remote access and systems containing sensitive data.
- 02
Choose supported methods
Check service capability, device support, shared or frontline use, accessibility and recovery needs.
- 03
Pilot and enrol more than one method
Avoid one lost device becoming a business outage; secure backup methods and emergency access.
- 04
Remove weaker paths
After successful rollout, disable unnecessary legacy and recovery paths that bypass the intended control.
- 05
Monitor and rehearse
Review MFA changes, failed sign-ins and recovery events, and rehearse a lost-device scenario.
What to test before handover
- Critical accounts ranked
- Methods selected by risk
- Backup method controlled
- Legacy access reviewed
- Recovery tested
- MFA changes monitored
- Admin accounts strengthened
Problems to catch early
- Assuming an authenticator prompt cannot be phished or abused through fatigue
- Leaving password-only legacy access enabled
- Using personal recovery details for shared business administration
Useful technical references
- Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
- Australian Signals Directorate, Australian Cyber Security Centre — Essential Eight explained
- Australian Signals Directorate, Australian Cyber Security Centre — Small business cloud security guides
Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.