Skip to main content

Multi-Factor Authentication Can Stop Hackers — But in 2026, You Need the Right MFA

Media Important Information on Using Multi-Factor Authentication to Stop Hackers

 

Passwords are no longer enough to protect a business.

An employee can choose a long, complicated password and still lose it to a convincing Microsoft 365 phishing page.

A password can also be:

  • reused on another website
  • stolen through malware
  • exposed in a data breach
  • captured by a fake login page
  • socially engineered from the user

This is why multi-factor authentication (MFA) has become such an important part of business cybersecurity.

MFA requires another form of verification before somebody can access an account.

So if a cybercriminal steals an employee's password, they still have another barrier to overcome.

But there is an important change businesses need to understand in 2026:

Not all MFA provides the same level of protection.

Traditional SMS codes and approval notifications are better than relying on passwords alone, but modern attackers have developed ways of targeting those methods too.

Microsoft now recommends businesses move towards phishing-resistant authentication, including passkeys, Windows Hello for Business and FIDO2 security keys.

What Is Multi-Factor Authentication?

Authentication is simply the process of proving that you are who you claim to be.

Traditionally, that meant:

Username + password

MFA adds another factor.

That could involve:

Something you know — password or PIN.

Something you have — phone, security key or trusted device.

Something you are — fingerprint or facial recognition.

A cybercriminal who obtains your Microsoft 365 password therefore cannot necessarily access the account.

They still need to satisfy the additional authentication requirement.

That simple extra barrier prevents a huge category of account compromises.

Why Passwords Alone Are Dangerous

The problem is not simply that people choose bad passwords.

Even an excellent password can be stolen.

Imagine an employee receives an email claiming:

“Your Microsoft 365 password expires today. Sign in now to prevent your account being disabled.”

The link opens a website that looks almost identical to Microsoft's real login page.

The employee enters their email address and password.

The attacker now has both.

Without MFA, that may be enough to access:

  • Outlook
  • OneDrive
  • SharePoint
  • Teams
  • company information

MFA creates another obstacle.

But sophisticated phishing attacks increasingly attempt to steal that second factor too.

MFA Isn't Unhackable

This is one of the most important things businesses need to understand.

MFA is extremely valuable.

But:

MFA does not mean an account can never be compromised.

Some MFA methods are phishable.

An attacker can create a fake Microsoft 365 sign-in page that captures the username and password and then relays the victim's authentication session to the legitimate Microsoft service.

This type of attack can sometimes defeat conventional MFA.

Microsoft specifically warns that traditional MFA methods remain vulnerable to phishing and recommends stronger, phishing-resistant authentication methods.

That does not mean you should switch MFA off.

It means you should use better MFA.

SMS Codes: Better Than Nothing, But No Longer the Goal

Many businesses started their MFA journey with text messages.

The employee enters a password.

Microsoft sends a code to their phone.

They enter the code.

Access is granted.

That remains preferable to password-only authentication, but SMS has weaknesses.

Attackers can target:

  • mobile accounts
  • SIMs
  • users through social engineering
  • real-time phishing sessions
  • one-time codes

Microsoft now describes SMS and voice as among the weaker authentication methods and is actively moving Microsoft Entra customers towards passkeys.

For businesses still heavily dependent on SMS MFA, 2026 is the year to start migrating.

Microsoft Is Retiring Its Own SMS and Voice MFA Delivery

This is a major Microsoft 365 change businesses should know about.

1 September 2026

Microsoft says users currently enabled for SMS or voice authentication will be automatically enabled for passkeys and nudged to register one when completing MFA.

1 February 2027

Microsoft-provided SMS and voice delivery for Microsoft Entra ID will be retired.

Microsoft says organisations should migrate users to phishing-resistant authentication before this date to avoid sign-in disruption.

Businesses with a genuine regulatory or operational requirement for SMS or voice will have an alternative route through customer-managed telecom providers, but Microsoft's recommended migration path is passkeys.

If your Microsoft 365 environment still relies heavily on text-message MFA, don't wait until January 2027 to investigate this.

Microsoft Authenticator Is Better — But Understand MFA Fatigue

Microsoft Authenticator can provide push notifications rather than SMS codes.

An employee signs in and receives an authentication request on their phone.

That is convenient.

But attackers discovered that convenience could also be exploited.

What Is an MFA Fatigue Attack?

Suppose an attacker already knows an employee's password.

They repeatedly attempt to sign in.

The employee's phone starts receiving authentication requests:

Approve sign-in?

Again.

And again.

And again.

Eventually, the employee may approve one simply because they are confused or want the notifications to stop.

This is sometimes called:

MFA fatigue

or:

MFA bombing.

Microsoft specifically identifies MFA fatigue as a security concern and introduced number matching to reduce accidental approvals.

Number Matching Makes Authenticator Stronger

Microsoft Authenticator now uses number matching for push-based MFA.

Instead of simply pressing Approve, the user sees a number during the sign-in process and must match it in Authenticator.

Microsoft says number matching is enabled for all Authenticator push notifications.

That makes blind approval much harder.

But employees still need one simple rule:

Never approve an authentication request you didn't initiate.

If unexpected MFA requests suddenly start appearing, report them.

Someone may already know your password.

The Better Direction: Phishing-Resistant MFA

The next stage of business authentication is not simply adding more codes.

It is removing the attacker's ability to steal something reusable.

Microsoft recommends phishing-resistant authentication methods including:

  • passkeys
  • Windows Hello for Business
  • FIDO2 security keys
  • certificate-based authentication

 

These methods are fundamentally stronger against phishing because authentication is cryptographically tied to the legitimate service.

A convincing fake Microsoft login page cannot simply ask you for a six-digit passkey code and reuse it.

There isn't one.

What Is a Passkey?

A passkey replaces the traditional reusable secret with cryptographic credentials.

Instead of typing a password and then receiving a code, you might authenticate using:

  • fingerprint
  • face recognition
  • device PIN
  • security key

The important part is what happens underneath.

Passkeys use cryptographic keys rather than a shared secret that can simply be copied from a phishing website.

Microsoft says passkeys are resistant to threats including phishing, SIM swapping and replay attacks.

Synced vs Device-Bound Passkeys

Microsoft Entra supports different passkey approaches.

Synced passkeys

These can be stored in a platform credential manager and synchronised between the user's devices.

Device-bound passkeys

These remain associated with a particular device.

Examples can include:

  • Microsoft Authenticator passkeys
  • FIDO2 hardware security keys
  • Entra Passkey on Windows

Microsoft's newer Entra Passkey on Windows can store a device-bound FIDO2 passkey inside the Windows Hello container and use a biometric or PIN for phishing-resistant authentication.

The best model depends on the organisation's security requirements and device estate.

What About Windows Hello for Business?

Windows Hello for Business is another strong option for Windows environments.

Employees can authenticate using:

  • facial recognition
  • fingerprint
  • PIN

But the PIN is not simply a shorter Microsoft 365 password.

Windows Hello for Business uses cryptographic credentials associated with the device.

Microsoft includes Windows Hello for Business among its recommended phishing-resistant authentication methods.

For businesses already managing Windows devices through Microsoft Entra ID and Intune, this can form an important part of a modern authentication strategy.

Protect Administrator Accounts First

If you cannot modernise every account immediately, prioritise the accounts capable of causing the most damage.

Administrator accounts should have stronger protection than ordinary users.

That includes accounts with access to:

  • Microsoft 365 administration
  • Microsoft Entra ID
  • Intune
  • security platforms
  • backups
  • finance systems
  • infrastructure
  • privileged applications

A compromised ordinary account is bad.

A compromised Global Administrator account can be catastrophic.

Where possible, privileged administrators should use phishing-resistant authentication rather than SMS.

Microsoft itself has adopted phishing-resistant MFA as a core security objective for employee accounts and recommends organisations follow a similar approach.

MFA Should Work With Conditional Access

MFA is much more effective when it forms part of a broader identity-security strategy.

Microsoft Entra Conditional Access can make authentication decisions based on factors such as:

  • user
  • device
  • application
  • location
  • risk
  • authentication strength

For example, a business might allow ordinary access using one set of controls but require a phishing-resistant authentication method for particularly sensitive resources.

The objective is not simply:

“Does this employee have MFA?”

A better question is:

“Is this the right authentication method for this user, device and resource?”

Don't Forget Recovery

Stronger authentication creates another challenge:

What happens when somebody loses their phone or security key?

A business needs a secure recovery process.

Otherwise, an attacker may simply bypass strong authentication by persuading the helpdesk to reset it.

Recovery should include appropriate identity verification.

Microsoft also supports Temporary Access Pass (TAP), a time-limited credential that can be used for onboarding and recovery scenarios. Microsoft recommends TAP as part of securely deploying phishing-resistant authentication.

The security of your recovery process matters just as much as the authentication method itself.

MFA Is Not a Complete Cybersecurity Strategy

Turning on MFA does not mean the cybersecurity project is finished.

Businesses should combine strong authentication with controls such as:

  • Conditional Access
  • least privilege
  • separate administrator accounts
  • endpoint protection
  • device compliance
  • security monitoring
  • patch management
  • backups
  • employee security awareness
  • incident response

Attackers adapt.

Security therefore needs layers.

If one control fails, another should still stand between the attacker and your business.

A Practical MFA Plan for Businesses in 2026

For Microsoft 365 businesses, I would approach the transition like this:

  1. Identify users still relying on SMS or voice authentication.
  2. Make sure every account has MFA rather than password-only authentication.
  3. Move users towards passkeys, Windows Hello for Business or other appropriate phishing-resistant methods.
  4. Prioritise administrator and high-risk accounts.
  5. Use Microsoft Authenticator with number matching where push MFA remains necessary.
  6. Tell employees never to approve unexpected authentication requests.
  7. Review Conditional Access and authentication-strength requirements.
  8. Create a secure onboarding and account-recovery process.
  9. Prepare users for Microsoft's passkey changes beginning 1 September 2026.
  10. Move away from dependence on Microsoft-provided SMS and voice before 1 February 2027.

Microsoft specifically recommends identifying users currently enabled for SMS or voice, moving them to passkeys and communicating the change before the transition.

The Most Important Message

If your business currently has no MFA:

Enable MFA.

If your business already has MFA:

Don't assume the job is finished.

Find out which methods your employees actually use.

If your organisation still relies heavily on SMS, voice or conventional push approvals, start planning the move towards phishing-resistant authentication.

The cybersecurity conversation has moved on from:

“Do you have MFA?”

The better question for 2026 is:

“How resistant is your MFA to phishing?”

How Hamilton Group Can Help

Hamilton Group can help businesses strengthen Microsoft 365 authentication without making everyday access unnecessarily difficult.

We can assist with:

  • Microsoft 365 security
  • Microsoft Entra ID
  • multi-factor authentication
  • passkeys
  • Microsoft Authenticator
  • Windows Hello for Business
  • Conditional Access
  • Microsoft Intune
  • administrator account security
  • authentication reviews
  • cybersecurity
  • user security awareness

With Microsoft's move towards passkeys beginning in September 2026 and Microsoft-provided SMS and voice authentication retiring in February 2027, now is a good time to review how your organisation authenticates its users.

Visit or call 0330 043 0069 to discuss securing your Microsoft 365 environment.