Tools
Which MFA method to standardise on
SMS is still the most deployed and the weakest. What to move to, in what order, and how to handle the people who cannot use an app.
The methods are not equivalent
Any second factor is better than none, which is how organisations end up on SMS and stop. But the attack that matters now is real-time phishing through a proxy, and against that, methods differ enormously. A code the user types can be relayed. A cryptographic response bound to the origin cannot.
| SMS | Authenticator code | Number matching | Passkey or FIDO2 | |
|---|---|---|---|---|
| Stops password reuse | ||||
| Stops SIM swap | ||||
| Stops push fatigue | ||||
| Stops real-time phishing proxy | ||||
| Works without a phone |
Number matching materially reduces push fatigue but does not make a relayed session impossible. Only origin-bound credentials do that.
The migration order that works
Turn off SMS as a default, not as a ban
Remove it from the registration campaign so new users never land on it. Banning it outright before people have registered something else creates a support queue and a rollback.
Push everyone to the Authenticator app with number matching
The realistic bulk move. It is free, it works on the phones people already have, and number matching kills the fatigue attack.
Put hardware keys on administrators first
Small population, highest value. Every account with standing privilege should be on a phishing-resistant method before anyone worries about the wider estate.
Solve the exceptions deliberately
Shop floor, shared devices, people without a smartphone. Hardware keys are usually the answer here too, and treating these as an afterthought is why rollouts stall at eighty percent.
The verdict
Authenticator with number matching for the estate, hardware keys for admins
It is the highest security you can actually roll out to everybody, and it puts phishing-resistant authentication where compromise does the most damage.
Do not standardise on SMS-only, and do not leave it enabled as a fallback for privileged accounts. A fallback method is the method an attacker will choose.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.