Cloud Security Stack
Tools and buyer guides

Tools

Which MFA method to standardise on

SMS is still the most deployed and the weakest. What to move to, in what order, and how to handle the people who cannot use an app.

10 min read · Reviewed 22 August 2026 · Written against Microsoft's published authentication method capabilities.

The methods are not equivalent

Any second factor is better than none, which is how organisations end up on SMS and stop. But the attack that matters now is real-time phishing through a proxy, and against that, methods differ enormously. A code the user types can be relayed. A cryptographic response bound to the origin cannot.

Resistance to the attacks that actually happen
SMSAuthenticator codeNumber matchingPasskey or FIDO2
Stops password reuse
Stops SIM swap
Stops push fatigue
Stops real-time phishing proxy
Works without a phone

Number matching materially reduces push fatigue but does not make a relayed session impossible. Only origin-bound credentials do that.

The migration order that works

01

Turn off SMS as a default, not as a ban

Remove it from the registration campaign so new users never land on it. Banning it outright before people have registered something else creates a support queue and a rollback.

02

Push everyone to the Authenticator app with number matching

The realistic bulk move. It is free, it works on the phones people already have, and number matching kills the fatigue attack.

03

Put hardware keys on administrators first

Small population, highest value. Every account with standing privilege should be on a phishing-resistant method before anyone worries about the wider estate.

04

Solve the exceptions deliberately

Shop floor, shared devices, people without a smartphone. Hardware keys are usually the answer here too, and treating these as an afterthought is why rollouts stall at eighty percent.

The verdict

Our pick

Authenticator with number matching for the estate, hardware keys for admins

It is the highest security you can actually roll out to everybody, and it puts phishing-resistant authentication where compromise does the most damage.

Who should skip

Do not standardise on SMS-only, and do not leave it enabled as a fallback for privileged accounts. A fallback method is the method an attacker will choose.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.