“Turn on MFA” is good advice, but MFA methods do not provide equal protection. The right choice depends on the attack you expect, the recovery options you can manage and what the service actually supports.
SMS codes
Text messages are widely available and better than a password alone, but phone numbers can be moved through SIM-swap fraud and codes can be entered into phishing pages. Use SMS when it is the strongest available option, then protect the carrier account with a PIN.
Authenticator-app codes
Time-based codes avoid the mobile network and can work offline. They still rely on the user recognizing the correct site: a real-time phishing page can collect a password and current code. Back up the authenticator securely or store setup and recovery codes separately.
Push approval
A push prompt is convenient, but repeated prompts can pressure someone into approving the wrong request. Number matching and clear location/device information make prompts safer. Deny anything unexpected and change the password if prompts continue.
Passkeys and hardware security keys
FIDO-based credentials are tied to the legitimate domain and are designed to resist phishing. A passkey may live on a phone or sync through a credential manager; a hardware key is a separate physical device. Both need a recovery plan, ideally with a second registered credential.
A practical priority order
- For email, finance and administration accounts, prefer passkeys or security keys.
- Use an authenticator app when phishing-resistant options are unavailable.
- Use SMS rather than leaving an account password-only.
- Save recovery codes and test the backup method.
MFA should make account theft harder without making legitimate recovery impossible. The strongest method is one that resists the likely attack and has an independent backup you can actually use.
Match the method to the threat
SMS may be better than no second factor, yet it is exposed to phone-number takeover and message interception. Authenticator codes remove the carrier dependency but can still be typed into a phishing page. Push approval is convenient but vulnerable to fatigue. Passkeys and hardware security keys resist ordinary credential phishing because the response is bound to the genuine domain.
Use a tiered deployment
Give administrators, finance staff and source-code maintainers phishing-resistant authentication first. Consumer accounts may need a practical mix: a passkey for daily use, another trusted device, and offline recovery codes. Avoid making an insecure help-desk reset the easiest route around a strong primary method.
Review authentication logs after deployment. A falling password-reset rate, fewer unsolicited prompts and successful recovery drills matter more than the number of methods technically enabled.
Evaluate MFA by attack resistance and recovery
A useful comparison separates four questions: can the factor be phished, can it be copied, can an attacker trigger it remotely, and can the owner recover without weakening the account? SMS is widely available but depends on the carrier. Time-based codes remove that dependency but can still be relayed by a phishing page. Push approval can be abused through repeated prompts. Passkeys and security keys bind the response to the legitimate domain, which blocks the usual credential relay.
Recovery can reverse that ranking. A hardware key with no spare may create an avoidable lockout. A passkey protected by a weak cloud-account reset may inherit that weakness. Keep at least two independent recovery routes for important accounts and protect the routes as carefully as the daily factor.
How to choose for a real team
Start with the accounts whose compromise would spread furthest: email administrators, source control, payroll and cloud infrastructure. Give those users phishing-resistant authentication and rehearse replacement. For lower-risk accounts, an authenticator application with offline recovery codes may be a practical improvement over SMS.
Measure rejected prompts, recovery failures and suspicious resets after deployment. An MFA programme should reduce successful takeovers without training users to approve anything that interrupts their work.