

Phishingresistant MFA: the new identity baseline for Belgian SMBs
Phishing remains the most common attack vector against Belgian small and mid-sized businesses. In recent years, many organizations have taken an important first step by enabling Multi-Factor Authentication (MFA). Unfortunately, attackers have adapted faster than most SMBs.
Traditional MFA methods, such as SMS codes or approval prompts, are increasingly bypassed through techniques like phishing kits, MFA fatigue, and token theft. As a result, Microsoft now positions phishingresistant MFA as the new minimum standard for identity protection.
The good news? This level of protection is now accessible and affordable for SMBs, especially those using Microsoft 365 Business Premium.
Why traditional MFA is no longer enough
Most SMB environments rely on one of these MFA methods:
- SMS or voice codes
- One-time passwords
- Push notifications in Microsoft Authenticator
While these methods are an improvement over passwords alone, they still rely on shared secrets or approvals that attackers can exploit.
By contrast, Microsoft reports that phishingresistant MFA blocks over 99.99% of identity-based attacks, compared to lower protection levels with traditional MFA.

What is phishingresistant MFA?
Phishingresistant MFA uses cryptographic authentication rather than reusable credentials. Authentication is bound to:
- the user
- the device
- the service
This makes credential replay, token theft, or fake sign-in pages ineffective.
Microsoft currently recognizes the following methods as phishingresistant:
- Windows Hello for Business
- FIDO2 security keys
- Passkeys (where supported)
- Certificate-based authentication
Even if users are tricked into clicking malicious links, authentication simply cannot be completed.
Why this matters for SMBs and not just enterprises?
Phishingresistant MFA is often assumed to be “enterprise-only”, but that is no longer true.
Microsoft 365 Business Premium includes:
- Microsoft Entra ID P1 / Conditional Access
- Windows Hello for Business
- Intune device management
This means most SMBs can deploy phishingresistant MFA right now!


The most practical option for SMBs: Windows Hello for Business
For the majority of SMB users, Windows Hello for Business is the most effective starting point.
- No additional hardware required
- Strong security using biometrics or PIN
- Better user experience than passwords + MFA
- Seamless integration with Entra ID and Intune
When combined with Conditional Access, Windows Hello allows partners to enforce phishingresistant MFA without disrupting employees.
When FIDO2 security keys make sense
While Windows Hello is ideal for most employees, FIDO2 security keys are recommended for:
- Administrators
- Executives and finance roles
- Shared workstations
- Industrial or shop floor environments
FIDO2 keys provide the highest level of assurance and are fully supported across Microsoft cloud services.

Rolling out phishingresistant MFA without friction
A successful SMB rollout typically follows a phased approach:
- Secure the baseline
- Disable legacy authentication
- Enforce MFA for all users
- Protect admin accounts first
- Introduce phishingresistant methods
- Enable Windows Hello for Business
- Deploy FIDO2 keys where appropriate
- Enforce with Conditional Access
- Require phishingresistant MFA for admins
- Gradually expand to all users
This approach balances security, usability, and adoption.

Licensing clarity for CSP partners
One of the most common SMB concerns is licensing complexity. In practice, it’s straightforward:
- Microsoft 365 Business Premium: sufficient for most users
- No Entra ID P2 required for basic phishingresistant MFA
- Optional upgrades only for advanced identity governance or reporting
For many SMB customers, phishingresistant MFA is a configuration exercise, not a licensing exercise.
Supporting Belgian SMB compliance expectations
Strong identity security is increasingly referenced in:
- NIS2 security expectations
- ISO 27001 access control requirements
- Cyber insurance assessments
Phishingresistant MFA helps organizations demonstrate that identity risks are proactively managed, not merely acknowledged.
For business owners and management, this shifts identity security from an IT discussion to a business risk conversation.


The CSP opportunity
For Microsoft CSP partners, phishingresistant MFA represents:
- A clear security differentiation
- A repeatable managed service
- A natural upsell after basic MFA
- A foundation for Zero Trust, Defender, and device security projects
Most importantly, it enables partners to move from reactive incident response to preventive identity protection.

