Skip to main content

Phishingresistant MFA: the new identity baseline for Belgian SMBs 

Phishing remains the most common attack vector against Belgian small and mid-sized businesses. In recent years, many organizations have taken an important first step by enabling Multi-Factor Authentication (MFA). Unfortunately, attackers have adapted faster than most SMBs. 

Traditional MFA methods, such as SMS codes or approval prompts, are increasingly bypassed through techniques like phishing kits, MFA fatigue, and token theft. As a result, Microsoft now positions phishingresistant MFA as the new minimum standard for identity protection. 

The good news? This level of protection is now accessible and affordable for SMBs, especially those using Microsoft 365 Business Premium. 

Why traditional MFA is no longer enough

Most SMB environments rely on one of these MFA methods: 

  • SMS or voice codes 
  • One-time passwords 
  • Push notifications in Microsoft Authenticator 

While these methods are an improvement over passwords alone, they still rely on shared secrets or approvals that attackers can exploit.

By contrast, Microsoft reports that phishingresistant MFA blocks over 99.99% of identity-based attacks, compared to lower protection levels with traditional MFA. 

What is phishingresistant MFA?

Phishingresistant MFA uses cryptographic authentication rather than reusable credentials. Authentication is bound to: 

  • the user 
  • the device 
  • the service 

This makes credential replay, token theft, or fake sign-in pages ineffective. 

Microsoft currently recognizes the following methods as phishingresistant: 

  • Windows Hello for Business 
  • FIDO2 security keys 
  • Passkeys (where supported) 
  • Certificate-based authentication 

Even if users are tricked into clicking malicious links, authentication simply cannot be completed. 

Why this matters for SMBs and not just enterprises?

Phishingresistant MFA is often assumed to be “enterprise-only”, but that is no longer true. 

Microsoft 365 Business Premium includes:
  • Microsoft Entra ID P1 / Conditional Access 
  • Windows Hello for Business 
  • Intune device management 

This means most SMBs can deploy phishingresistant MFA right now!  

The most practical option for SMBs: Windows Hello for Business

For the majority of SMB users, Windows Hello for Business is the most effective starting point. 

  • No additional hardware required 
  • Strong security using biometrics or PIN 
  • Better user experience than passwords + MFA 
  • Seamless integration with Entra ID and Intune 

When combined with Conditional Access, Windows Hello allows partners to enforce phishingresistant MFA without disrupting employees. 

When FIDO2 security keys make sense

While Windows Hello is ideal for most employees, FIDO2 security keys are recommended for: 

  • Administrators 
  • Executives and finance roles 
  • Shared workstations 
  • Industrial or shop floor environments 

FIDO2 keys provide the highest level of assurance and are fully supported across Microsoft cloud services. 

Rolling out phishingresistant MFA without friction

A successful SMB rollout typically follows a phased approach

  1. Secure the baseline 
    • Disable legacy authentication 
    • Enforce MFA for all users 
    • Protect admin accounts first 
  2. Introduce phishingresistant methods 
    • Enable Windows Hello for Business 
    • Deploy FIDO2 keys where appropriate 
  3. Enforce with Conditional Access 
    • Require phishingresistant MFA for admins 
    • Gradually expand to all users 

This approach balances security, usability, and adoption. 

Licensing clarity for CSP partners

One of the most common SMB concerns is licensing complexity. In practice, it’s straightforward: 

  • Microsoft 365 Business Premium: sufficient for most users 
  • No Entra ID P2 required for basic phishingresistant MFA 
  • Optional upgrades only for advanced identity governance or reporting 

For many SMB customers, phishingresistant MFA is a configuration exercise, not a licensing exercise. 

Supporting Belgian SMB compliance expectations

Strong identity security is increasingly referenced in: 

  • NIS2 security expectations 
  • ISO 27001 access control requirements 
  • Cyber insurance assessments 

Phishingresistant MFA helps organizations demonstrate that identity risks are proactively managed, not merely acknowledged. 

For business owners and management, this shifts identity security from an IT discussion to a business risk conversation. 

The CSP opportunity

For Microsoft CSP partners, phishingresistant MFA represents: 

  • A clear security differentiation 
  • A repeatable managed service 
  • A natural upsell after basic MFA 
  • A foundation for Zero Trust, Defender, and device security projects 

Most importantly, it enables partners to move from reactive incident response to preventive identity protection. 

Other Microsoft Cloud Solutions blogs

Upcoming Microsoft Events

If you have more questions or

need help