Security
Phishing-resistant authentication for Microsoft 365 tenants: why Authenticator push is no longer enough, how passkeys actually work, and how to migrate without locking people out.
- From Authenticator MFA to multi-device passkeys
Authenticator push and TOTP (Time-based One-Time Password, a 6-digit temporary code) are still phishable. Synced passkeys, how the sign-in actually works, and a sequenced Entra rollout that does not strand people on a new phone.
