Skip to content
Insights
Request Services
MFA factors
Cheat sheet · printable · CC BY 4.0

MFA factor comparison — phishing-resistance scoring

Every common MFA factor scored on phishing-resistance, friction, cost, and audit acceptance.

Share

Use your browser print dialog. Landscape orientation. Table is wide.

askmeidentity · MFA factors · 2026-05-22

MFA factor comparison — phishing-resistance scoring

A printable single-page comparison of MFA factors — passkeys, hardware tokens, push, OTP, SMS, voice — scored on phishing-resistance, user friction, deployment cost, and whether auditors accept them as "strong" auth.

Scoring legend

  • ·Phishing-resistance: ★★★★★ = fully phishing-resistant (cannot be relayed); ★ = trivially phishable
  • ·Friction: ★ = instant + invisible; ★★★★★ = requires deliberate user action with physical device
  • ·Cost: ★ = free / included with platform; ★★★★★ = high per-user hardware cost
  • ·Auditor acceptance: ★★★★★ = accepted at all AAL levels; ★ = below baseline for any modern AAL

Phishing-resistant factors

FIDO2 security key (YubiKey, Feitian)Phish ★★★★★ · Friction ★★★ · Cost ★★★★ · Audit ★★★★★
Platform passkey (Touch ID, Windows Hello, Android)Phish ★★★★★ · Friction ★ · Cost ★ · Audit ★★★★★
PIV / CAC smart cardPhish ★★★★★ · Friction ★★★★ · Cost ★★★★ · Audit ★★★★★ (federal baseline)
Cert-based (mTLS)Phish ★★★★★ · Friction ★★ · Cost ★★★ · Audit ★★★★★

Strong but phishable factors

Microsoft Authenticator / Okta Verify push + number matchPhish ★★★ · Friction ★★ · Cost ★ · Audit ★★★★
TOTP / HOTP (Google Authenticator)Phish ★★ · Friction ★★ · Cost ★ · Audit ★★★★
OATH OTP hardware token (RSA SecurID, YubiKey OTP)Phish ★★ · Friction ★★★ · Cost ★★★★ · Audit ★★★★
Risk-based (Conditional Access — device + geo + behavior)Phish ★★★ · Friction ★ · Cost ★★ · Audit ★★★ (as 2nd factor, not 1st)

Weak factors (avoid for new programs)

Push notification (no number match)Phish ★ · Friction ★ · Cost ★ · Audit ★★ (vulnerable to MFA fatigue)
SMS / voice OTPPhish ★ · Friction ★★ · Cost ★★ · Audit ★ (NIST deprecates for restricted use)
Email magic linkPhish ★ · Friction ★★ · Cost ★ · Audit ★ (only as good as the email account)
Security questions / KBAPhish ★ · Friction ★★★ · Cost ★ · Audit ★ (NIST advises against)

AAL mapping (NIST 800-63B)

AAL1Single factorAny reasonable factor
AAL2Two factorsResistant to phishing for primary auth (push + number match acceptable)
AAL3Hardware crypto authenticatorFIDO2 / smart card / PIV — phishing-resistant required

Decision rules

  • ·Privileged users: AAL3 — FIDO2 or PIV only. No exceptions.
  • ·Regular workforce: AAL2 minimum — push with number match acceptable for now, FIDO2 / passkeys for greenfield.
  • ·External / customers: passkeys are the new default. OTP / SMS only as fallback during rollout.
  • ·Help-desk MFA reset is the social-engineering vector. Tighten that workflow even if the factors are strong.
askmeidentity.com · CC BY 4.0 · Reviewed 2026-05-22
More cheat sheets

All printable references in one place.

See all cheat sheetsStandards explainers

Identity, cybersecurity, and custom software for regulated enterprises. Audit-ready operations from advisory through audit.

Americas HQ

Wilmington, DE

America/New York

India HQ

Hyderabad, TG

Asia/Kolkata

Services
  • IAM Consulting
  • IAM Technologies
  • Custom Software & AI
  • IAM Staffing
  • Request Services
  • Case Studies
Resources
  • All Resources
  • Complete Guide to IAM
  • IAM Frameworks Compared
  • IAM Certification Roadmap
  • IAM API Hub
  • IAM Explainers
  • IAM Vendor Status
  • Release Notes
  • State of Identity
  • State of PAM
  • State of IGA
  • State of CIAM
  • State of AI Agent Identity
  • IAM Salary Benchmark
  • Vendor Pricing Index
  • Year in Review 2026
  • Acquisition Tracker
  • Outage Tracker
  • Identity Incidents
  • Vulnerability Tracker
  • Cheat Sheets
  • Standards Explainers
  • Migration Playbooks
  • Audit Checklists
  • Reference Architectures
  • RFP Templates
  • IAM Anti-Patterns
  • Compliance Crosswalk
  • Market Landscape
  • Awesome IAM
  • IAM Glossary
  • Compliance Frameworks
  • Integration Guides
  • Vendor Alternatives
  • IAM by Industry
  • Salary Lookup
  • Directory
Research & media
  • IAM Compensation 2026
  • Vendor Moves Q3 2026
  • Identity Incidents Q3 2026
  • Vendor Security Posture 2026
  • Vendor Pricing 2026
  • AI Citation Tracker
  • Top 50 IAM Tools 2026
  • Podcast
  • Videos
  • Newsletter
  • Newsletter Archive
  • Embed Widgets
Free tools
  • JWT Decoder
  • JWT Signer
  • SAML Decoder
  • SAML Metadata Diff
  • OAuth Flow Visualizer
  • OIDC Debugger
  • OIDC Discovery Validator
  • PKCE Generator
  • WebAuthn Tester
  • Bearer Token Inspector
  • SCIM Validator
  • Password Entropy
  • IAM RFP Template
  • PAM Vendor Selector
  • Maturity Assessment
  • ROI Calculator
  • TCO Calculator
  • MFA Bypass Risk
  • Audit-Prep Burden
  • Quizzes
Company
  • About
  • Leadership
  • Approach
  • Why Choose Us
  • Partners
  • Press Kit
  • Press Topics
  • Global Presence
  • Locations
  • Insights
  • Now
  • Community
  • Open Roles
  • Submit Resume
  • Training
  • Contact

© 2026 askmeidentity, Inc.. Safeguard your digital frontier.

  • Privacy Policy
  • Terms of Service
  • Accessibility