MFA Helps. It Is Not Magic.
Some phishing kits steal your signed-in session after MFA. Phishing-resistant sign-in closes that gap.
Illustrative scenario
How It Looks in Real Life
You sign in through a link, complete MFA normally, and land in your mailbox. Later, IT sees your account accessed from another country, without any MFA prompt.
Understand it
How the Attack Works
Adversary-in-the-middle pages sit between you and the real site. You complete MFA, but the page captures the session token issued afterwards, letting the attacker reuse your signed-in session. Passkeys and security keys resist this because they check the real site address.
Red flags
Warning Signs
- Signing in through a link instead of a bookmark or app.
- Address bar showing a domain that is close to, but not, the real one.
- Sign-in alerts from unfamiliar locations shortly after you signed in.
Safer habits
What to Do Instead
- 1Open important services from bookmarks or official apps.
- 2Use passkeys or security keys where your organisation supports them.
- 3Report unexpected sign-in alerts promptly.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: entered credentials or shared a code
- 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
- 2Change the password from a trusted device by typing the real address yourself.
- 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
- 4Review recovery email, phone number and forwarding rules for unexpected changes.
If you: approved app permissions or a sign-in request
- 1Report it straight away so IT can revoke the session or app consent.
- 2Remove the unfamiliar app from your account’s connected apps or permissions page.
- 3Changing your password does not remove app permissions or tokens already issued.
Knowledge Check
What Would You Do?
Which statement is accurate?
Fictional example for learning. Not a test score or certification.
Sources
- Microsoft Security Blog: Defending against evolving identity attack techniques (May 2025)
- CISA: Multifactor Authentication
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.