• Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
  • Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
HBS logo
HBS Logo
  • Infrastructure
    • CLOUD

      • Cloud Solutions
      • Public Cloud
      • Hybrid Cloud
      • Infrastructure as a Service
      • Cloud Security Solutions
      • Backup, Replication and Disaster Recovery
      • HBS Cloud Hosting Services

      DATA CENTER

      • Data Center Solutions
      • Traditional Data Center
      • Hyperconverged
      • Colocation
      • Directory Services
      • Cloud Email and Calendar Solutions

      NETWORK AND ACCESS

      • Network Infrastructure
      • Enterprise Mobility
      • Wireless Solutions
      • SD-WAN
      • Structured Cabling
      • Staff Augmentation
      Data Center Solutions blue gradient background badge with white text
  • Managed Services
    • MANAGED ONE

      • Managed One Overview
      • Managed Backup and Disaster Recovery
      • Managed Email and Collaboration Security
      • Managed Firewall

       

      • Managed HaaS and SaaS
      • Managed IT Help Desk
      • Managed Network and Server Monitoring

      HBS + PARTNER SOLUTIONS

      • HBS Secure with Verkada
      • HBS Collaborate with Webex
      • Managed XDR
      HBS Managed One Megamenu Graphic
  • Modern Workplace
    • MICROSOFT

      • Microsoft Licensing Management
      • Microsoft Modern Workplace
      • Microsoft Copilot
      • Microsoft Fabric
      • Microsoft Funding Opportunities

       

      • Dynamics 365 Business Central
      • Dynamics 365
      • Dynamics GP

      COLLABORATION

      • Audio Visual
      • Unified Communication Solutions
      • HBS Collaborate with Webex
      HBS Collaborate with Webex blue gradient background badge
  • Professional Services
    • ADVISORY

      • Virtual CISO
      • Virtual CIO
      • Project Management
      • IT Business Consulting

      ENGINEERING SERVICES

      • Staff Augmentation

      AI & ANALYTICS

      • Artificial Intelligence
      • AI Advance
      • AI Predict
      • AI Assist
      • Data Management and Analytics
      • Microsoft Copilot
      • Microsoft Fabric

      APPLICATION INNOVATION

      • Website Development
      • Application Development

      DOCUMENT MANAGEMENT

      • Document Management Services
      • Document and Check Scanners
      Discover your AI Readiness blue gradient background with white text. Bottom right photo of young man in glasses smiling while looking at laptop. Red to green temperature gauge png
  • Security
    • CYBERSECURITY

      • Managed XDR
      • Penetration Testing
      • Vulnerability Scanning
      • Email Security Services
      • Digital Forensics and Incident Response
      • Backup, Replication and Disaster Recovery
      • Firewalls
      • Cloud Security Solutions

       

      • Virtual CISO
      • Virtual Security Team
      • Virtual Security Engineer
      • Cybersecurity Risk Assessment
      • Governance and Compliance
      • SOC 2
      • CMMC
      • Managed Security Awareness Training

      PHYSICAL SECURITY

      • Security Solutions
      • HBS Secure with Verkada
      Cybersecurity Risk Assessment Megamenu Graphic
  • Search
Contact Us
Blog

MFA Maturity: No Longer the Destination, But that Starting Point

  • Joe Gunnells, HBS Information Security Consultant
  • September 1, 2026
  • Read time: 5 mins.
Blog hero: MFA JOURNEY headline in bold blue outline with subtitle about multi-factor authentication on a pale curved-background banner

An InfoSec perspective on how multi-factor authentication has changed, where it is headed, and what it means for organizations still working toward full adoption.

Key Point: MFA is now a baseline expectation, but the journey has shifted from simply turning MFA on to selecting authentication methods that can withstand modern identity-based attacks.

For years, multi-factor authentication (MFA) has been one of easiest—and best—cybersecurity recommendations to make. Ask nearly any security professional what the single most effective control is to reduce account compromise risk. Their answer will be MFA.

Today, MFA alone is no longer considered an advanced security control. It is the baseline expectation.

At HBS, we have spent the better part of the last decade helping organizations deploy MFA across Microsoft 365, VPNs, remote access solutions, cloud applications, and privileged accounts. Five to ten years ago, the conversation was simply: “Do you have MFA enabled?” A Yes have security teams confidence the risk was covered.

That is no longer enough.

Now, that conversation looks dramatically different than 2016, or even 2021. Threats have evolved, attackers have adapted, and the industry is shifting its focus from simply deploying MFA to deploying the right kind of MFA.

The Evolution of MFA

The first generation of MFA projects focused almost exclusively on adoption as organizations moved away from password-only defenses. Text messages, phone calls, and push notifications became common second factors, and these methods drastically reduced the success of traditional password attacks.

Attackers adjusted. Instead of just stealing passwords, they began targeting the authentication process itself.

Phishing kits now capture MFA tokens. Adversary-in-the-middle attacks intercept sessions. SIM swapping targets SMS codes. MFA fatigue campaigns bombard users until a single approval slips through.

The cybersecurity adjusted back. We’ve moved toward phishing-resistant methods like FIDO2 security keys, Windows Hello for Business, device-bound passkeys, and other passwordless technologies. Major identity providers now treat passkeys as the default authentication experience, rather than an enhancement.

Instead of asking “Do we have MFA?” the questions need to be, “What kind of MFA do we have?” and “How resistant is our MFA to modern attacks?”

The Rise of Passwordless and Passkeys

Microsoft sign-in prompt: sign in faster with face, fingerprint, or PIN, with Next button and blue action area (informational image).
Courtesy of Microsoft

A significant trend we are witnessing at HBS is the acceleration of passwordless authentication.

For years, passwordless access felt more like an aspiration goal that was reserved for large enterprises with mature security programs. But that is quickly changing, thanks to passkeys, biometrics, Windows Hello for Business, hardware security keys, and device-bound credentials all becoming increasingly accessible for organizations of all sizes.

It’s easy to see why: passwords are still the most frequently attacked component of the authentication process. Every technology that removes or reduces dependence on passwords also reduces organizational risk.

One thing we find particularly interesting is that many orgs are now beginning to skip directly from legacy authentication to modern passwordless approaches. Instead of spending years of perfecting SMS-based MFA or push notifications, companies are moving directly toward phishing-resistant authentication as part of their identity modernization efforts.

Risk-Based Authentication Becomes the Standard

Another major shift is the move toward adaptive or risk-based authentication.

Historically, MFA policies were largely static. Every user received the same MFA prompt regardless of location, device, risk, or behavior.

Modern identity platforms are becoming significantly more intelligent. Authentication decisions can now consider factors such as:

  • Device compliance
  • Geographic location
  • Sign-in risk
  • Impossible travel scenarios
  • User behavior patterns
  • Endpoint health
  • Application sensitivity

Instead of challenging users every time they sign in, organizations can now focus MFA requirements where risk is highest. This creates a better user experience while strengthening security simultaneously.

This is a fundamental shift from the “one-size-fits-all” MFA deployments that dominated the past decade.

Current Reality: Too Many Organizations Are Still Trying to Reach the MFA Starting Line

Woman in a blue blouse uses a smartphone at a desk, with a laptop and tablet nearby on the workspace.

While the cybersecurity industry is discussing passkeys, phishing-resistant MFA, and passwordless futures, many organizations are still working through basic MFA deployments.

This is especially common among smaller municipalities, healthcare providers, school districts, manufacturers, and organizations with legacy applications that were never designed for modern authentication methods.

At HBS, we often encounter environments where:

  • MFA exists for administrators but not all users.
  • Remote access is protected, but email access is not.
  • Users have registered for MFA but enforcement has not been enabled.
  • Legacy authentication protocols remain active.
  • Service accounts and privileged accounts are excluded from MFA protections.

These organizations should not be discouraged by discussions around passkeys and passwordless technologies.

The most important step is still implementing MFA consistently across the organization. An organization moving from password-only authentication to Microsoft Authenticator or similar MFA solutions will achieve a substantially greater risk reduction than an organization debating the finer points of passkey strategy while leaving large portions of its user base unprotected.

Security maturity is a journey, not a single project.

The Next Five Years

Looking ahead, we expect identity security to become even more central to cybersecurity programs. Firewalls, antivirus solutions, and network controls remain important, but identity increasingly serves as the primary security perimeter.

The future of MFA will likely include:

  • Widespread adoption of passkeys and passwordless authentication
  • Increased use of hardware-backed credentials
  • More phishing-resistant authentication requirements
  • Risk-based and behavioral authentication decisions
  • Greater integration between endpoint security and identity controls
  • Reduced reliance on SMS and traditional one-time passcodes

Organizations that have already deployed MFA should begin evaluating what comes next. Organizations that have not yet completed their MFA journey should prioritize reaching that baseline as soon as possible.

Today, MFA is the minimum expectation. The conversation is now about how organizations evolve beyond traditional MFA and build an identity security program capable of defending against the threats of the next decade and beyond.

At HBS, we view MFA not as the finish line, but as the foundation. The organizations that succeed over the next five years will be the ones that treat identity security as a continuous journey, adapting their authentication strategies as quickly as attackers evolve theirs.

The organizations still struggling with MFA implementation should remember one important fact: every mature identity program started exactly where they are today. The difference is that they started the journey.

Ready to strengthen your identity security? Start by connecting with HBS.

Frequently Asked Questions

Is SMS-based MFA still safe to use?

SMS MFA still blocks many password-only attacks. It does not stand up well against SIM swapping or adversary-in-the-middle attacks. Organizations moving off SMS should prioritize FIDO2 keys or passkeys for their highest-risk accounts first.

What is phishing-resistant MFA?

Phishing-resistant MFA uses cryptographic keys tied to a specific device and service, so a stolen credential cannot be reused elsewhere. FIDO2 security keys, Windows Hello for Business, and device-bound passkeys all fall into this category.

What's the difference between MFA and passwordless authentication?

MFA adds a second factor on top of a password. Passwordless authentication removes the password entirely and relies on a device-bound credential or biometric instead. Passkeys are the most common passwordless method today.

How do I know if my MFA deployment has gaps?

Common gaps include admin accounts protected while standard users are not, remote access covered while email is not, legacy authentication protocols still active, and service accounts excluded from enforcement. Each gap gives an attacker a path around the controls already in place.

Should smaller organizations wait for passkeys before finishing MFA rollout?

No. Full MFA coverage across every user and account reduces more risk than a partial passkey rollout. Organizations still working toward baseline MFA should finish that deployment first, then evaluate passwordless options.

Related Content

The text "MFA Bombing Beating Back the Bad Guys" on a white and grey textured background.

Combatting MFA Bombing

Identify and prevent MFA bombing attacks. Stay vigilant and protect your accounts by recognizing legitimate MFA requests and following best security practices.

Learn More »
Blog banner with the title “Rising Risks, Proactive Defenses for Mobile Security,” spotlighting strategies for securing mobile devices in an increasingly connected world.

Mobile Device Security: Phishing, Mishing, and More

Protect your business from evolving mobile threats. Learn the top mobile security risks, best practices to mitigate them, and how HBS can help.

Explore More »
Person in a blue shirt holds blueprint plans against their chest while using a smartphone at a desk setup with a computer, lamp, and plant nearby.

Still Using Text Message MFA? Time to Plan Ahead

Microsoft is retiring SMS and voice MFA by Feb. 1, 2027, shifting Entra ID to passkeys. Learn what’s changing and how HBS can help you prepare.

Start Here »
  • Authentication, MFA, Phishing, Security, Security Awareness
Blog

Connect:

[email protected]  |  800.236.7914

HBS logo

HQ | 1700 Stephen Street
Little Chute, WI 54140
Locations

HBS Remote Support | Service & Technical Support | E-Bill Portal
Standard Terms & Conditions | Cookie Policy | Privacy Policy | Onboarding Form | End User Agreements | E-Bill FAQ | Site Map
Any purchase is governed by the HBS Standard Terms and Conditions.
©2026 Heartland Business Systems. All rights reserved.

Halo from HBS
This chat may be recorded as described in our Privacy Policy.