October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Replace SMS MFA With Passkeys: An Organization’s Migration Plan

CISA and NIST guidance points organizations away from SMS codes and toward phishing-resistant FIDO authentication. Here’s how to choose passkeys or security keys, plan recovery, and manage legacy systems.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organizations should plan to replace SMS-based multi-factor authentication (MFA) with phishing-resistant FIDO authentication, including passkeys where they fit. The direction is clear in CISA and NIST guidance, but there is no single deadline in that guidance that applies to every organization. The right rollout depends on your systems, users, assurance requirements, and recovery design.

Why organizations are moving away from SMS MFA

A text-message code can be intercepted or relayed. When a user manually enters a one-time password, the code is not cryptographically bound to the particular website or sign-in session. A convincing impostor site can therefore capture the code and pass it to the legitimate service during an active sign-in.

As an Amazon Associate I earn from qualifying purchases.

NIST SP 800-63B Revision 4 says manually entered authenticator outputs, including OTPs, are not phishing-resistant for this reason. It classifies PSTN-based authenticators such as SMS OTP as restricted and requires a migration plan for possible future unacceptability within the guideline’s applicable digital-identity context. That is not a universal private-sector cutoff date.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s January 2023 guidance describes FIDO/WebAuthn as the practical route to phishing-resistant MFA, and says support is built into major browsers, operating systems, and smartphones. In December 2024, its mobile communications guidance recommended migrating away from SMS-based MFA. These are strong signals to plan a transition, not proof that every organization must remove SMS on the same date.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What replaces SMS: passkeys, platform authenticators, or security keys?

FIDO authentication uses cryptographic credentials that work with the intended service rather than relying on a code that a user types into a page. A passkey is one way to use this approach; adopting FIDO does not automatically mean buying a physical key for every employee.

Option How it works When it may fit Planning point
Platform passkey Uses an authenticator built into a phone or computer. Users have supported devices and the organization’s identity provider and applications support FIDO/WebAuthn. Check device coverage, credential management, syncing policy, and recovery before making it the standard.
Syncable passkey Can be available across a user’s devices through a credential-syncing service. Cross-device use and easier recovery are useful, and the organization’s assurance requirements allow it. Assess who can access synced credentials and what controls the syncing provider offers. NIST’s April 2024 supplement describes conditions under which syncable authenticators can support phishing resistance, including use at AAL2 with additional requirements; it also notes that this approach is not suitable for every service.
Roaming FIDO security key A separate physical authenticator, used with compatible devices and services. Some users need an authenticator independent of their phone or computer, or need a backup or shared-device arrangement. Verify connector or NFC needs, supported operating systems, identity-provider compatibility, issuance, replacement, and spare-key handling for the specific model.
SMS OTP A sign-in code is delivered over the phone network and manually entered. May remain temporarily for a system that cannot yet support a stronger method. It is not phishing-resistant. Treat continued use as an exception with an owner and a migration plan.

For syncable authenticators, NIST’s 2024 supplement describes potential usability benefits, including cross-device support and simplified recovery, while making clear that suitability depends on the application and implementation. Do not assume a passkey provider’s syncing model meets every organization’s credential-control or assurance requirements.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to replace SMS MFA with passkeys

  1. Inventory SMS use. List identity-provider accounts, business applications, administrative consoles, remote access, and recovery flows that send SMS codes. Record the user groups affected and whether each application supports FIDO/WebAuthn directly or through enterprise identity or single sign-on.
  2. Prioritize high-impact access. Start with administrators and accounts that can reach sensitive data or change security settings. Identify applications where SMS is the only available MFA method, and assign an owner to each exception.
  3. Set the acceptable authenticator policy. Decide which users can use platform passkeys, whether syncable credentials meet policy, and where roaming security keys are needed. Compare options against assurance requirements, device compatibility, managed-device coverage, credential control, onboarding and recovery, support workload, and backup arrangements.
  4. Pilot enrollment and sign-in. Test enrollment, routine sign-in, device replacement, lost-device recovery, and access from the devices employees actually use. Include people who have multiple devices or use shared workstations where relevant.
  5. Document recovery before expanding. Define how users regain access if an authenticator is lost or unavailable, who verifies their identity, and how temporary access is granted and revoked. Keep a controlled break-glass route for essential operations, and protect it as carefully as the normal sign-in path.
  6. Roll out in stages and track exceptions. Expand by application or user group. Monitor enrollment and support issues, set review dates for systems still relying on SMS, and tie each exception to an upgrade or migration plan.
  7. Remove weaker fallbacks where feasible. Once passkey sign-in and recovery work reliably, disable SMS as a sign-in fallback where the service permits. A weaker alternate path can undermine the protection of the stronger primary method. Some services may still use SMS for account recovery; assess that flow separately rather than assuming every text message can be eliminated.

What to do about legacy applications

Some older systems cannot accept phishing-resistant MFA directly. CISA recommends identifying systems without MFA support and upgrading or migrating them. For business applications, enterprise identity or single sign-on integration can often add MFA without replacing every application at once.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a system cannot move immediately, record the limitation and use interim controls while planning the upgrade. CISA identifies number matching and additional controls as possible interim measures when phishing-resistant MFA is not available. Number matching can reduce some approval mistakes, but it is not phishing-resistant and should not be described as equivalent to a FIDO authenticator.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Confirm whether the application can be placed behind an identity provider that supports FIDO/WebAuthn.
  • Limit access to the users and devices that still need the legacy workflow.
  • Apply additional safeguards appropriate to the system’s risk while SMS remains in use.
  • Set an accountable owner and a review point for the migration plan rather than allowing the exception to become permanent by default.

How to handle recovery without bringing the same weakness back

Passkey enrollment is only part of the design. An organization also needs a way to handle a lost phone, a replaced computer, a failed security key, or an employee who cannot complete sign-in. If recovery simply falls back to SMS, an attacker may target that weaker route instead of the passkey.

Document who can authorize recovery, what identity checks are required, how backup authenticators are issued, and how access is removed when devices or employees leave the organization. For syncable passkeys, include the credential provider’s access and recovery controls in that assessment. For physical keys, plan issuance, secure storage of spares, and replacement.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the guidance does—and does not—require

CISA’s January 2023 fact sheet supports planning for FIDO/WebAuthn and describes platform and roaming authenticators, as well as migration planning for systems that cannot adopt phishing-resistant MFA immediately. Its December 2024 mobile guidance specifically says to migrate away from SMS-based MFA, describes hardware FIDO keys as most effective where feasible, and accepts passkeys as an alternative. It also notes that some services may retain SMS in account-recovery flows.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST’s Revision 4 guidance makes the standards case against manually entered OTPs and treats PSTN authenticators as restricted in its stated digital-identity context. Its 2024 supplement addresses syncable authenticators, including passkeys, and the conditions for their use. Neither source establishes one cross-sector deadline or a single best authenticator for every workforce. Organizations should apply the guidance relevant to their programs and risk requirements, then document their own migration sequence.

Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.