Glossary
Phishing-resistant MFA
Authentication bound to the real site and device, such as FIDO2/WebAuthn keys or Okta FastPass, that a fake login page or push flood cannot defeat.
Phishing-resistant MFA uses authenticators whose response is cryptographically bound to the legitimate site and, usually, to a device: FIDO2/WebAuthn security keys and platform authenticators, smart cards, or Okta FastPass. A proxy phishing page cannot relay the response, and there is no push prompt for an attacker to spam, which defeats both adversary-in-the-middle phishing and MFA fatigue. Okta Security recommends such authenticators for administrators in its guidance on cross-tenant impersonation and on session hijacking. It does not protect the recovery process: a factor reset by a deceived helpdesk still hands the account over.