top of page
  • X
  • Linkedin

Why Businesses Are Switching from SMS Codes to Security Keys

Oct 2
8 min read

A stolen password used to be enough to break into a business account. Then multi-factor authentication raised the bar. Now attackers have changed their tactics again.


For years, many organisations have relied on SMS codes or authenticator app codes to protect email, cloud storage, finance systems and admin portals. That was a clear improvement over passwords alone. If someone guessed or bought a password, they still needed the second factor.


The problem is that traditional MFA is no longer the barrier it once was.


Phishing kits can now capture usernames, passwords and one-time codes in the same session. Some attacks trick users into approving login prompts they did not start. SMS messages can be intercepted, redirected or delayed. Even when mobile-based MFA works, it can create practical headaches for staff and IT teams.


That is why more businesses are looking at security keys. Devices such as YubiKey hardware keys from Yubico use a physical key to confirm the user and the website they are signing in to. Instead of typing a code from a text message, the user plugs in or taps a key, then touches it to complete the login.


The change sounds small. The security difference can be significant.


Close-up view of a small hardware security key beside a laptop keyboard
A physical key makes the login process harder to fake.

Why passwords and SMS codes are showing their age


Passwords remain a weak point because people have too many of them. Even with password managers, reused and weak passwords still appear across business systems. Attackers know this, so they target the login process itself.


SMS codes were once seen as a simple second step. The user enters a password, receives a text message, types in the code and gains access. It is easy to understand, which helped MFA adoption.


But SMS has several weaknesses:


  • Mobile numbers can be moved or abused through social engineering.

  • Messages can be delayed when signal is poor.

  • Staff may lose access when they change phones or travel.

  • Personal mobiles become part of the business security process.

  • Phishing pages can ask for the code in real time.


Authenticator apps fix some of those problems. They do not rely on mobile networks, and they are usually safer than SMS. Yet many app-based codes are still phishable. If a fake login page asks for the six-digit code, a busy user may enter it without noticing anything is wrong.


Push notifications can also create risk. In an MFA fatigue attack, a criminal repeatedly sends approval requests until someone taps “approve” just to stop the interruptions, or because they assume the request is genuine.


The core issue is simple: traditional MFA often proves that a user has a code, but it may not prove they are on the real website.


That gap matters most for services such as Microsoft 365, where one compromised account can expose email, files, calendars, Teams chats and third-party app connections.


What a security key does differently


A security key is a small physical device used during sign-in. It may connect by USB-A, USB-C or NFC, depending on the model and the device being used. Some keys also support Lightning or other connection methods.


The user signs in as usual, then proves possession of the key by touching it or tapping it against a compatible device. Behind the scenes, the key uses public key cryptography to confirm the login.


That sounds technical, but the idea is straightforward.


When a security key is registered with a service, it creates a unique cryptographic relationship with that service. The secret never leaves the key. At login, the service sends a challenge, and the key responds in a way that proves it is the same registered key.


Crucially, modern security keys based on FIDO2 and WebAuthn also check the website origin. That means the key knows whether the user is signing in to the real service or a lookalike phishing site.


If someone lands on a fake Microsoft 365 sign-in page, the security key should not complete authentication for that fake site. The attacker may still capture the password, but they do not get the successful second factor they need.


That is the main reason security keys have become more attractive for business use. They are not just another code. They help tie authentication to the legitimate service.


Eye-level view of a security key plugged into a tablet on a stone kitchen counter
Security keys can work across different devices without relying on SMS.

Why phishing resistance is the main advantage


Phishing remains one of the most common ways attackers gain access to business accounts. It works because it targets people during familiar tasks. A message looks like a file share, an invoice, a Teams notification or a password expiry warning. The page looks convincing enough. The user is busy.


With password and SMS-based MFA, the attacker can guide the user through the whole process:


  1. The user enters their email address.

  2. The user enters their password.

  3. The fake page asks for the MFA code.

  4. The attacker uses those details on the real site before the code expires.


This is often called real-time phishing or adversary-in-the-middle phishing. The user may never realise what happened until suspicious mailbox rules appear, files are accessed or invoices are tampered with.


A security key changes that flow. The fake page cannot simply ask the user to type in a valid one-time code. The key must authenticate to the real domain. If the domain does not match, the login fails.


This is why security keys are often described as phishing-resistant MFA.


No single control removes all risk. Malware, poor recovery processes and weak admin practices can still create problems. But security keys close a major gap that SMS and app codes leave open.


For high-risk accounts, that difference is especially valuable. Admin accounts, finance users, directors, HR staff and anyone with access to sensitive data should have stronger protection than a text message code.


The user experience can be simpler


Security is easier to maintain when people do not hate using it. This is where security keys can surprise teams.


Many users are used to MFA being a minor interruption. They fetch a phone, unlock it, wait for a text or open an app, then type a number into a browser. If the phone battery is low, the mobile signal is poor or the app has moved to a new device, the login process slows down.


A security key can be more direct.


The process often looks like this:


  1. Enter the username.

  2. Enter the password, unless passwordless sign-in is enabled.

  3. Touch or tap the security key.


For some setups, the password can be removed from the daily sign-in flow altogether. The user may sign in with a security key and a PIN or biometric step, depending on the platform and policy.


That helps for several reasons:


  • There is no code to read or mistype.

  • The user does not need to share a personal phone number.

  • The key can move between supported devices.

  • The process is consistent across many services.

  • IT teams spend less time dealing with phone changes.


This matters in real working conditions. Staff travel. Contractors use different devices. People replace phones. Some employees do not want business authentication tied to their personal smartphone. Others work in areas where mobile signal is unreliable.


Security keys give businesses another path. They reduce reliance on mobile networks, personal devices and one-time codes.


Top-down view of a hardware security key attached to a simple keyring on a linen cloth
A security key can be carried like any other work key.

How business security keys support Microsoft 365


Microsoft 365 is often one of the first places businesses look when improving account security. It holds email, documents, Teams conversations and identity connections to other tools. If attackers compromise a Microsoft 365 account, they may gain a useful foothold.


Microsoft supports FIDO2 security keys through Microsoft Entra ID, formerly Azure Active Directory. That allows organisations to use compatible hardware keys for secure sign-in, including passwordless options where policies allow.


A well-planned rollout can improve Microsoft 365 security without making sign-in harder. For example, a business may start by requiring security keys for administrators and privileged users. It may then expand to finance, leadership and other roles with access to sensitive systems.


This is also where keyword-heavy searches tend to point in the same direction. Businesses looking for YubiKey for Business often also compare Microsoft 365 security options, YubiKey Microsoft 365 deployment paths and passwordless authentication policies.


The key is to avoid treating security keys as a loose accessory. They work best when they are part of a clear identity plan.


That plan should cover:


  • Which users need keys first.

  • Which services will accept security key sign-in.

  • How spare keys are issued and stored.

  • What happens if a user loses a key.

  • How onboarding and offboarding will work.

  • Which recovery methods are allowed.


Recovery deserves special care. If the backup process falls back to weak SMS verification, attackers may simply target the recovery route instead. Strong authentication needs strong recovery rules too.


When SMS still has a place


Security keys are more secure than SMS for many business scenarios, but that does not mean every organisation can remove SMS overnight.


SMS may still be useful during transition, for lower-risk accounts or as a temporary fallback while a wider rollout is planned. Some legacy systems may not support modern authentication methods. Some users may need extra support during the change.


The goal should be to reduce dependence on weak methods over time, not create chaos by switching everything at once.


A practical approach is to rank accounts by risk.


High-priority users may include:


  • Global administrators and IT admins.

  • Finance and payroll staff.

  • Senior leaders.

  • HR users with access to personal data.

  • Staff who handle sensitive client information.

  • Users who are regularly targeted by phishing.


These groups benefit most from phishing-resistant MFA. Once the organisation has a working process, security keys can be extended more broadly.


What to consider before rolling out security keys


A successful security key rollout is not only a technical task. It also needs clear communication and simple rules.


Start with compatibility. Check the systems, browsers and devices people use. USB-A keys suit older laptops and desktops. USB-C keys suit many newer devices. NFC can be useful for compatible phones and tablets.


Next, decide how many keys each person needs. Many organisations issue a primary key and keep a spare registered key in a secure place. This prevents a lost key from becoming a major business interruption.


Training should be short and practical. Users need to know:


  • What the key is for.

  • How to use it during sign-in.

  • What to do if a prompt appears unexpectedly.

  • How to report a lost key.

  • Why the key should not be shared.


Keep the message simple. A security key is like a physical access card for digital systems. If someone else has it, or if it goes missing, IT needs to know.


Policies should also cover contractors, shared devices and remote workers. If people work across different locations, posting, replacing and revoking keys must be planned.


Wide-angle view of several hardware security keys in labelled storage trays
A clear issue and recovery process helps security keys work at scale.

The move beyond codes is already under way


Passwords and SMS codes helped businesses take the first step towards better account security. They still offer more protection than a password alone. But attackers have learnt how to work around them, especially through phishing.


Security keys raise the standard. They make it much harder for a fake login page to capture everything needed for access. They reduce dependence on personal mobiles. They can make daily sign-in faster. They also fit well with modern identity platforms, including Microsoft 365.


The best starting point is not to replace every login method at once. Start with the accounts that would cause the most damage if compromised. Put strong recovery processes in place. Give users clear instructions. Then expand as confidence grows.


For many businesses, the question is no longer whether MFA is needed. It is whether the MFA in place is strong enough for the threats people face now. Security keys are becoming the clearer answer.


Comments


bottom of page