Phishing-resistant MFA is authentication that cannot be tricked, relayed or replayed by an attacker — typically FIDO2 passkeys or security keys bound to the real login domain — and it is now the single most effective control a UAE business can deploy against AI-powered credential theft. SMS codes and push approvals were a good first step; in 2026 they are the step attackers have learned to walk straight through.
The numbers are hard to ignore. The UAE Cybersecurity Council reports that more than 90% of digital breaches are now supported by AI-driven phishing and fraud techniques, and that over 75% of breaches in the country begin with a phishing email or fraudulent message. A CyberArk study found 92% of UAE organisations suffered at least three successful identity-related breaches in the twelve months to April 2026 — well above the EMEA average of 80%. Proofpoint’s account-takeover research adds the uncomfortable detail: in 59% of compromised accounts, MFA was already switched on.
Why traditional MFA is no longer enough
Most organisations in Dubai and the wider GCC rely on one-time codes or “approve sign-in” push notifications. Three attack patterns now defeat both routinely.
Adversary-in-the-middle (AiTM) phishing
Kits such as Evilginx and Tycoon 2FA sit between the victim and the real Microsoft 365 or Google login page, proxy every keystroke — including the MFA code — and steal the resulting session cookie. The attacker never needs the password again; they simply replay the session.
Device code phishing
Attackers abuse Microsoft’s legitimate device-authorisation flow. The victim receives a convincing HR, DocuSign or government-themed message, enters a short code on a genuine microsoft.com page, and unknowingly issues the attacker a long-lived refresh token. Proofpoint’s regional lead describes the technique as “exploding across the threat landscape” in the UAE, with new tooling appearing weekly. Because the token persists, changing the password does not evict the intruder.
MFA fatigue and AI-crafted lures
Push-bombing floods a user with approval prompts until one is accepted, while generative AI now produces flawless Arabic and English lures that mimic UAE banks, ministries and courier firms. The tell-tale spelling errors staff were trained to spot have gone.
What “phishing-resistant” actually means
An authentication method is phishing-resistant when the credential is cryptographically bound to the genuine website’s origin and never leaves the user’s device. A passkey created for login.microsoftonline.com will simply refuse to respond to a proxy at a look-alike domain, so there is nothing to steal and nothing to relay. In practice this means:
- FIDO2 passkeys synced through Windows Hello, Apple iCloud Keychain or Google Password Manager — the fastest route for most SMEs.
- Hardware security keys (YubiKey, Feitian) for administrators, finance teams and anyone with privileged access.
- Certificate-based authentication on managed, compliant devices, tied to Conditional Access.
Adoption is accelerating globally: the FIDO Alliance estimates over 5 billion passkeys are now in use, and roughly 68% of enterprises are deploying them for staff. Cyber insurers have also shifted — missing or partial MFA is now among the leading reasons a policy application is declined at first submission.
A 90-day roll-out plan for UAE businesses
Days 1–30: Close the doors attackers use most
- Enable Microsoft Entra token protection and continuous access evaluation so a stolen session cookie fails outside the device that created it.
- Block the device code flow for all users via Conditional Access unless a specific business case exists.
- Turn on number matching and disable SMS as an MFA method for administrators.
- Review OAuth app consents and revoke anything unrecognised.
Days 31–60: Move privileged users to phishing-resistant methods
- Issue hardware keys to global admins, finance approvers and executives; enforce them with an authentication-strength policy.
- Register a backup key per user and store it securely — lock-out is the most common reason projects stall.
- Pair this with a privileged access management review so admin rights are just-in-time rather than standing.
Days 61–90: Extend passkeys to everyone
- Enable passkeys in Microsoft Authenticator and platform authenticators; run a pilot with one department, then roll out by group.
- Restrict legacy authentication and require compliant devices for access to email and files.
- Feed sign-in logs into 24/7 monitoring so anomalous token use is caught in minutes, not months — our managed detection and response guide explains what good coverage looks like.
Comparing MFA methods
| Method | Stops AiTM proxy? | Stops device code phishing? | Stops MFA fatigue? |
|---|---|---|---|
| SMS / email one-time code | No | No | N/A |
| Authenticator app code | No | No | N/A |
| Push with number matching | No | No | Partly |
| Passkey / FIDO2 security key | Yes | Yes (with flow blocked) | Yes |
| Certificate-based on managed device | Yes | Yes (with flow blocked) | Yes |
The regulatory angle
The UAE PDPL requires “appropriate technical measures” to protect personal data, and the National Cyber Accreditation Programme rolling out through 2026 will hold critical-infrastructure suppliers to baseline identity controls. Strong, phishing-resistant authentication is the clearest evidence a business can offer a regulator, auditor or insurer that it took credential theft seriously before an incident, not after. Our Microsoft 365 security guide covers the wider tenant hardening that should accompany it.
Frequently asked questions
Is Microsoft Authenticator phishing-resistant?
Not by default. Push approvals and six-digit codes from Authenticator can be relayed by an adversary-in-the-middle kit. Authenticator becomes phishing-resistant only when you enable its passkey capability and enforce it through an Entra authentication-strength policy.
Do we need hardware keys for every employee?
No. Hardware keys are the right choice for administrators, finance and executives. For the wider workforce, synced passkeys on managed laptops and phones deliver the same cryptographic protection at almost no cost, with far less help-desk friction.
How long does a passkey roll-out take for a 200-user UAE business?
Typically six to twelve weeks. Privileged users can move within days; the remainder is change management — enrolment guides in Arabic and English, a pilot group, and a help-desk process for lost devices. Isstah usually runs it alongside a Conditional Access review so the policies land together.
About the author — Written by the Isstah Technologies team. Isstah Technologies is a Dubai-based IT and cybersecurity system integrator serving businesses across the GCC, delivering cybersecurity, cloud integration, network & infrastructure, and digital transformation. Want a phishing-resistant MFA design for your Microsoft 365 or Google Workspace tenant? Talk to our Dubai team or WhatsApp +971 56 277 4060 for a free consultation.