THREAT BRIEFING · 13.08.2026 DEENFRES

Practice & Implementation

Adaptive MFA: Why Break Standard Rules

By Alec Chizhik · July 21, 2026 · 5 min read

“Multi-Factor Authentication (MFA) is on” isn’t a target state. Static second factors break under prompt fatigue, session hijacking and assistance processes. Adaptive MFA manages risk per login – and relieves exactly where standard rules generate noise.

Key Takeaways

  • Risk controls the factor. Device, location, behavior and resource value determine step-up – not a generic “always push”.
  • Phishing‑resistant factors first. Passkeys/FIDO where possible; SMS and fatiguing push prompts only as a transition.
  • Hardening assistance processes. Helpdesk resets and break‑glass are often the weakest path – not the login button.

Related:What is a Passkey? Definition and Standards  /  Passkeys in the Enterprise: The End of Passwords

Where Standard MFA Fails

What is Adaptive MFA? Adaptive MFA (risk-based multi-factor authentication) controls based on signals such as device, network, behavior and resource value whether and which additional factor is required – up to blocking or passwordless-only instead of rigid push-for-all rules.

Many organizations have rolled out MFA: app push or SMS on all accounts, ticking the compliance box. Attackers and reality exploit the gaps around it. Fatigue attacks bombard users with push requests until one is approved. Session cookies and token theft bypass the second factor after login. Social engineering at the help desk resets the factor without verifying the account owner.

Adaptive MFA addresses the decision question: When is device trust sufficient, when is a phishing-resistant step-up mandatory, when is login hard-blocked?

Definition · Adaptive MFA

Risk-based multi-factor authentication: Signals (device, network, behavior, resource, identity) determine whether and which additional factor is required – up to blocking or passwordless-only.

Signals That Should Actually Be Controlled

Baseline for practice: managed vs. unknown device, geo- and network-unusual accesses, impossible travel, new browsers/UA, access to privileged apps (admin portals, financial systems, identity admin) and identity type (human, service, break-glass).

Low-Risk login from a managed device on the corporate network to a non-critical app: as frictionless as possible (passkey or SSO session). High-Risk: new location, personal device, access to Entra/AD admin – phishing-resistant step-up or deny. This reduces fatigue, because not every coffee-order login should trigger a push.

Factors sorted by resilience

Passkeys and FIDO2 security keys are the target state for privileged and broad user groups where hardware and OS cooperate. TOTP is better than SMS, but phishable. Push without number matching is fatigue‑prone; with number matching it is better, but not phishing‑resistant. SMS and voice calls remain a stopgap – and should be removed from privileged pathways.

Adaptive MFA without a factor roadmap ends up as “still SMS, only less often.” Policy must enforce the upgrade path: critical apps must use only resistant methods.

Scenario Signal Response
Everyday Managed device, known network Passkey/SSO, low friction
Travel / new New country, new device Step‑up FIDO/Passkey
Privileged IAM-/cloud admin portal Phishing‑resistant only, optionally CAE
Abuse Impossible travel, token anomaly Block + SOC alert

Source: Praxis framework SecurityToday (Conditional Access / risk‑based auth)

The Forgotten Half: Recovery and Operations

Adaptive rules are of little use if the helpdesk resets second factors over the phone the moment someone says “IT.” Recovery requires robust identity management, dual control for privileged accounts, and comprehensive logging. Break-glass accounts: documented offline, MFA-resistant, alerted upon use, and regularly tested.

Implementation Checklist

  • Tier apps: privileged / normal / low-risk with clear authentication rules
  • Pilot Passkeys/FIDO for admins, then roll out broadly
  • Push fatigue: enforce number matching or switch to resistant factors
  • Helpdesk resets and break-glass accounts with dual control and alerting

Adaptive MFA is an operational discipline, not a one-off project checkbox. Metrics to track: share of phishing-resistant logins, push-fatigue incidents, successful vs. blocked high-risk logins, and time to step-up enrollment. Only then does “MFA enabled” become a controllable security layer.

In practice, a 90-day phased approach works best: start with privileged accounts using Passkeys or FIDO, then high-risk applications with step-up authentication, and finally broad rollout with reduced noise. Monthly metrics in the security report should include: share of phishing-resistant logins, blocked high-risk attempts, and helpdesk reset incidents. This transforms MFA from a compliance checkbox into a controllable security layer that reduces user fatigue and surfaces real abuse.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Is adaptive MFA the same as Conditional Access?

Conditional Access is often the policy tool. Adaptive Multi-Factor Authentication (MFA) is the target model: risk-based factor selection. In practice, the two overlap significantly.

Can we immediately deactivate SMS?

Aim for privileged accounts. For the broader rollout: transition via Passkey enrollment, with exceptions only temporarily limited.

Does Number-Matching help against all MFA attacks?

It mitigates fatigue abuse, but does not replace phishing-resistant factors and does not protect against token theft after login.

First: Passkeys or adaptive rules?

Both approaches run in parallel: resilient factors for admins, adaptive rules targeting noise and high‑risk logins. Priority is given to privileged accounts.

How do I measure success?

Share of phishing‑resistant authentication, blocked high‑risk logins, help‑desk reset incidents and user complaints of fatigue – monthly in the security report.

Lesetipps der Redaktion

LesetippWas ist ein Passkey? Definition, Funktionsweise und StandardsLesetippPasskeys im Unternehmen: Das Ende des PasswortsLesetippAdaptive MFA im NIS2-Audit: Wann die Policy zum Nachweis taugt

Mehr aus dem MBF Media Netzwerk

cloudmagazinDie Copilot-Wende: erst mussten die Menschen an Bord seinMyBusinessFutureMehr Tempo im Back Office: Wie Banken ihre dokumentenintensiven Prozesse endlich in den Griff bekommenDigital ChiefsKimi stoppt Abos: 7 Checks fürs KI-Capex

Bildquelle: KI-generiert (Juli 2026)

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH