Qutzl LLC LogoQutzl Insights
3 min read

Phishing-resistant MFA for executives first

Why the CEO's mailbox is the first account that deserves FIDO2 or passkeys, not another SMS code.

Executives get phished like everyone else. The difference is what happens after the password works. Their mailboxes hold wire approvals, board threads, attorney correspondence, and enough context to impersonate the company convincingly. App-based MFA helps, but push fatigue and real-time phishing kits have made “something you approve on your phone” a weaker bar than it used to be.

Phishing-resistant MFA means factors that cryptographically bind the login to the real site, typically FIDO2 security keys or platform passkeys. These are not magic, but they remove the “type your code into the fake portal” failure mode that still beats SMS and many authenticator flows.

Why executives go first

They are high-value targets. Attackers research titles, travel schedules, and vendor relationships before they send the lure. One compromised executive account can fund payroll fraud, BEC, and lateral movement into finance systems in a single afternoon.

They set the tone. If the owner refuses a hardware key because it feels inconvenient, IT will fight the same battle with every manager. When leadership enrolls first and keeps a backup key in a drawer, the rest of the org notices.

Their exceptions become permanent. “Just use SMS while I’m on the road” turns into years of weak MFA on the account that matters most. Executives need a travel plan (backup key, second device, supervised break-glass), not a downgrade.

What to deploy

For Microsoft 365 and most major SaaS tenants today, the practical stack looks like this:

  • Primary: FIDO2 security key or platform passkey (Windows Hello, iCloud Keychain where policy allows)
  • Backup: second key stored offline, or a second enrolled device, not SMS as the only fallback
  • Break-glass: one documented emergency admin path that is excluded from user policies on purpose

Do not hand executives a consumer key with no backup and no enrollment window. You will get locked out during a board meeting.

What not to do

  • Do not roll out phishing-resistant MFA company-wide on day one if nobody has enrolled anything yet. Admins and executives first, then finance, then everyone else.
  • Do not treat SMS as “good enough for the owner because they are busy.” Busy people click links.
  • Do not skip Conditional Access. Requiring a FIDO key only on the web sign-in an attacker uses is the point; legacy protocols and token theft still need separate controls.

How to decide timing

If you are still on password-only sign-ins, fix that before you debate key brands. If you already enforce app-based MFA for all users, your next budget conversation should be keys for privileged roles, not another awareness poster.

Ask three questions in the leadership meeting:

  1. Who can approve money movement from email alone?
  2. Whose mailbox would we use to convince staff to change banking details?
  3. Are those accounts on phishing-resistant MFA today?

If the answer to question three is no, you have a priority list.

Bottom line

Start phishing-resistant MFA with executives and other high-impact accounts, give them a real backup plan, and enforce it with Conditional Access so weak factors cannot sneak back in. Everyone else can follow in waves, but the accounts attackers want most should not be the last ones you protect.