Cybersecurity

Move beyond SMS codes for safer sign-ins

Free attack unsecured laptop vector

Multi-factor authentication, often shortened to MFA, asks for another check when someone signs in. It helps stop a stolen password from becoming an account takeover.

Text message codes are better than using a password alone, but they are no longer the strongest option. A criminal may trick a phone provider into moving your number to another SIM, intercept a message or capture the code through a fake sign-in page.

For accounts that hold business email, customer information or financial records, it is worth moving to a safer sign-in method.

Why SMS codes have limits

A text message travels through the mobile phone network. Your business does not control that network or the process a provider uses to move a phone number between SIM cards.

If a criminal takes control of your number, your phone may suddenly lose service while calls and text messages go to their device. They may then use texted security codes during a sign-in or password reset.

SMS codes can also be stolen through phishing. A fake Microsoft 365 page, for example, can ask for a username, password and text message code. The criminal can use those details on the real site while the code is still valid.

This does not mean you should turn SMS authentication off before a replacement is ready. A text code is still safer than a password on its own. The goal is to move important accounts to a stronger option through a planned change.

Better sign-in options

Passkeys

A passkey lets you sign in with a device you already use, protected by a fingerprint, face scan or device PIN. It checks that the website or app is the genuine one before completing the sign-in.

That makes a passkey much harder to steal through a fake login page. The exact setup and recovery process vary between services, so your business should test how staff will enrol a new device or recover access.

Physical security keys

A security key is a small device that plugs into a computer or connects to a phone. The user touches the key to approve a sign-in.

There is no code to type into a fake page. A remote attacker would usually need the key as well as any other required sign-in details. Keep a securely stored spare key and document the recovery process so a lost key does not lock someone out of a critical account.

Authenticator apps

An authenticator app is a useful step up from SMS because it does not depend on your mobile number. Some apps create a short code. Others ask you to approve a sign-in.

Typed app codes can still be captured by a convincing fake page. Basic approval prompts can also be abused if a criminal sends repeated requests and someone approves one by mistake.

Number matching is safer than a simple approve button. It asks the user to match a number shown on the sign-in screen, which helps them check that they started the request. Staff should still reject any request they did not initiate and report it.

Plan the change carefully

Start with the accounts that could cause the most damage if compromised. This usually includes administrator accounts, business email, banking, accounting and systems that hold customer information.

Before rollout:

  • Check which sign-in methods each service supports.
  • Choose the method that suits the account and the way staff work.
  • Give staff a clear enrolment guide.
  • Set up secure recovery options and spare keys where needed.
  • Test the process with a small group before changing everyone.
  • Remove old sign-in methods only after the replacement works.

Administrators should use separate accounts for administration and everyday work. Their stronger sign-in method should not depend on SMS.

Make safer sign-ins easier for staff

People are more likely to accept a change when they understand what it prevents and know where to get help. Explain that the new process protects email, payments and customer information, rather than presenting it as another IT rule.

Use our Microsoft 365 Security Checklist to record which accounts have MFA and which sign-in methods they use.

Still relying on text message codes for important accounts? Book an MFA planning consultation with JCPIT Support. We will map the available sign-in methods and plan the change without locking staff out.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
The Daily Cloud Checkup: A Simple 15-Minute Routine to Prevent Misconfiguration and Data Leaks
Next Article →
The Server Refresh Deadline: Why Windows Server 2016’s End of Support Should Drive Your Cloud Migration Plan