← Law-firm security

MFA for Law Firms: Which Methods Actually Resist Phishing?

Not all multifactor authentication provides the same protection. Here is how security keys, passkeys, authenticator apps, push prompts, and text codes differ.

Turning on multifactor authentication is one of the highest-value security improvements a small firm can make. But “MFA enabled” is not the end of the decision. The method matters.

Some methods add friction for an attacker but can still be captured or approved during a convincing phishing attack. Phishing-resistant methods are designed so that a credential created for the real service cannot simply be replayed at an impostor website.

Both CISA and NIST recommend moving sensitive and privileged accounts toward phishing-resistant authentication.

A practical hierarchy

Strongest widely available option: security keys and passkeys

FIDO/WebAuthn authentication uses cryptography tied to the legitimate website. The user does not type a reusable code that a fake login page can steal. The authenticator may be a physical security key or a passkey stored on a phone, computer, or password manager.

Use it first for:

  • firm email administrators;
  • practice-management administrators;
  • accounting, payroll, and banking access;
  • cloud-storage administrators;
  • domain, website, and DNS accounts;
  • password-manager accounts; and
  • anyone with access to especially sensitive matters.

Keep more than one enrolled authenticator for critical accounts and store the spare securely. A strong login method without a recovery plan can create its own business-continuity problem.

Good interim option: authenticator-app codes

Time-based one-time codes from an authenticator app are generally preferable to text messages because they do not depend on the mobile telephone network. But the user still types a code into a website, so a real-time phishing site can capture and relay it.

Use authenticator apps when passkeys or security keys are unavailable, while planning an upgrade for the most consequential systems.

Improve push notifications with number matching

A simple “Approve/Deny” notification can be abused through repeated prompts, hoping a tired or confused user eventually approves one. Number matching requires the login screen and the trusted device to display or confirm the same number. CISA describes this as a more secure interim measure when phishing-resistant MFA is not yet available.

No employee should approve an unexpected login prompt. An unexpected prompt is a security event worth reporting, not a nuisance to dismiss.

Last resort: SMS or voice codes

Text and voice codes are better than a password alone, but they can be exposed through phishing, account recovery weaknesses, telephone-number transfer fraud, or compromised messaging access. Use them where they are the only option, not as the firm’s preferred standard.

Roll it out without locking out the firm

1. Inventory important accounts

Start with email, file storage, practice management, payment processing, banking, payroll, accounting, remote access, password management, the domain registrar, and social media. Record the account owner, administrators, recovery method, and available MFA types.

2. Protect administrators first

Administrator accounts can change settings, add users, export data, reset authentication, or disable protections. Secure them before ordinary accounts, then expand coverage to everyone.

3. Separate daily and administrative identities

Where the service permits it, do routine work from an ordinary account and reserve administrative access for configuration changes. A phished daily account should not automatically confer control over the whole firm.

4. Enroll recovery methods deliberately

Avoid recovery that silently reduces a strong account to a text message or a shared inbox. Keep recovery codes offline in a protected location. Document who may use them, when, and how the event will be reviewed.

5. Test before enforcement

Enroll at least two permitted authenticators for critical accounts. Test normal login, a lost-device scenario, staff departure, and emergency access. Then enforce MFA so users cannot opt out.

6. Train around one simple rule

Employees should never approve a login they did not initiate. They should navigate to important services from a saved bookmark or password manager rather than an email link, and report suspicious prompts immediately.

Questions for each provider

  • Does the service support passkeys or FIDO2 security keys?
  • Can an administrator require the strongest method and disable weaker fallbacks?
  • Can users enroll a new authenticator without additional approval?
  • Are authentication and recovery events logged?
  • Can alerts be sent when MFA settings change?
  • Can all sessions and trusted devices be revoked quickly?
  • What happens to access when an employee leaves?

A sensible MFA rollout makes a stolen password, and even a convincing fake login page, insufficient to enter the firm’s most important systems.

Primary references

This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction—consult yours.

Usus founders program

Help shape legal AI that shows its work

Tell us a little about you and the legal work you want technology to handle more rigorously. Lu Jin will review every submission.

By submitting, you agree that Usus may contact you about the founders program and related product updates. Read our privacy notice.