The Dispatch

MFA in 2026: Why Push Notifications Are Out and Passkeys Are In

Written by John Ohlwiler | 9/10/26, 11:45 AM

 

Attackers now exploit it through MFA fatigue attacks, bombarding users with approval requests until someone clicks "Accept." Passkeys eliminate this vulnerability entirely. They are phishing-resistant, device-bound, and already replacing push MFA across industries.

What Is Push Notification MFA and Why Was It a Big Deal?

Multi-factor authentication (MFA) was a genuine leap forward when it became mainstream. Rather than relying on a password alone, push MFA sends a notification to your phone asking you to tap "Approve" when you sign in. It added a second layer of verification and blocked the vast majority of credential-stuffing attacks.

As of early 2025, roughly 70% of workforce users had MFA enabled, according to Okta's Secure Sign-In Trends Report.¹ That adoption story is a real win. But security is not a checkbox you fill in once. What was strong two years ago is now an active attack surface.

What Is MFA Fatigue and How Are Attackers Exploiting It?

MFA fatigue (also called push bombing) is exactly what it sounds like. Attackers who have obtained valid credentials flood a target with push approval requests. Some users approve them by accident. Others, after receiving dozens of notifications at 2 a.m., approve just to make it stop.

The Verizon 2025 Data Breach Investigations Report documented this technique in detail, noting that attackers rely on "repeated MFA push notifications to victims until they press Accept out of fatigue or confusion."² The FBI and CISA both called out the Scattered Spider threat group for using push bombing against organizations in telecommunications, financial services, gaming, and retail.

This is not a theoretical risk. It is an active attack pattern targeting businesses of every size.

Why Push MFA Falls Short in 2026

The core problem with push notification MFA is that it is still phishable. An attacker who steals your username and password can trigger a legitimate-looking push notification. All it takes is one distracted moment from an employee.

CISA has been direct on this point: "FIDO/WebAuthn or PKI-based MFA are the only forms resistant to phishing, push bombing, and SIM swap attacks."³ Everything else, including SMS codes, authenticator app push notifications, and even time-based one-time passwords (TOTP), carries some exploitable vulnerability.

If your business is still running purely on push notification MFA, you have not solved the authentication problem. You have delayed it.

What Are Passkeys and How Do They Work?

A passkey replaces the traditional username-and-password combination with a cryptographic key pair. One key lives on your device (or in your device's secure enclave). The other is registered with the website or application. When you authenticate, your device proves its identity using biometrics or a PIN to unlock the private key. Nothing sensitive is ever transmitted over the network.

This matters for two reasons. First, there is no password to steal. Second, the authentication is cryptographically bound to the legitimate service. A fake login page cannot intercept a passkey handshake because the domain itself is part of the authentication process.

There are now 5 billion active passkeys in use worldwide.⁴ That is not a niche technology. It is a standard that major platforms have already adopted and that businesses are deploying at scale.

Where Does Passkey Adoption Stand Right Now?

The 2026 FIDO Alliance report puts the numbers in sharp relief:

  • 90% of consumers now have passkey awareness, up from 75% just a year prior.⁴

  • 75% of consumers have enabled passkeys on at least one account.⁴

  • 68% of organizations with 500 or more employees are actively deploying passkeys for workforce authentication.¹

  • 30% have already made passkeys their primary sign-in method.⁴

The business case is not just security. Organizations that have deployed passkeys report 45% faster employee login times, a 35% reduction in password reset helpdesk tickets, and 32% fewer phishing-related incidents.⁴

Compare that to traditional push MFA, which carries a 63% login success rate. Passkeys deliver a 93% login success rate in the same user population.¹ That is a security improvement and a productivity improvement in the same move.

What Should Your Business Do Right Now?

You do not need to rip out your current MFA setup overnight. But you do need a plan. Here is how Sentry approaches it with clients working through the Secure stage of the Technology Maturity Model:

  • Step 1: Assess what MFA methods are currently in use. Not all MFA is equal. Push notifications, SMS codes, and TOTP apps each carry different risk profiles. Understanding your current posture is the starting point.

  • Step 2: Enable number matching as an interim control. If push MFA is staying in the short term, require users to match a number displayed during sign-in to the push notification. It does not eliminate the risk, but it significantly reduces the effectiveness of push bombing.

  • Step 3: Prioritize phishing-resistant MFA for high-value accounts. Executive accounts, finance access, IT administrator accounts, and any system handling sensitive data should move to passkeys or FIDO2-compliant hardware keys first.

  • Step 4: Build toward a passkey-first environment. Microsoft, Google, Apple, and most enterprise platforms now support passkeys natively. A roadmap to passkey adoption is a reachable goal, not a distant aspiration.

If you are unsure where to start, that is exactly what a technology assessment is for.

Frequently Asked Questions

Do passkeys work with Microsoft 365 and Google Workspace?

Yes. Both Microsoft and Google support passkeys for workforce authentication. Microsoft Entra ID (formerly Azure AD) has native passkey support, and Google Workspace supports FIDO2-compliant passkeys for organizational accounts.

Are passkeys harder for employees to use than push notifications?

No. They are typically faster. Employees authenticate using a fingerprint, face scan, or device PIN. There are no codes to copy, no approval windows to find, and no push notifications to wait on. The 93% login success rate versus 63% for traditional push MFA reflects that real-world ease of use.¹

What happens if an employee loses their device?

Passkeys can be managed and revoked centrally, the same way a lost access badge is deactivated. Recovery flows depend on the platform, but enterprise deployments typically use a managed credential backup or IT-administered recovery method.

Is push notification MFA still better than just a password?

Yes, absolutely. Any form of MFA is significantly better than a password alone. The point is not that push MFA is worthless. The point is that it is no longer sufficient as your primary defense for sensitive access.

How do I know if my business is ready to make the switch?

A security assessment will tell you quickly. The relevant questions are: which systems support FIDO2 authentication, which accounts carry the highest risk, and what does your current helpdesk load from password resets look like? Sentry can run that evaluation for you.

The Bottom Line: Push notification MFA solved yesterday's problem. Passkeys solve today's. Reach out to the Sentry team at sentryitsolutions.com for a technology assessment. We will show you exactly what your authentication posture looks like and what it takes to close the gaps.

REFERENCES

1. Okta, Secure Sign-In Trends Report 2025. Data via Swif.ai, "MFA Statistics for 2026." https://www.swif.ai/blog/mfa-statistics

2. Verizon, 2025 Data Breach Investigations Report, Verizon Business, 2025.

3. Cybersecurity and Infrastructure Security Agency (CISA), phishing-resistant MFA guidance, in coordination with the FBI.

4. FIDO Alliance, 2026 FIDO Report: Passkeys at Global Scale, summarized by Descope, 2026. https://www.descope.com/blog/post/2026-fido-report