ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Passkeys, Authenticator Apps and SMS: Choosing MFA for a Law Firm

Not all multi-factor authentication is equally strong. Compare SMS codes, authenticator apps, push approvals and passkeys to choose the right mix for your firm.

3 min readBy Counsel Cyber Team

Multi-factor authentication is the most important single control for protecting law firm accounts, and most firms have turned it on in some form. But the type of MFA matters. Attackers have developed ways to defeat the weaker methods, so it is worth knowing the differences and planning to upgrade.

This guide compares common options in plain language. CISA publishes guidance on MFA and encourages organizations to move toward phishing-resistant methods, so check its current materials for details.

What MFA Does

MFA requires something beyond a password, such as a code or a device, to sign in. If a password is stolen through phishing or a previous breach, the attacker still cannot get in without the second factor. The stronger the second factor, the harder it is for an attacker to work around.

The Common Methods

SMS text message codes

A code is sent to the user's phone number. This is better than a password alone and easy to roll out. The weaknesses: attackers can trick mobile carriers into moving a number to a new SIM, messages can be intercepted in some situations, and users can be tricked into reading a code to a caller or typing it into a fake login page.

Verdict: acceptable as a fallback, not a preferred method for important accounts.

Authenticator app codes

An app on the phone generates a rotating six-digit code. It does not rely on the phone network, so SIM swapping is not an issue. But the codes can still be typed into a convincing fake login page and captured in real time.

Verdict: a solid improvement over SMS, but still phishable.

Push notifications

The user taps Approve on a prompt. This is convenient, but attackers exploit it with MFA fatigue: they trigger repeated prompts until a tired or confused user taps approve. Number matching, where the user must enter a number shown on the sign-in screen, and showing the application and location in the prompt, reduce this risk.

Verdict: acceptable if number matching and context are enabled, and with training to deny unexpected prompts.

Passkeys and security keys

These use public-key cryptography tied to a device or a hardware key and to the specific website. A fake login page cannot capture a usable credential because the key will not work on the wrong site. This is why such methods are described as phishing-resistant. Passkeys may be stored on a phone, a computer or a physical key, and vendors continue to expand support.

Verdict: the strongest practical option, particularly for administrators, partners with high-value access and anyone handling funds.

Biometrics and Windows Hello-style sign-in

Fingerprint or face recognition unlocks a locally stored credential on the device. When built on the same standards as passkeys, they are both convenient and strong.

Choosing for Your Firm

A realistic approach is to layer:

  1. Everyone: MFA on all accounts, with authenticator app or push with number matching as the baseline
  2. Administrators and finance staff: phishing-resistant methods, such as security keys or passkeys
  3. Fallback methods: limit SMS to recovery and exceptions, and expire exceptions
  4. Legacy applications: identify systems that do not support modern MFA and plan to replace, isolate or wrap them

Rollout Tips

  • Enroll at least two methods per person so a lost phone does not cause a lockout
  • Create a documented, verified process for resetting MFA, because attackers call help desks pretending to be staff
  • Disable older authentication protocols that bypass MFA
  • Use conditional access to require stronger authentication from unfamiliar locations or devices
  • Train staff to refuse unexpected prompts and report them
  • Cover shared and service accounts
  • Include attorneys and partners without exception

Common Mistakes

  • Treating MFA as done once enabled, without reviewing exceptions
  • Allowing the help desk to reset MFA with weak verification
  • Leaving legacy protocols open
  • Not protecting the recovery methods
  • Granting blanket exemptions to leadership

Why This Belongs in Your Ethics Thinking

ABA Model Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information, and Rule 1.1, Comment 8, ties competence to understanding technology risks. Stronger authentication is a clear, documentable step. Cyber insurance applications and client questionnaires ask about MFA directly, so know which methods you use and where.

Support From Counsel Cyber

Counsel Cyber helps law firms roll out MFA, move toward phishing-resistant methods for high-risk users, and secure reset processes. If you are not sure what protects your accounts today, we can report on it.