GreenLoop IT Solutions : Articles
365 Best-Practices: Blocking New Registrations of Insecure Authentication Methods
Cybersecurity threats are becoming increasingly sophisticated, and organizations must stay ahead of attackers by strengthening how users prove their identity.
This article explains why GreenLoop is taking steps to phase out lower-security authentication methods while at the same time guiding clients toward stronger, phishing-resistant options. It is written for business and technology decision makers who may not work directly with authentication in Microsoft 365, but play a key role in establishing secure organizational policies.
Why Some Authentication Methods Are Considered Insecure
Not all multi-factor authentication (MFA) methods offer the same level of protection. Some of the most common and familiar options—such as text message (SMS) codes, phone call verification, and email-based codes—are unfortunately also some of the easiest for attackers to exploit.
These issues often stem from vulnerabilities outside your organization’s control:
- SMS and voice calls can be spoofed. Attackers can impersonate phone numbers through techniques such as SIM swapping, making it possible to intercept verification codes. These attacks have existed for a long time, but the barrier to entry continues to get lower for a sufficiently motivated attacker.
- Email-based verification is only as secure as the mailbox it’s sent to. When users rely on codes sent to personal email accounts, those accounts may not follow corporate security standards, creating weak points attackers can exploit.
Stronger Authentication Options
Modern authentication technologies provide significantly stronger protection against phishing, spoofing, and other attack techniques. These methods improve security by ensuring that login approvals cannot easily be intercepted or copied.
- Authenticator apps (such as Microsoft Authenticator) using push notifications or rotating codes. These are much harder for attackers to intercept compared to SMS.
- Hardware or software one-time token generators, which provide unique codes that aren’t tied to phone numbers or email accounts.
- Passkeys and FIDO2-based authentication, which generate secure, device-bound credentials that cannot be reused or stolen by attackers. These technologies offer the strongest available resistance to phishing attacks.
What GreenLoop Is Doing
1. Helping Clients Adopt Stronger Authentication
Passkeys and other advanced authentication methods are maturing quickly, but many organizations still face challenges adopting them across every device and user group. GreenLoop is working closely with clients to identify high-impact opportunities to deploy these stronger methods—especially for protecting sensitive systems and the users most frequently targeted by attackers.
2. Blocking New Registrations of Insecure Methods
In many organizations, users have already registered less-secure MFA methods in the past. Disabling these insecure methods outright would prevent those users from logging in, potentially causing business disruption.
To limit further exposure without introducing operational risk, GreenLoop’s best-practices now include a policy that prevents any new registrations of insecure authentication methods such as SMS, voice, and email codes. Users who already rely on these methods may continue using them while new policies and controls are developed, but no additional users will be able to enroll them going forward.
This gives organizations time to transition users at a sustainable pace while still preventing the expansion of insecure practices. GreenLoop will partner with clients to move remaining users to stronger authentication methods as part of this phased approach.
References: