TL;DR
Multi-Factor Authentication (MFA) requires two or more independent proofs of identity—something you know, have, or are—before granting access, closing the gap left by passwords alone. Traditional push- and code-based MFA still leaves users exposed to MFA fatigue and phishing proxies that intercept one-time codes. Proximia extends MFA with live biometrics and continuous, presence-based verification through the XiFi Card, so protection continues for the life of the session instead of stopping at sign-in.
- MFA closes the account-takeover gap that password-only sign-in leaves open by requiring a second, independent proof of identity.
- 97% of identity attacks exploit password credentials, which is why even basic MFA blocks most automated takeover attempts (Microsoft, 2025).
- Attackers still trick about 1 in 3 distracted users into approving a fraudulent MFA prompt, the tactic known as MFA fatigue or push bombing (Microsoft Security Research).
- Legacy MFA methods like SMS codes and shared push approvals remain vulnerable to phishing proxies and SIM swapping, which is driving adoption of phishing-resistant, passkey-based MFA.
- Proximia's XiFi Card adds continuous, presence-based verification after sign-in, so a session stays protected for as long as the verified user remains present.
What Is Multi-Factor Authentication (MFA)?
Multi-Factor Authentication (MFA) is a security method that requires users to provide two or more independent verification factors to access a system.
These factors fall into three categories:
- Something you know: a password or PIN.
- Something you have: a phone, token, or smart card.
- Something you are: a biometric identifier like a fingerprint or face scan.
By requiring more than one factor, MFA significantly reduces the likelihood of unauthorized access—even if one credential is compromised.
The Evolution of MFA: From Passwords to Adaptive Trust

Early MFA implementations used SMS-based codes or hardware tokens. These methods worked -- but over time, attackers learned to exploit them. SIM swapping, phishing proxies, and session hijacking made static MFA less effective.
Today, MFA is evolving into adaptive authentication -- a dynamic approach that considers user behavior, device health, location, and proximity.
This model uses continuous, context-aware monitoring to verify identity seamlessly and adjust authentication requirements based on risk.
Real Life Example: A hospital clinician signing in from their usual workstation may not be prompted again, but a sign-in attempt from another country would trigger immediate re-verification.
Pros and Limitations of MFA: Where It Works and Where It Evolves
Where It Works
- Reduces credential-based risk: MFA adds an additional verification layer beyond passwords, significantly lowering the likelihood of unauthorized access when credentials are compromised.
- Supports Zero Trust principles: By requiring verification beyond a single factor, MFA reinforces the concept that access should not be assumed based on a successful sign-in alone.
- Strengthens regulatory alignment: MFA aligns with standards such as NIST SP 800-63B and is commonly required for HIPAA, CJIS, and other regulated environments.
- Improves audibility: Authentication events are logged and traceable, supporting security monitoring, incident response, and compliance reporting.
Where Traditional MFA Shows Its Limits

As MFA adoption has increased, so has the sophistication of attacks and user expectations. These limitations are not failures of MFA itself, but indicators of where the model is evolving.
- Phishing-resistant gaps: Legacy MFA methods that rely on one-time codes or push approvals can still be targeted by modern phishing and man-in-the-middle techniques. This has driven adoption of phishing-resistant MFA and passkey-based approaches. Phishing-resistant MFA blocks over 99% of identity-based attacks, even when an attacker already has the correct username and password (Microsoft Digital Defense Report 2025).
- User experience friction: Repeated authentication prompts can interrupt workflows, particularly in high-frequency or shared-device environments. Adaptive and risk-based MFA reduces this by applying additional checks only when context changes.
- Approval fatigue: Push-based MFA can create habituation over time. Context-aware authentication and presence-based verification reduce reliance on repeated manual approvals.
SMS-based MFA limitations: SMS delivery is vulnerable to interception and redirection, which is why security frameworks increasingly recommend app-based or hardware-backed factors instead.
Why MFA Is a Foundation, Not the End State
MFA remains a critical security control, but modern identity strategies are moving beyond static checkpoints toward adaptive, phishing-resistant, and continuous authentication models. These approaches preserve MFA's benefits while addressing its operational and usability gaps, setting the stage for persistent trust rather than one-time verification.
Types of MFA
Traditional MFA
Static MFA challenges users every time they sign in, regardless of context. This improves security but often frustrates users and drives resistance.
Adaptive MFA
Adaptive MFA intelligently balances security with usability. It evaluates factors like:
- Device reputation and health
- User behavior (typing patterns, mouse movement)
- Sign-in context (location, time of day)
- Proximity of a trusted device or Smart Card
If everything checks out, users sign in frictionlessly. If risk spikes, additional authentication, like biometric confirmation, is triggered.
This is how Proximia's presence-aware MFA operates: it maintains strong, silent verification in the background, adjusting only when trust signals change.
Types of MFA Attacks on the Rise
Even MFA isn't invincible. Attackers increasingly exploit human and technical weaknesses.
Push Bombing (MFA Fatigue)
Attackers flood users with approval notifications, hoping one is accepted accidentally. About 1 in 3 distracted users approve a fraudulent MFA prompt this way (Microsoft Security Research).
Solution: Use adaptive or biometric MFA that eliminates repeated push prompts and validates presence physically.
Phishing Proxies
Adversaries use reverse-proxy websites to intercept credentials and MFA tokens in real time. The Tycoon 2FA phishing-as-a-service platform, for example, uses this technique to capture a victim's live session after they complete sign-in and MFA -- roughly 80% of its victims were enterprise users (SpyCloud, 2026 Identity Exposure Report).
Solution: Implement phishing-resistant MFA via FIDO2 or hardware-based authenticators that never share secrets.
SMS & SIM Swapping
Attackers hijack phone numbers to intercept one-time passcodes.
Solution: Replace SMS MFA with TOTP apps or cryptographic credentials bound to specific devices.
TOTP Token Reuse
Time-based codes can still be phished if entered on spoofed pages.
Solution: Deploy secure, context-aware authentication methods like WebAuthn or proximity-based identity validation.
When MFA Is Enough — and When It’s Not
MFA dramatically reduces breach risk, but modern threats like session hijacking, MFA fatigue, and phishing proxies reveal its limitations.
MFA is enough when:
- Combined with secure SSO.
- Protected by device-bound authenticators.
- Supported by trained, vigilant users.
MFA is not enough when:
- Users can be socially engineered to approve requests.
- SMS or TOTP remain the primary factors.
- Sessions persist without re-verification of presence.
Attackers recaptured 8.6 billion stolen session cookies from criminal underground sources in 2025, underscoring that MFA alone cannot protect a session once it's underway (SpyCloud, 2026 Identity Exposure Report). Adding live biometric sign-in plus continuous, presence-based verification via the XiFi Card -- like Proximia's platform -- closes these gaps by tying access to verified, ongoing presence rather than one-time checks.
The Future of MFA: Continuous, Context-Aware, and Presence-Driven

In 2026 and beyond, MFA is increasingly moving toward adaptive authentication that integrates risk signals, device context, and presence detection.
Key trends include:
- Passwordless MFA: Combining biometrics + passkeys for stronger factors.
- Proximity-Aware Sessions: Validating that the right person remains active.
- Decentralized Identity: Reducing data exposure via cryptographic trust.
- Presence-Aware Session Locking: Automatically locking the session the moment a verified user steps away.
The end goal is seamless security -- one that authenticates continuously, invisibly, and reliably.
Proximia’s Approach to Phishing-Resistant MFA
Proximia redefines MFA by extending full identity assurance throughout the entire session, not just at sign-in.
- Biometric Verification: Confirms the right individual at sign-in with live biometrics.
- Proximity Detection: Uses the XiFi Card or a registered mobile device to verify ongoing presence.
- Session Persistence: Automatically locks when users leave range or lose proximity signals.
Unlike traditional MFA, which ends after sign-in, Proximia keeps verifying presence for the life of the session via the XiFi Card -- creating a frictionless, phishing-resistant layer aligned with Zero Trust and FIDO2 principles.
Result: Fewer prompts. Fewer breaches. Stronger assurance.
Frequently Asked Questions
Final Thoughts
MFA remains one of the most effective security controls available, but it's evolving fast.
Static, one-time verification is no longer enough to combat phishing, fatigue, or social engineering.
Adaptive, biometric, and presence-based MFA, like that offered by Proximia, goes beyond the sign-in event to continuously verify presence throughout every session.
Ready to strengthen your authentication strategy?
Discover how Proximia delivers phishing-resistant MFA that adapts to your environment.
Cited Sources
- Verizon. 2026 Data Breach Investigations Report (DBIR).
https://www.verizon.com/business/resources/reports/dbir/ - CISA. Implementing Phishing-Resistant MFA -- 2024 Guidance.
https://www.cisa.gov/resources-tools/resources/phishing-resistant-mfa-guidance - FIDO Alliance. FIDO2 and Phishing-Resistant Authentication Overview.
https://fidoalliance.org/fido2/ - Microsoft. Digital Defense Report 2025.
blogs.microsoft.com/on-the-issues - Microsoft Security Research. MFA fatigue and push-bombing prompt research.
- SpyCloud. 2026 Identity Exposure Report.
https://spycloud.com/blog/2026-annual-identity-exposure-report/ - NIST. SP 800-63B Digital Identity Guidelines.
https://pages.nist.gov/800-63-3/sp800-63b.html



