Frontrow Technology
← Wiki

Glossary

FIDO2: Phishing-Resistant Authentication for Australian Microsoft 365 Environments

FIDO2 is an open authentication standard combining WebAuthn and CTAP2, providing a significantly more secure alternative to passwords and SMS-based MFA, resistant to phishing attacks.

Last reviewed 23 May 2026

How FIDO2 Works

FIDO2 leverages public-key cryptography, eliminating the need to transmit passwords over the network. It involves an authenticator (hardware security key, fingerprint reader, etc.) and a relying party (the service being accessed). During registration, a key pair is generated – the public key is stored with the relying party, while the private key remains securely within the authenticator. Authentication then relies on cryptographic signatures, making it extremely difficult for attackers to steal credentials.

FIDO2 and the ACSC Essential Eight

The Australian Cyber Security Centre’s Essential Eight Maturity Level 2 (ML2) now mandates phishing-resistant MFA for privileged accounts and those routinely accessed over the internet. FIDO2 is a practical and increasingly common solution to meet this requirement. Many AU mid-market organisations are adopting FIDO2 to bolster their security posture, particularly given the ongoing threat landscape and the increasing scrutiny from regulators like APRA and the OAIC regarding data security and privacy obligations under the Privacy Act 2024.

Want Frontrow to walk this through with your team?

30 minutes. No deck. We'll walk through your tenant, your priorities, and the next sensible move.