Activate phishing-resistant MFA with Cloudflare

Thwart phishing scams by enforcing strong authentication

Phishing remains one of the most prevalent kinds of threats—and it is often just the first step in a larger attack. Implementing FIDO2-compliant multi-factor authentication (MFA) as part of a Zero Trust security approach neutralizes the threat posed by multi-channel phishing.

Phishing resistant MFA - HERO - Image

The Cloudflare difference

Security lock icon
Reduce multi-channel phishing risk

Avoid vulnerabilities of other authentication methods. Unlike one-time PINs, FIDO2 MFA cannot be intercepted by an attacker. Implement MFA broadly — and require it — through Zero Trust policies.

Icon squared - Phishing
Enhance your access management

Augment your identity provider (or multiple providers) with Zero Trust Network Access (ZTNA) to easily enforce FIDO2 MFA across more resources.

Security shield protection checkmark - Icon
Maximize MFA impact

Avoid vulnerabilities of other authentication methods. Unlike one-time PINs, FIDO2 MFA cannot be intercepted by an attacker. Implement MFA broadly — and require it — through Zero Trust policies.

HOW IT WORKS

Defeat phishing with FIDO2 MFA and Cloudflare

Cloudflare’s Zero Trust platform can enforce FIDO2 MFA consistently across SaaS, self-hosted, and non-web resources.

  • Implement Cloudflare’s ZTNA service to apply strict contextual verification for accessing all your organization’s resources.
  • Bolster security with FIDO2-compliant MFA that makes it nearly impossible to intercept or steal users’ credentials.
  • Selectively enforce strong MFA, starting with sensitive apps. Go beyond just supporting FIDO2 MFA and start to require it.
  • Enable broad deployment. Not all apps support FIDO2 MFA natively. As an aggregation layer, Cloudflare’s ZTNA service helps roll it out to all resources.
[ZT PMM] Phishing resistant MFA diagram

What our customers are saying

Man on laptop
Cloudflare logo

The Cloudflare security team needed to rapidly address a phishing attack that attempted to harvest and then use Okta login credentials from employees. Though the attackers successfully stole credentials and attempted to log in, they could not overcome the security key login requirement of Cloudflare’s Zero Trust implementation.

Requiring FIDO2-compliant MFA, like security keys, as part of Zero Trust access policies for all users and apps can strengthen the barrier against multichannel phishing attacks.

“While the attacker attempted to log in to our systems with compromised credentials, they could not get past the hard key requirement.”

Ready to discuss phishing-resistant MFA?

Contact us

Välj din jobbnivå … *
Annat
C-nivå
Chef
Direktör
Individuell medverkande
Student
VP
Välj din jobbroll … *
Annat
Chef
DevOps
Finans/anskaffning
Försäljning/marknadsföring
Infrastruktur
IT
Nätverk
Press/Media
Produkt
Student
Säkerhet
Teknik
Välj land …
Afghanistan
Albanien
Algeriet
Andorra
Angola
Anguilla
Antarktis
Antigua och Barbuda
Argentina
Armenien
Aruba
Australien
Azerbajdzjan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgien
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius och Saba
Bosnien och Hercegovina
Botswana
Bouvetön
Brasilien
Brittiska Jungfruöarna
Brittiska territoriet i Indiska oceanen
Brunei
Bulgarien
Burkina Faso
Burundi
Caymanöarna
Centralafrikanska republiken
Chile
Colombia
Cooköarna
Costa Rica
Curaçao
Cypern
Danmark
Djibouti
Dominica
Dominikanska republiken
Ecuador
Egypten
Ekvatorialguinea
El Salvador
Elfenbenskusten
Eritrea
Estland
Etiopien
Falklandsöarna
Fiji
Filippinerna
Finland
Frankrike
Franska Guyana
Franska Polynesien
Franska sydterritorierna
Färöarna
Förenade arabemiraten
Gabon
Gambia
Georgien
Ghana
Gibraltar
Grekland
Grenada
Grönland
Guadeloupe
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard- och McDonaldöarna
Heliga stolen (Vatikanstaten)
Honduras
Hongkong
Indien
Indonesien
Irak
Iran
Irland
Island
Isle of Man
Israel
Italien
Jamaica
Japan
Jemen
Jersey
Jordanien
Julön
Kambodja
Kamerun
Kanada
Kap Verde
Kazakstan
Kenya
Kina
Kirgizistan
Kiribati
Kokosöarna
Komorerna
Kongo
Kongo-Kinshasa
Kroatien
Kuba
Kuwait
Laos
Lesotho
Lettland
Libanon
Liberia
Libyen
Liechtenstein
Litauen
Luxemburg
Macao
Madagaskar
Malawi
Malaysia
Maldiverna
Mali
Malta
Marocko
Martinique
Mauretanien
Mauritius
Mayotte
Mexiko
Moldavien
Monaco
Mongoliet
Montenegro
Montserrat
Mozambique
Myanmar
Namibia
Nauru
Nederländerna
Nepal
Nicaragua
Niger
Nigeria
Niue
Nordkorea
Nordmakedonien
Norfolkön
Norge
Nya Kaledonien
Nya Zeeland
Oman
Pakistan
Palestina
Panama
Papua Nya Guinea
Paraguay
Peru
Pitcairnöarna
Polen
Portugal
Puerto Rico
Qatar
Réunion
Rumänien
Rwanda
Ryska federationen
Saint Kitts och Nevis
Saint Lucia
Saint Vincent och Grenadinerna
Saint-Barthélemy
Saint-Martin (franska delen)
Saint-Pierre och Miquelon
Salomonöarna
Samoa
San Marino
Sankta Helena, Ascension och Tristan da Cunha
São Tomé och Príncipe
Saudiarabien
Schweiz
Senegal
Serbien
Seychellerna
Sierra Leone
Singapore
Sint Maarten (nederländska delen)
Slovakien
Slovenien
Somalia
Spanien
Sri Lanka
Storbritannien
Sudan
Surinam
Svalbard och Jan Mayen
Sverige
Swaziland
Sydafrika
Sydgeorgien och Sydsandwichöarna
Sydkorea
Sydsudan
Syrien
Tadzjikistan
Taiwan
Tanzania
Tchad
Thailand
Tjeckien
Togo
Tokelau
Tonga
Trinidad och Tobago
Tunisien
Turkiet
Turkmenistan
Turks- och Caicosöarna
Tuvalu
Tyskland
Uganda
Ukraina
Ungern
Uruguay
USA
Uzbekistan
Vanuatu
Venezuela
Vietnam
Västsahara
Wallis- och Futunaöarna
Zambia
Zimbabwe
Åland
Österrike
Östtimor

 
In submitting this form, you agree to receive information from Cloudflare related to our products, events, and special offers. You can unsubscribe from such messages at any time. We never sell your data, and we value your privacy choices. Please see our Privacy Policy for information.

WHY CLOUDFLARE

Cloudflare’s connectivity cloud restores control and visibility to IT environments

Using Cloudflare’s unified platform of cloud-native services, you can implement a Zero Trust security model with strong MFA capabilities that conquer phishing schemes.

Icon container
Composable architecture

Address diverse security and networking needs with extensive interoperability and customizable networking.

ABM - Woolworths - Elevating the Digital Customer Journey - Card 1 - Icon
Performance

Deliver better user experiences with a global network that is approximately 50 ms from ~95% of Internet users.

Cloudflare radar - Tile
Threat intelligence

Prevent more attacks with intelligence gleaned from proxying ~20% of the web and blocking ~215 billion threats daily.

Mobile device icon
Unified interface

Reduce tool sprawl and alert fatigue by uniting every hybrid work security service in one UI.

Resources

Thumbnail - Report - Template 3 Graphs

Case study

How Cloudflare stopped a targeted phishing attack

Read how Cloudflare’s Zero Trust approach, including security keys, helped thwart a targeted phishing attack.

Read case study  
Blog Resource Thumbnail

BLOG POST

How Cloudflare implemented security keys

Learn the steps Cloudflare took to roll out FIDO2 security keys and Zero Trust to all apps and employees.

Read blog  

Phishing-resistant MFA FAQs