Start with the action and threat model
Authentication establishes that the party returning to an account controls an approved authenticator. The control needed for routine sign-in may differ from the control needed to change payment details, add a device or recover an account.
Map phishing, credential stuffing, malware, SIM swap, session theft, social engineering and insider risks. Then select controls that reduce the most consequential failures without creating unusable journeys.
Compare methods as systems, not labels
Passwords and one-time codes
Passwords remain common but require protection against reuse, stuffing and phishing. SMS or email codes add friction but may inherit weaknesses from the delivery channel and recovery process.
Passkeys and cryptographic authenticators
Passkeys can provide phishing-resistant authentication with platform or roaming authenticators. Evaluate device support, account synchronisation, enrolment, loss and enterprise policy.
Biometric authentication
Biometrics may unlock a local cryptographic credential or be matched remotely. These architectures have different privacy, liveness, network and recovery implications.
The NIST authentication guidance provides a useful assurance and authenticator-management reference.
Account recovery deserves equal scrutiny
Strong sign-in controls can be bypassed if recovery relies on weaker evidence. Define the risk of device loss, inaccessible email, changed phone numbers and attacker-controlled support interactions.
- Notify users about authenticator and recovery changes
- Apply delays or step-up checks to high-risk recovery
- Limit support-agent privileges and preserve evidence
- Use device, session and behavioural context
- Test recovery accessibility and legitimate failure cases
Authentication provider criteria
Assess enrolment, everyday use, replacement, recovery and revocation together. Attackers look for the least protected path through the lifecycle.
