Do passkeys meet the Essential Eight Maturity Level 2 MFA requirement?

Yes for online services, no on their own for workstation logon. Essential Eight Maturity Level 2 requires phishing-resistant MFA in two distinct places. Passkeys satisfy the requirement for users of online services. Signing in to the computer itself needs Windows Hello for Business, FIDO2 security keys or smart cards, so a clean ML2 generally needs passkeys plus Windows Hello for Business.

The two ML2 phishing-resistance requirements

Since the November 2023 update to the maturity model, ML2 requires that MFA used by users of online services is phishing-resistant, and separately that MFA used for authenticating to systems (workstation logon) is phishing-resistant, where the ACSC names smart cards, security keys and Windows Hello for Business as acceptable methods. Microsoft's own Entra ID mapping for ML2 lists the two requirements separately. This is the nuance most businesses miss: rolling out passkeys in Microsoft Authenticator covers the first leg and leaves the second untouched. The authoritative source is ASD's Essential Eight maturity model.

Why push MFA and SMS fail the test

Phishing resistance at ML2 and ML3 is grounded in the verifier-impersonation resistance concept from NIST SP 800-63B. Any method where the user types a code or approves a prompt (SMS, one-time codes, Authenticator push, even with number matching) can be relayed through an adversary-in-the-middle proxy: the user completes MFA against the real Microsoft login and the attacker takes the session token. Passkeys qualify because the credential is cryptographically bound to the exact service it was registered against, so it cannot be replayed to a fake login page. Push MFA stops password-only attacks; it does not stop the attack pattern actually hitting Australian businesses now.

What this means for DISP members

Since the September 2024 uplift to the Defence Security Principles Framework (Principle 16, Control 16.1), DISP requires the full Essential Eight at Maturity Level 2 across the ICT systems used to correspond with Defence, at every membership level including Entry Level. Transitional assessments against the old Top Four concluded on 15 November 2025, and the DISP Cyber Security Questionnaire now assesses ML2-aligned controls as part of ongoing annual assurance, so the MFA control is re-checked, not checked once. A Defence-industry business still running Authenticator push as its primary MFA has a live gap on that control today. See the Department of Defence's DISP guidance for the current requirements.

Getting to a clean ML2

The pattern we deploy is passkeys in Microsoft Authenticator (or on Windows) for online services, Windows Hello for Business on managed Windows devices for workstation logon, and FIDO2 security keys for administrators, break-glass accounts and shared-device users. Enforcement is done through Conditional Access authentication strengths, which Microsoft 365 Business Premium already licenses. With Microsoft making passkeys the Entra ID default from 1 September 2026, the compliance work and the platform direction now point the same way; see the SMS and voice retirement timeline.

How Blue Arc IT Solutions helps

We are experienced supporting DISP member organisations and deliver phishing-resistant MFA as part of our ML2 Uplift Programme: gap assessment, rollout, enforcement and the evidence for your annual assurance. Start at the passkeys for Microsoft 365 businesses hub, or see DISP IT support in Canberra and what Essential Eight Maturity Level 2 involves.

Last reviewed: 20 July 2026. The Essential Eight remains the standard in force while ASD consults on its successor Essentials series; check the ASD link above for current requirements.

Frequently asked questions

Is Microsoft Authenticator with number matching phishing-resistant?

No. Number matching reduces accidental approvals from MFA fatigue, but the method still relies on the user approving a prompt, so it can be relayed through a fake login page. It does not meet the phishing-resistance requirement at Essential Eight Maturity Level 2.

Does Windows Hello for Business need an extra licence?

No. Windows Hello for Business is included with Windows and Microsoft Entra ID at no additional cost, which makes it the usual way to cover the workstation-logon leg of Maturity Level 2 on managed Windows devices.

Do DISP members have to use passkeys specifically?

No. The requirement is phishing-resistant MFA, and smart cards, FIDO2 security keys and Windows Hello for Business also qualify. Passkeys are simply the lowest-cost path for the online-services requirement because they are included in every Entra ID licence and need no hardware purchase for most users.