Table of contents
The administrator account is the most valuable account in the company. If an attacker gets it, they no longer need to break into anyone else’s – they take over mail, files and identities for everyone. So the second factor on administrator accounts has to be one that cannot be stolen through a phishing page. SMS and app codes are not.
Why SMS and codes are not enough
Modern phishing is not “enter your password”. It is a proxy page that looks like the Google or Microsoft sign-in, forwards your password and immediately your six-digit code to the real server, and takes over the session. The code is valid for 30 seconds; the attacker needs three. For the same reason a push approval on the phone is not enough – after the tenth prompt, users approve anything.
A FIDO2 hardware key (YubiKey, Google Titan, Feitian and others) works differently: it signs a challenge that includes the site’s domain. If the page is not the real one, the signature is useless. The user has nothing to type and nothing to “accidentally approve”. It is the only widely available method that Google and Microsoft consider phishing-resistant, and the CIS Benchmark requires it for administrators.
The minimum policy for administrators
- Security keys only. Google Workspace: enforce 2SV with “Only security key” in the administrators’ organisational unit. Microsoft 365: a Conditional Access policy requiring phishing-resistant authentication strength for administrator roles.
- Two keys each. One for daily use, one in the safe or with the managing director. A key lost on Friday evening with no spare means an administrator without access until Monday – or, worse, a hurried “temporary” weakening.
- No SMS and no voice. Disable them as allowed methods for administrators entirely, not just leave them unused.
- A recovery procedure on paper. Who may restore an administrator’s access, how identity is verified, where it is recorded. Google reserves this action for super administrators, so at least two people in the company must hold keys.
- Separate administrator accounts. The administrator reads daily mail under a normal account; the admin account is separate, with no or minimal mailbox, used only for administration.
For external providers too
The same applies to your IT provider’s accounts in your tenant – and you can enforce it technically, not just write it into the contract. Provider accounts sit in a separate organisational unit with the key policy applied; in Enterprise editions, add a context-aware access level that allows sign-in only from a managed device and from your country.
What it costs
A key costs €30-70. Five administrators with two keys each – under €700 once. It is the cheapest security measure with the largest effect a company can buy; the rest is an hour of configuration and half an hour for the procedure.
And the other users?
For ordinary users, enforced 2SV with Google Authenticator or Google prompt is a good minimum. Passkeys on a phone or computer are as phishing-resistant as keys and cost nothing – that is the next step after administrators. But start with the administrators: theirs are the accounts through which everyone else can lose everything.
Two-step verification for all users and keys for administrators are included in every one of our support plans.


