Standard phishing works because shared secrets — passwords, one-time codes, push approvals — can be entered into or relayed through a look-alike site. Phishing-resistant methods cryptographically tie the authentication to the legitimate origin and verify the user device-side, removing the relayable secret.
Key points
High-value priorityAdministrators, finance staff, executives, and remote workers facing targeted phishing benefit most; roll out by risk, not only by convenience.
Enrollment and recoveryDevice loss, replacement, and account recovery must be as strong as the login method, or recovery becomes the weak point.
Important limitationPhishing resistance protects the authentication event, not the session afterward. Token theft, malicious OAuth grants, endpoint compromise, and social engineering of recovery or support staff remain possible.