Comparing Multi-Factor Authentication Methods from SMS and TOTP to FIDO2/WebAuthn and Passkeys: A Qualitative Study of Practitioner Perspectives
Abstract
The escalation of cyber-attacks has intensified the need for stronger multi-factor authentication (MFA), motivating a shift from traditional knowledge- and possession-based factors, such as SMS one-time passwords (OTP) and time-based one-time passwords (TOTP), toward FIDO2/WebAuthn credentials and passkeys. This study qualitatively compares five widely deployed MFA methods, grouped as traditional (SMS-based OTP, TOTP, and push-based authentication) and advanced (FIDO2 security keys and platform biometric authenticators), across four criteria: usability, security, cost, and implementation challenges. Adopting an interpretive qualitative design, the study draws on semi-structured interviews with four identity-and-access-management (IAM) practitioners, analysed through Braun and Clarke's six-phase reflexive thematic analysis. Coding produced an initial framework of 30 codes that was consolidated into four themes corresponding to the study criteria. Practitioners consistently characterised traditional methods as more affordable and broadly familiar but weaker in security and more prone to operational reliability problems, whereas FIDO2 security keys and platform biometrics were described as offering stronger phishing resistance and smoother day-to-day operation at a higher initial and maintenance cost. The study situates these accounts within organisational governance and cross-regional regulatory drivers of adoption and recommends a risk-based migration toward FIDO2/WebAuthn and passkeys.