Prefer WebAuthn.
Not perfect, sure. Webauthn is definitely more secure, but far less convenient.
That's why Google gave all its employees Security Keys. Instead of "Well, we spend a little bit of money on some half-solution but we just raised the bar and so we'll have to spend more forever and always risk phishing attacks" they just solved the problem.
This saves you extra money because your adversaries stop trying. Not only are remaining attacks unsuccessful, they become much rarer and the associated clean-up (even if it's just helpdesk reassuring employees that although they fell for that scam email claiming to be from HR their credentials are fine) cost is reduced.
Think about SSH. People scan and attack every SSH server on the public IPv4 Internet. But not on IPv6. Why not? Because it's statistically useless to attempt with 128-bit addresses. You're just wasting your time and money.
So the attacker at best gets valid credentials for their phishing site, which in WebAuthn are deliberately uncorrelated to other credentials, the attacker can't do anything useful with that information. In practice, of course you don't have or want credentials for their phishing site so they just get a Javascript error and give up.