Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

cybersecurity awareness Microsoft Microsoft Entra Microsoft Security Passwordless Authentication

Microsoft Entra ID Makes Passkeys the New Standard

For years, SMS and voice-based multifactor authentication (MFA) have provided an important layer of security beyond passwords. However, as phishing, social engineering, SIM-swapping, and AI-powered attacks become increasingly sophisticated, these methods are no longer considered sufficiently resilient against modern threats. Microsoft is now encouraging organizations to adopt phishing-resistant authentication through passkeys.

Passkeys leverage public-key cryptography rather than shared secrets like passwords or SMS codes. This makes them inherently resistant to phishing attacks while providing a faster and more user-friendly login experience. According to Microsoft, AI-enabled phishing campaigns have achieved click-through rates significantly higher than traditional campaigns, making compromised credentials a growing security concern.

What Is Changing?

Starting September 1, 2026, Microsoft Entra ID users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys. During their next MFA sign-in, users will be prompted to register a passkey.

Microsoft will continue this transition through a phased timeline:

  • September 1, 2026: Passkey registration prompts begin for users using SMS or voice authentication.
  • September 18, 2026: Microsoft will publish supported telecom providers and pricing information for organizations that still require SMS or voice authentication.
  • October 30, 2026: Administrators can begin configuring third-party telecom providers through the Microsoft Security Store.
  • February 1, 2027: Microsoft-provided SMS and voice authentication services will be retired. Organizations requiring those methods must use approved telecom partners.
  • After February 1, 2027: Passkey registration will be enforced for users relying on SMS or voice authentication, with no opt-out available. [microsoft.com]

What This Means for Businesses

For organizations already investing in Zero Trust and identity-driven security strategies, this move aligns perfectly with industry best practices. Passkeys reduce the attack surface associated with stolen passwords, MFA fatigue attacks, and phishing campaigns while simplifying the user experience.

Microsoft recommends that organizations begin preparing now by:

  • Identifying users still relying on SMS or voice authentication.
  • Enabling and planning a passkey deployment.
  • Leveraging registration campaigns to accelerate user adoption.
  • Communicating upcoming authentication changes to employees.
  • Testing alternative authentication methods such as Microsoft Authenticator passkeys, Windows-based Entra passkeys, or FIDO2 security keys. [microsoft.com]

Why This Matters

Identity remains the primary target in modern cyberattacks. Once an attacker gains access to a user account, they can automate discovery, privilege escalation, and lateral movement at machine speed. By making passkeys the default authentication experience, Microsoft is helping organizations significantly reduce the risk of credential compromise and strengthen their overall security posture.

For MSPs, IT departments, and security leaders, the message is clear: now is the time to move beyond passwords, SMS codes, and voice authentication and embrace phishing-resistant identity protection.  The future of authentication is passwordless, and Microsoft is accelerating that future with Microsoft Entra ID.

Leave a comment

Your email address will not be published. Required fields are marked *