Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication

Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication
Photo by Ann H on Pexels

Microsoft will begin making passkeys the default authentication experience for Entra ID users on September 1, 2026. The company will retire its native delivery of SMS and voice authentication on February 1, 2027, pushing organizations toward phishing-resistant credentials or external telecom providers.

News Date: 2026-07-13

Microsoft is preparing a major authentication change for enterprise customers by making passkeys the default sign-in method in Entra ID. Beginning September 1, 2026, users who are enabled for SMS or voice authentication will also be enabled for passkeys and prompted to register one during a future multifactor authentication event.

A Move Away From Phishable Factors

Passkeys rely on public-key cryptography rather than passwords, one-time codes or shared secrets. The credential is bound to the legitimate service, making it substantially harder for a phishing page or social engineer to capture something that can be replayed from another device.

Microsoft says identity attacks are becoming faster and more convincing as adversaries adopt artificial intelligence. SMS codes can also be exposed through phishing, SIM-swapping attacks, telecom weaknesses and fraudulent account-recovery requests. Voice authentication faces similar social-engineering and interception concerns.

The more consequential deadline arrives on February 1, 2027, when Microsoft will stop providing native SMS and voice delivery for Entra ID. Organizations that must retain these methods for regulatory, operational or accessibility reasons will be able to contract with supported telecom providers through the Microsoft Security Store.

Preparation Cannot Wait Until September

Microsoft plans to publish provider information and commercial details on September 18, 2026. Administrators will be able to configure supported providers beginning October 30. The announced dates apply to Entra ID's public cloud, with separate schedules expected for other cloud environments.

Recommended Migration Plan

  • Identify users and applications still dependent on SMS or voice.
  • Choose between synced passkeys, device-bound passkeys and FIDO2 keys.
  • Run a controlled pilot with executives, administrators and support personnel.
  • Update account-recovery and device-replacement procedures.
  • Prepare clear user guidance before registration prompts appear.

I believe making phishing-resistant authentication the default is the right direction, but the migration will expose weak recovery processes in many organizations. A strong passkey deployment can still be undermined if a help desk resets access after receiving a convincing fraudulent call.

Enterprises should therefore treat this as an identity-program change rather than a simple authentication toggle. Success requires technical deployment, user education, resilient recovery controls and support for employees who cannot use the standard device-based registration process.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path