Microsoft Cracks Down on Legacy Authentication Methods
Microsoft has enforced a structural shift towards mandatory phishing-resistant identity in its Entra ID platform. As of September 7, the company terminated the use of unregistered directory contact data for self-service password reset (SSPR). This change means that mobile numbers and secondary emails not explicitly registered as authentication methods no longer function for verification.
The enforcement follows a previous shift on September 1, where passkeys became the default authentication experience in Entra ID. While users can currently snooze this transition, the runway is limited, with Microsoft-provided SMS and voice authentication set to be fully retired by February 1, 2027.
This move addresses the threat landscape's demand for more secure identity protection. Microsoft environments face over 600 million daily identity attacks, with AI-enabled phishing campaigns achieving click-through rates of 54% compared to 12% for traditional campaigns.