Microsoft Ditches SMS and Voice Authentication in Entra ID, Defaults to Passkeys
Microsoft is shifting away from SMS and voice authentication methods in its Entra ID platform, replacing them with passkeys as the default login experience. This move aims to reduce phishing risks associated with these traditional methods.
The company will automatically enable users for passkeys starting September 1, 2026, prompting them to register a passkey during their next MFA sign-in. Passkeys use cryptographic credentials tied to devices or credential managers, making it more difficult for attackers to target them through phishing kits and other means.
Microsoft plans to fully retire its native telecom delivery for SMS and voice in Entra ID by February 1, 2027, requiring organizations that continue relying on these channels to use a customer-managed telecom provider. The company will publish information about available providers from September 18, 2026, allowing customers to select and configure them starting October 30, 2026.