Microsoft Ditches SMS and Voice MFA for Passkeys in Entra ID
Microsoft is pushing forward with its plan to make passkeys the default authentication method in Entra ID. Beginning September 1, 2026, passkeys will become the go-to for users, while SMS and voice multifactor authentication delivery will be retired on February 1, 2027.
The company describes passkeys as 'phishing-resistant credentials' based on cryptographic key pairs rather than shared secrets. This makes them less vulnerable to common account-takeover techniques such as credential phishing and SIM-swapping.
Under the new policy, Entra tenants with users enabled for SMS or voice authentication will have those users automatically enabled for passkeys in the Authentication Methods Policy. Users will then be prompted to register a passkey during a subsequent sign-in that requires MFA.