Microsoft Ditches SMS Authentication Amidst Rise of AI-Driven Phishing Attacks
Microsoft has issued a warning to IT administrators, advising them to stop using SMS and voice-based authentication due to AI-powered phishing attacks. The company cites the ease with which attackers can manipulate these channels using artificial intelligence.
The rise in AI-driven attacks is notable for their high success rate compared to older phishing attempts. Microsoft states that SIM swapping has also become easier with AI, allowing bad actors to move a user's phone number to a new SIM card without much effort.
Starting September 1, Entra users will be prompted to set up a passkey during sign-in if they are using SMS or voice authentication. By February 1, 2027, Microsoft plans to fully retire these methods and require passkeys for all users.