Microsoft Ditches SMS Authentication for Passkeys on Entra ID
Microsoft is introducing significant changes to its Entra ID sign-in process, affecting millions of users worldwide. The company will no longer support SMS and phone-based authentication methods due to their vulnerability to cyberattacks.
From September 1st, users will be automatically set up to use passkeys instead. Passkeys are encrypted codes tied to a password manager or specific device, providing an additional layer of security against phishing attacks.
The change aims to combat the increasing threat of credential abuse, which currently accounts for 13% of data breaches, according to Verizon's latest Data Breach Investigations Report. Microsoft's move follows its previous shift away from user passwords in favor of passkeys last year.
While some companies may have flexibility to send SMS over a different telco message, the majority will be required to adopt passkeys by February 1st next year.