Microsoft Ditches SMS, Voice Auth for Passkeys in Entra ID
Microsoft has announced that it will make passkeys the default authentication experience in Entra ID starting September 1, 2026. This change is part of Microsoft's broader effort to eliminate phishable credentials as enterprises expand cloud usage, remote access, and AI-enabled workflows.
Passwords, one-time SMS codes, and voice-based verification remain frequent targets of credential phishing, adversary-in-the-middle attacks, SIM swapping, social engineering, and replay attacks. To mitigate these risks, Microsoft will automatically enable passkeys for users currently enabled for SMS or voice authentication in Entra ID tenants.
Passkeys use public-key cryptography rather than shared secrets, making them more secure than traditional authentication methods. They can be stored in credential managers, such as iCloud Keychain and Google Password Manager, allowing users to access credentials across supported devices.