Microsoft Makes Passkeys The Default For Entra ID

insight-m

Microsoft will begin making passkeys the default authentication method in Microsoft Entra ID from 1 September 2026, marking a major change in how organisations protect user accounts as AI-powered phishing and identity attacks continue to grow.

What Has Changed?

The move is part of Microsoft’s wider effort to reduce reliance on authentication methods that cyber criminals can intercept, steal or manipulate, such as SMS text messages and voice calls.

From 1 September 2026, organisations using Microsoft Entra ID will see users who currently rely on SMS or voice authentication automatically enabled for passkeys. The next time those users complete multifactor authentication, they will be prompted to register a passkey.

Microsoft says: “As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey.”

The company is also encouraging organisations to begin preparing now rather than waiting for the rollout to begin.

Why Microsoft Is Making The Move

Microsoft says the decision reflects the changing nature of cyber attacks, particularly as AI enables criminals to launch more sophisticated phishing campaigns at greater speed and scale.

In announcing the change, the company said: “As identity attacks grow more sophisticated in the AI era, organisations need stronger authentication methods that protect users from phishing, credential theft, and social engineering.”

Traditional multifactor authentication using SMS or voice was once considered a major improvement over passwords alone. However, Microsoft says these methods still rely on shared secrets or communication channels that attackers increasingly know how to exploit.

The company points to techniques such as SIM swapping, social engineering and multifactor authentication bypass attacks, all of which have become more accessible to attackers.

Microsoft also says AI is making the problem significantly worse. For example, according to Microsoft Threat Intelligence, AI-enabled phishing campaigns have achieved click-through rates of up to 54 per cent, compared with roughly 12 per cent for more traditional phishing attacks.

The company warns that once an attacker compromises an identity, AI can rapidly automate discovery, privilege escalation and lateral movement across an organisation, dramatically increasing the speed and scale of an attack.

Why Passkeys Are Different

Unlike passwords or SMS authentication codes, passkeys use public-key cryptography rather than shared secrets. That means there is no password or authentication code that can be intercepted, stolen or tricked out of a user through a phishing website.

Microsoft says this makes passkeys phishing-resistant by design while also simplifying the sign-in process.

As the company explains: “Passkeys use public-key cryptography rather than shared secrets, making them phishing-resistant by design. They also provide a faster, simpler sign-in experience for users.”

Microsoft Entra ID supports a range of passkey options, including synchronised passkeys stored in services such as iCloud Keychain and Google Password Manager, device-bound passkeys stored in Microsoft Authenticator or Windows, and FIDO2 hardware security keys.

What Happens Next?

The introduction of passkeys is only the first stage of Microsoft’s transition.

On 1 February 2027, Microsoft says it will retire its own SMS and voice authentication capability within Entra ID altogether. Organisations that still require those authentication methods because of regulatory, operational or technical requirements will instead need to obtain them through third-party telecoms providers available via the Microsoft Security Store.

Microsoft says organisations should begin identifying users who still rely on SMS or voice authentication, plan their passkey deployment strategy, communicate upcoming changes to staff and use Entra ID’s built-in registration campaigns to encourage adoption before the deadlines arrive.

Summarising the transition, Microsoft said: “SMS and voice have served their purpose well, bringing multifactor authentication to billions of users who otherwise would have had none. But the threat environment has evolved beyond their capabilities, and we need to evolve with it.”

What Does This Mean For Your Business?

For businesses, Microsoft’s announcement reflects a much broader change in cyber security. As AI makes phishing attacks more convincing and easier to automate, organisations are increasingly moving away from authentication methods that depend on passwords, text messages and one-time codes.

The change also shows that passkeys are rapidly becoming the new standard for business identity protection rather than an emerging technology. Organisations that continue relying heavily on SMS or voice authentication may find themselves under increasing pressure to modernise as software suppliers, regulators and cyber insurers place greater emphasis on phishing-resistant authentication.

The move reflects a wider change across the cyber security industry as organisations look to replace authentication methods that can be phished, intercepted or manipulated with stronger, phishing-resistant alternatives.

For businesses already using Microsoft Entra ID, the message is that now is the time to begin planning the move to passkeys, preparing users for the change and ensuring authentication policies are ready well before Microsoft’s new deadlines take effect.

Posted in

Mike Knight