Site icon Publoria Blogs

Microsoft Makes Passkeys the Default for Entra ID as Passwordless Security Expands

Microsoft Makes Passkeys

REDMOND, Wash. — Microsoft is making a major change to how millions of workplace users authenticate, turning passkeys into the default authentication experience in Microsoft Entra ID as the technology industry moves away from passwords, text-message codes and other methods increasingly vulnerable to phishing.

Beginning September 1, 2026, Microsoft will start rolling out passkeys as the default authentication experience for users in Entra ID who are currently enabled for SMS or voice authentication. Those users will be automatically enabled for passkeys and prompted to register one during a future multifactor-authentication sign-in.

The change represents one of Microsoft’s clearest moves yet toward passwordless, phishing-resistant authentication.

It also comes as businesses face a more aggressive cyber threat environment in which attackers increasingly use social engineering, credential theft, automated phishing and AI-assisted techniques to compromise employee accounts.

Microsoft Is Moving Away From SMS and Voice

For years, SMS and voice calls have been widely used as second-factor authentication methods.

They were a significant improvement over passwords alone because an attacker generally needed access to a user’s phone or telephone number to complete the authentication process.

But security researchers have long warned that these methods remain vulnerable to phishing, SIM-swapping attacks and social engineering.

Microsoft now considers passkeys a stronger alternative.

The company says passkeys use public-key cryptography and are designed to resist phishing because the authentication credential is not shared with a website in the same way as a password or one-time code.

What Changes on September 1

The first major transition begins September 1.

Users who are enabled for SMS or voice authentication in Microsoft Entra ID will automatically be enabled for passkeys under Microsoft’s managed authentication settings.

When those users subsequently complete multifactor authentication, they will receive a prompt encouraging them to register a passkey.

Microsoft says organizations should begin preparing users before the rollout rather than waiting for the prompts to appear.

The company is also providing administrators with tools to identify employees who still rely on SMS or voice authentication.

February 2027 Brings a Bigger Change

The September rollout is only the first step.

Microsoft plans to retire Microsoft-provided SMS and voice authentication on February 1, 2027.

After that date, organizations that still need SMS or voice authentication for specific regulatory, technical or operational reasons will be able to use supported third-party telecommunications providers through the Microsoft Security Store.

For organizations without a specific need to retain SMS or voice, Microsoft’s recommended path is to move users to passkeys or another phishing-resistant authentication method.

The company says that after February 1, users whose only available MFA option is SMS or voice will be required to register a passkey before they can continue signing in.

Why Microsoft Is Making the Change

Microsoft’s argument is straightforward: the threat landscape has changed.

SMS and voice authentication were designed for an earlier security environment.

Today’s attackers can automate phishing campaigns, impersonate legitimate services and manipulate users at scale.

Microsoft says its threat intelligence has observed AI-enabled phishing campaigns with significantly higher click-through rates than more traditional campaigns.

That creates a problem for businesses.

An employee does not necessarily have to be technically sophisticated to become the entry point for an attack.

A convincing phishing message can persuade a user to disclose a password or authentication code.

Passkeys are intended to make that process much harder.

How Passkeys Work

Passkeys replace traditional password-based authentication with cryptographic credentials.

Instead of a password that can be copied and entered on another website, a passkey relies on a private cryptographic key stored through a supported device or credential manager.

The corresponding public key is registered with the service.

During authentication, the device proves possession of the private key without exposing it to the website.

That makes passkeys fundamentally different from passwords and one-time SMS codes.

Passkeys Can Be Stored in Different Ways

Microsoft Entra ID supports several types of passkeys.

These include synced passkeys, which can be stored in platform credential managers such as iCloud Keychain or Google Password Manager.

It also supports device-bound passkeys, including passkeys stored in Microsoft Authenticator, Windows environments and FIDO2 security keys.

That flexibility is important for large companies with employees using different devices and operating systems.

FIDO2 Security Keys Remain an Option

Organizations with particularly sensitive environments can use hardware-based FIDO2 security keys.

Microsoft describes these as device-bound passkeys in which the private key remains on the physical security key.

Such devices can connect through USB, NFC or Bluetooth depending on the model.

Microsoft recommends these types of credentials for highly regulated industries and users with elevated privileges.

That could include administrators who have access to critical company infrastructure.

The Goal Is Phishing Resistance

The biggest security advantage of passkeys is their resistance to phishing.

With a traditional password, an attacker can create a fake login page and persuade a user to enter credentials.

The attacker can then reuse those credentials against the legitimate service.

A passkey is tied cryptographically to the legitimate website or service.

That makes the traditional fake-login-page technique substantially less effective.

AI Is Raising the Stakes

Microsoft’s decision comes as artificial intelligence is changing the cybersecurity landscape.

AI can help defenders identify threats faster, but it can also help attackers create more convincing phishing campaigns.

Attackers can generate personalized messages, imitate writing styles and automate social-engineering operations.

The result is a security environment in which employees may face more convincing attacks than they did only a few years ago.

Microsoft says this is one reason phishing-resistant authentication has become increasingly important in the AI era.

Passwords Are Becoming the Weakest Link

Passwords remain one of the most common sources of account compromise.

Users reuse passwords, choose predictable combinations and sometimes store credentials in insecure locations.

Even strong passwords can be stolen through phishing or malware.

Multifactor authentication provides an additional layer, but the security of MFA depends on the authentication method.

A phishing-resistant passkey can therefore provide stronger protection than a password combined with an SMS code.

Microsoft’s Broader Zero Trust Strategy

The passkey rollout is part of Microsoft’s broader push toward identity-based security.

Microsoft Entra Conditional Access acts as a Zero Trust policy engine, allowing organizations to make access decisions based on signals involving users, devices and applications.

The broader philosophy is that organizations should not automatically trust users simply because they are connected to a corporate network.

Instead, access should be continuously evaluated.

Strong authentication is a central component of that approach.

Businesses Will Need to Prepare Employees

The technology may be more secure, but adoption still requires planning.

Employees need to understand what a passkey is, how to register one and how to recover access if they lose a device.

IT departments need to identify users who still depend on SMS or voice authentication.

They also need to ensure that authentication policies are configured correctly.

Microsoft recommends organizations begin the migration before the mandatory deadlines.

The Help Desk Could Become a Critical Factor

Large passkey migrations can create an unexpected operational challenge: employee support.

When authentication systems change, users may encounter problems with device compatibility, account recovery or registration.

That means companies should prepare help-desk teams before launching large-scale passkey registration campaigns.

Microsoft’s registration campaign features are intended to help organizations move users to passkeys at scale while reducing the administrative burden.

Companies Have Some Flexibility During the Transition

Microsoft is not eliminating every option immediately.

A temporary opt-out mechanism is available during the September 1, 2026 through February 1, 2027 transition period for organizations that need additional time to migrate users or establish alternative arrangements.

However, Microsoft says the standard passkey migration and enforcement timeline will apply after February 1, 2027.

That gives businesses a window to prepare without making the transition indefinite.

Regulated Industries May Face Different Needs

Some organizations operate under regulations or technical requirements that may make SMS or voice authentication necessary in certain circumstances.

Microsoft has acknowledged these scenarios.

Beginning October 30, 2026, customers with legitimate needs to retain SMS or voice will be able to select and configure supported telecommunications providers through the Microsoft Security Store.

That approach allows Microsoft to move its own platform away from native SMS and voice delivery while giving specialized customers an alternative.

What This Means for IT Departments

For corporate IT teams, the transition creates several immediate priorities.

First, administrators should identify which employees still use SMS or voice authentication.

Second, they should determine which passkey types are appropriate for different employee groups.

Third, organizations should test registration and account-recovery procedures.

Fourth, companies should communicate the change clearly before users encounter the new prompts.

A poorly managed rollout could create unnecessary confusion.

A well-planned migration could significantly strengthen an organization’s identity security.

Passkeys Could Reduce Security Costs

There may also be a financial benefit.

Successful phishing attacks can lead to account takeovers, ransomware incidents, data breaches and expensive investigations.

Preventing those attacks can save businesses significant amounts of money.

Passkeys may also reduce some password-reset and authentication-related support requests over time.

The savings will vary by organization, but the security benefits could make passwordless authentication increasingly attractive to large enterprises.

Microsoft Is Not Alone

Microsoft’s move reflects a broader industry shift.

Apple, Google and other major technology companies have already incorporated passkeys into consumer and enterprise authentication experiences.

The technology is increasingly supported across smartphones, browsers and operating systems.

That growing compatibility is important because authentication standards become more useful when users can carry credentials across the devices and services they already use.

The Enterprise Market Is Moving First

Large businesses are particularly important to the passkey transition.

Enterprise accounts can provide attackers with access to sensitive databases, cloud infrastructure, financial systems and internal communications.

A compromised administrator account can be especially damaging.

For that reason, organizations are increasingly prioritizing phishing-resistant authentication for employees with elevated privileges.

Microsoft’s Entra rollout could accelerate that trend.

The Consumer Experience Could Also Change

Although the current announcement focuses on Microsoft Entra ID, the broader shift toward passkeys could eventually influence how consumers interact with online services.

As people become accustomed to unlocking accounts with a fingerprint, face scan, device PIN or hardware key rather than typing a password, traditional password-based authentication may become less common.

The long-term goal is a web where authentication is both more secure and easier to use.

The Security Industry Is Watching

Cybersecurity companies are closely watching the passkey transition because identity security has become one of the fastest-growing areas of enterprise security.

As organizations move away from passwords, companies that provide identity-management, privileged-access management and endpoint-security tools will need to adapt.

Passkeys could become a foundational component of enterprise security architectures.

The Remaining Challenge Is Adoption

Technology alone cannot solve every authentication problem.

Users still need secure devices.

Companies still need strong access policies.

Administrators still need to monitor suspicious activity.

Employees still need to understand security risks.

Passkeys can reduce the effectiveness of phishing, but they do not eliminate every possible route into an account.

Identity security will therefore remain a layered discipline.

What Companies Should Do Now

Organizations using Microsoft Entra ID should consider several steps before the September rollout:

The objective should be to complete the transition before Microsoft’s mandatory deadline.

A Major Turning Point for Enterprise Authentication

Microsoft’s decision is more than a product update.

It represents a broader change in how companies think about identity.

For decades, passwords were the default way people proved who they were online.

Then came multifactor authentication.

Now the industry is moving toward authentication that does not rely on shared secrets at all.

Passkeys represent a significant step in that evolution.

The Bottom Line

Microsoft is making passkeys the default authentication experience in Microsoft Entra ID beginning September 1, 2026, accelerating the enterprise shift away from SMS, voice authentication and other phishing-prone methods.

Users currently enabled for SMS or voice authentication will be automatically enabled for passkeys and prompted to register them as the rollout reaches their organization.

The next major deadline comes on February 1, 2027, when Microsoft will retire its own native SMS and voice authentication delivery for Entra ID. Organizations that have legitimate reasons to continue using those methods will be able to work with supported third-party telecom providers.

The move reflects Microsoft’s broader response to a rapidly changing cybersecurity environment.

AI-assisted phishing, social engineering and automated attacks are making traditional authentication methods increasingly vulnerable. Microsoft argues that passkeys provide stronger protection because they use public-key cryptography and are designed to resist phishing.

For businesses, the message is clear: passwordless authentication is moving from an optional security upgrade toward the default enterprise model.

The organizations that begin preparing now will have more time to test their authentication policies, educate employees and establish recovery procedures.

Those that wait until the deadlines arrive could face unnecessary disruption.

As Microsoft pushes Entra ID toward a passkey-first future, the broader technology industry is moving toward a new security standard—one where proving your identity no longer depends on remembering a secret or trusting a text message.

Source angle: Microsoft Security Blog and Microsoft Learn documentation covering the Entra ID passkey rollout, SMS/voice retirement timeline, phishing-resistant authentication and enterprise identity security.

Exit mobile version