Passwords and SMS Are Dead: Microsoft Begins Sunsetting Text Message Verification for Consumer Accounts
ID: c52a9fa1-cc64-5f90-8c61-402224f16525
STIX ID: report--c52a9fa1-cc64-5f90-8c61-402224f16525
Feed Name: securityonline.info
Microsoft announces the phased deprecation of SMS verification for consumer accounts and urges users to adopt passkeys, biometrics, or verified email one‑time passwords. The advisory explains that SMS-based tokens are susceptible to interception and SIM‑swap attacks, describes how passkeys provide non-exportable, origin‑bound cryptographic authentication, and recommends registering multiple passkeys or revoking passwords to achieve a passwordless account posture.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
