Microsoft Entra ID gets passkeys default authentication starting September
ID: b5656ef2-facc-5c65-82c0-75ae68a97cd7
STIX ID: report--b5656ef2-facc-5c65-82c0-75ae68a97cd7
Feed Name: Bleeping Computer
Microsoft will make passkeys the default Entra ID authentication beginning September 2026 and will retire Microsoft-provided SMS and voice multifactor authentication on February 1, 2027; users currently using phone-based SMS/voice will be automatically prompted to register passkeys and organizations should ensure all users adopt phishing-resistant methods (passkeys, Windows Hello for Business, FIDO2, smart cards) to avoid sign-in disruptions. The change is motivated by rising credential theft and AI-enabled phishing (including campaigns linked to groups like ShinyHunters) and Microsoft provides tooling and documentation to help admins discover SMS/voice users and deploy passwordless authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
