Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
ID: 088708f5-6306-5475-a364-3e63e954b84b
STIX ID: report--088708f5-6306-5475-a364-3e63e954b84b
Feed Name: Microsoft Security
Microsoft Entra ID will make passkeys the default phishing-resistant authentication method starting Sept 1, 2026, auto-enabling passkeys for users who currently use SMS or voice and prompting them at next MFA sign-in; Microsoft will retire its native SMS/voice telecom delivery on Feb 1, 2027, after which organizations requiring SMS/voice must contract third-party telecom providers via the Microsoft Security Store. The announcement explains the security rationale (AI-enabled phishing and SIM swap risks), provides a timeline and migration guidance (identify users, plan passkey rollout, run registration campaigns, and prepare communications), and lists key dates for provider selection and enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
