
Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication
Microsoft Prioritizes Phishing Resistance: Passkeys Default for Entra ID, SMS/Voice MFA Phased Out
The digital landscape demands robust authentication, and Microsoft is taking a significant step forward. In a strategic move to bolster security against prevalent phishing attacks, Microsoft is making passkeys the default authentication experience within Microsoft Entra ID. This pivotal change is accompanied by the scheduled retirement of Microsoft-provided SMS and voice authentication for multi-factor authentication (MFA), pushing organizations toward more resilient credentialing methods. This shift directly addresses the escalating threat of phishing, which continues to exploit weaker authentication mechanisms.
The Evolution of Entra ID Authentication
Microsoft Entra ID (formerly Azure Active Directory) is central to identity and access management for countless organizations globally. Its security features are paramount to protecting corporate resources. The decision to elevate passkeys to the default authentication method underscores a clear commitment to phishing-resistant credentials. Traditional methods like passwords, and even one-time codes delivered via SMS or voice, remain susceptible to sophisticated phishing techniques that can intercept or trick users into revealing their credentials.
Passkeys, built on the FIDO (Fast Identity Online) standard, offer a cryptographic, device-bound, and phishing-resistant alternative. They eliminate the need for shared secrets (passwords) and significantly reduce the attack surface for credential theft.
Phasing Out SMS and Voice MFA: A Necessary Transition
While SMS and voice authentication provided an additional layer of security over single-factor authentication, their inherent vulnerabilities have become increasingly apparent. SIM swap attacks, social engineering, and the interception of SMS messages pose significant risks. Microsoft’s decision to retire these methods reflects a critical understanding of the evolving threat landscape.
Starting September 1, 2026, users currently enabled for SMS or voice authentication will be impacted. Organizations relying on these methods must proactively transition their users to stronger, phishing-resistant alternatives. This deadline provides a clear roadmap for migration and emphasizes the urgency of adopting modern authentication practices.
Why Passkeys Are the Future of Authentication
Passkeys represent a paradigm shift in user authentication. They offer several key advantages:
- Phishing Resistance: Passkeys are cryptographically tied to a specific device and website, making them immune to phishing attacks where users are tricked into entering credentials on a malicious site.
- Enhanced Security: They eliminate shared secrets (passwords) and rely on public-key cryptography, significantly reducing the risk of credential compromise.
- Improved User Experience: Passkeys often involve simple biometric verification (fingerprint, face recognition) or a device PIN, offering a faster and more seamless login experience than typing complex passwords or one-time codes.
- Standardization: Based on the FIDO standard, passkeys promote interoperability across various devices and platforms.
Remediation Actions and Migration Strategy
For organizations utilizing Microsoft Entra ID, this announcement necessitates immediate action and a strategic migration plan. Here are key remediation steps:
- Audit Current MFA Usage: Identify all users currently configured for SMS or voice authentication within Entra ID.
- Educate Users: Launch comprehensive awareness campaigns to inform users about the upcoming changes, the benefits of passkeys, and the deprecation of SMS/voice MFA.
- Enable Passkey Registration: Configure Entra ID to allow and encourage passkey registration for users. Provide clear instructions and support for the registration process.
- Implement Conditional Access Policies: Utilize Entra ID Conditional Access policies to enforce the use of phishing-resistant MFA methods, including passkeys, for sensitive applications and resources.
- Phased Rollout: Consider a phased approach for migrating users from SMS/voice MFA to passkeys or other strong authentication methods. Start with pilot groups before broader deployment.
- Explore Alternative Strong MFA: If passkeys are not immediately feasible for all users, explore other strong, phishing-resistant MFA options supported by Entra ID, such as FIDO2 security keys.
- Monitor Progress: Continuously monitor user adoption of new authentication methods and address any challenges or support needs.
Conclusion
Microsoft’s decision to make passkeys the default authentication in Entra ID and retire SMS and voice authentication marks a crucial turning point in enterprise cybersecurity. This proactive measure strengthens the authentication posture of organizations, significantly mitigating the risks associated with phishing attacks. By embracing phishing-resistant credentials like passkeys, businesses can provide a more secure and efficient access experience for their users, aligning with the highest standards of modern identity protection. The September 1, 2026 deadline for SMS and voice authentication retirement serves as a clear call to action for organizations to transition to more robust security measures.


