• 2 min read
Microsoft makes Entra passkeys the default in September
Microsoft will switch Entra ID users on SMS and voice MFA to passkeys starting in September 2026, ahead of retiring telecom-based auth on February 1, 2027.

Image: BleepingComputer
Microsoft says passkeys will become the default authentication method for Entra ID starting in September 2026, a shift that will automatically affect users who still rely on SMS and voice-based authentication.
Those phone-based methods will be fully retired on February 1, 2027 across all tenants. Users already signing in with phishing-resistant options such as passkeys, Windows Hello for Business, FIDO2 security keys, smart cards, or other similar methods will not need to change.
Microsoft said that as the rollout reaches each organization, users currently enabled for SMS or voice authentication will be prompted to register a passkey the next time they complete multifactor authentication.
“As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey.”
The company also warned that organizations should move users to phishing-resistant authentication before the 2027 cutoff to avoid sign-in disruptions, since SMS and voice will no longer be available as native Microsoft Entra capabilities after that date.
Admins with the Global Reader, Authentication Policy Administrator, or Security Reader roles can identify affected users with the Entra SMS/Voice Policy Scanner PowerShell script. Organizations that still need phone-based authentication will have to use third-party telecom providers through the Microsoft Security Store.

Recommended reading
Joomla extension bugs hit CISA’s exploited list
Microsoft tied the change to a broader rise in credential theft and phishing. The company said threat actors, including the ShinyHunters extortion gang, have recently targeted Microsoft Entra SSO accounts in SaaS data-theft campaigns using stolen credentials.
It also said Microsoft Threat Intelligence has seen AI-enabled phishing campaigns hit click-through rates of 54%, versus roughly 12% for more traditional campaigns.
“Microsoft Threat Intelligence has observed AI-enabled phishing campaigns reaching click-through rates as high as 54%, compared with roughly 12% for more traditional campaigns, making stolen passwords and phishable second factors an urgent risk.”
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


