Microsoft Is Making Passkeys the Default Sign-In Method: What Your Business Needs to Know
Cybersecurity threats continue to evolve, and older multifactor authentication methods such as SMS text messages and voice calls are no longer considered strong enough for today’s threat environment. The Cybersecurity and Infrastructure Security Agency (CISA) has warned that not all MFA methods offer the same level of protection, noting that some methods can be vulnerable to phishing, SIM-swapping, Signaling System 7 (SS7) exploitation, and other attacks that may allow threat actors to intercept codes or bypass MFA protections. Microsoft has also stated that SMS and voice are among the most vulnerable authentication methods available today because attackers can increasingly phish, intercept, or manipulate these channels. That is why Microsoft is moving organizations toward phishing-resistant authentication and making Passkeys the default authentication method in Microsoft Entra ID.
Passkeys are part of a broader shift toward authentication that is both more secure and easier for users. Instead of relying on passwords or one-time codes that can be stolen, Passkeys use public-key cryptography and device-based verification, such as Windows Hello, facial recognition, fingerprint recognition, or a device PIN. This helps reduce the risk of phishing and credential theft while simplifying the sign-in experience for employees across devices and applications. Organizations can strengthen this approach even further by combining Passkeys with password management and identity security tools like Keeper, which Infotect offers to help businesses securely manage credentials, reduce password-related risk, and support a more practical path toward stronger authentication.
What Is Changing?
Beginning September 1, 2026, Microsoft will start rolling out Passkeys as the default authentication experience for users who currently rely on SMS or voice authentication for multifactor authentication (MFA). Users will be prompted to register a Passkey the next time they complete an MFA sign-in process.
Microsoft has also announced that its built-in SMS and voice authentication services for Entra ID will be retired on February 1, 2027. Organizations that continue to use these methods after that date will need to work with third-party telecom providers or transition users to more secure authentication options.
What Does This Mean for Your Organization?
For most organizations, there is no immediate action required today. However, businesses should begin preparing for the transition by:
Identifying users who currently rely on SMS or voice authentication
Educating employees about Passkeys
Planning for user enrollment as Microsoft introduces Passkey registration prompts
Working with your IT partner to ensure a smooth transition before February 2027
Learn More
For complete details, review Microsoft's official announcement:
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID – Read Microsoft's announcement