Microsoft Sets Passkeys as Default Authentication in Entra ID, Phasing Out SMS and Voice

0
1

Key Takeaways

  • Microsoft will make passkeys the default authentication method in Microsoft Entra ID, retiring built‑in SMS and voice MFA.
  • Starting Sept 1 2026, users currently using SMS/voice will be prompted to register a passkey at their next MFA sign‑in.
  • The automatic passkey enablement can be postponed, but the transition is irreversible; full retirement of native telecom delivery occurs Feb 1 2027.
  • After the retirement date, any user whose only MFA option is SMS/voice must register a passkey before they can sign in—no opt‑out will be allowed.
  • Organizations should identify affected users, enable Passkey (FIDO2), and run a staged registration campaign well before the deadlines.
  • A temporary opt‑out for the automatic passkey enablement (Sept 1 2026 – Feb 1 2027) is available via Microsoft Graph, but it only delays, not prevents, the eventual mandatory passkey requirement.
  • Post‑retirement, organizations needing SMS/voice must use a customer‑managed telecom provider from the Microsoft Security Store, reserving such services for limited regulatory or operational needs.
  • Emphasizing passkeys, Windows Hello for Business, and FIDO2 security keys will strengthen security and reduce reliance on phishing‑prone authentication channels.

Microsoft’s Shift to Passkeys as Default Authentication
Microsoft announced that passkeys will become the default sign‑in experience in Microsoft Entra ID, marking a strategic move away from authentication methods that are vulnerable to phishing. This change aligns with the broader industry push toward phishing‑resistant credentials, such as FIDO2‑based keys, which eliminate reusable secrets that attackers can harvest from fake login pages. By establishing passkeys as the default, Microsoft aims to simplify security for end users while raising the baseline protection for enterprises.

Timeline for Automatic Passkey Enablement
Beginning September 1 2026, any user who is currently enabled for SMS or voice‑based multifactor authentication (MFA) will automatically be enrolled for passkeys. During their next MFA sign‑in, these users will see a prompt encouraging them to register a passkey on their device or credential manager. The prompt will appear repeatedly until the user completes registration, though they may postpone it during the transition window.

User Control During the Transition Period
While the automatic enablement will start in September 2026, Microsoft allows users to repeatedly postpone the registration prompt. This grace period is intended to give organizations and end users time to adapt without immediate lockout. However, postponing does not cancel the requirement; it merely delays the inevitable push toward passkey registration before the final retirement date.

Security Risks of SMS and Voice Authentication
SMS and voice‑based MFA have long been targeted by attackers using techniques such as phishing kits, SIM swapping, social engineering, number porting, and interception. Because these methods rely on a shared secret that can be reused or intercepted, they are inherently less resistant to credential theft. Passkeys, by contrast, use cryptographic credentials bound to a specific device or credential manager, eliminating the reusable secret that attackers could replay on a fraudulent site.

Types of Passkeys Supported in Entra ID
Microsoft Entra ID supports both synced and device‑bound passkeys. Synced passkeys can be stored in cloud credential managers such as iCloud Keychain or Google Password Manager, allowing seamless use across a user’s multiple devices. Device‑bound passkeys remain tied to a single piece of hardware and include options like Windows Hello for Business, Microsoft Authenticator passkeys, Entra Passkey on Windows, and FIDO2 security keys. This flexibility lets organizations choose the model that best fits their security and usability requirements.

Final Retirement of Native Telecom Delivery
The next major milestone is February 1 2027, when Microsoft will fully retire its native telecom delivery for SMS and voice authentication in Entra ID. After this date, the built‑in SMS and voice channels will no longer function. Organizations that still depend on these methods must switch to a customer‑managed telecom provider available through the Microsoft Security Store. Microsoft will publish the list of approved providers starting September 18 2026, with configuration possible from October 30 2026.

Mandatory Passkey Registration After Retirement
Once the native SMS and voice services are retired, any user whose only remaining MFA option is SMS or voice will encounter a blocking passkey registration prompt at sign‑in. They will be required to register a passkey before they can access their account. Microsoft explicitly states that there will be no opt‑out from this enforcement, making early migration essential to avoid disruption of user access and potential help‑desk overload.

Preparation Steps for Administrators
Administrators should begin by identifying users who are still enabled for SMS or voice in the Entra Authentication Methods Policy or in any legacy MFA configurations. Microsoft provides a PowerShell‑based analyzer to help locate these accounts. After identification, security teams should enable the Passkey (FIDO2) authentication method, create targeted user groups, and launch a staged registration campaign. This phased approach allows organizations to monitor adoption, address issues, and ensure a smooth transition before the automatic enablement begins.

Temporary Opt‑Out Mechanism
Between September 1 2026 and February 1 2027, administrators can temporarily delay the automatic passkey enablement by setting the passkeyDynamicMigration property in the authentication methods policy via Microsoft Graph. This opt‑out only postpones the migration; it does not exempt organizations from the eventual February 2027 retirement or the mandatory passkey requirement. Using this setting can be useful for pilot groups or for aligning the rollout with internal change‑management windows.

Strategic Implications for Enterprises
The announcement signals that SMS and voice MFA should now be regarded as legacy fallback options rather than long‑term authentication controls. Enterprises are encouraged to prioritize passkeys, Windows Hello for Business, and FIDO2 security keys as their primary MFA factors. Customer‑managed telecom services should be reserved for narrowly defined scenarios—such as specific regulatory mandates or operational constraints—where phishing‑resistant alternatives cannot be deployed. By adopting passkeys broadly, organizations reduce the attack surface associated with credential interception and SIM‑based fraud, while also benefitting from a more user‑friendly authentication experience that does not rely on memorizing or entering codes.

Conclusion: Moving Toward a Phishing‑Resistant Future
Microsoft’s roadmap for Entra ID makes it clear that the future of authentication lies in device‑bound, cryptographic credentials that are inherently resistant to phishing and replay attacks. The phased rollout—starting with automatic prompts in September 2026 and culminating in the mandatory passkey requirement after February 2027—gives organizations a clear timeline to prepare. By following the recommended steps—identifying affected users, enabling passkey options, running targeted registration campaigns, and leveraging the temporary opt‑out only when necessary—enterprises can achieve a seamless transition, enhance security posture, and eliminate reliance on outdated, vulnerable authentication methods.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here