Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

0
Medium
Vulnerability
Published: 07/13/2026 (07/13/2026, 17:00:00 UTC)
Source: Microsoft Security Blog

Description

Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 11:18:35 UTC

Technical Analysis

Microsoft Entra ID is updating its authentication experience by making passkeys the default sign-in method starting September 1, 2026. Passkeys use public-key cryptography, providing phishing-resistant authentication compared to SMS and voice methods, which rely on shared secrets vulnerable to interception and social engineering. Microsoft will retire its native SMS and voice authentication delivery on February 1, 2027. Organizations must transition users to passkeys or configure third-party telecom providers via the Microsoft Security Store for SMS/voice if required. This change responds to the evolving threat landscape, including AI-powered phishing campaigns and MFA bypass tactics, to enhance identity security.

Potential Impact

The update reduces reliance on phishable authentication methods (SMS and voice) that are vulnerable to interception, SIM swapping, and social engineering. By making passkeys the default, Microsoft Entra ID strengthens protection against credential theft and phishing attacks. Organizations continuing to use SMS or voice authentication must contract with third-party telecom providers and bear associated costs. Users will be required to register passkeys for MFA sign-in after the transition, improving overall authentication security posture.

Mitigation Recommendations

A fix is effectively available as Microsoft is rolling out passkeys as the default authentication method starting September 1, 2026. Organizations should plan and execute migration to passkeys promptly to avoid reliance on SMS and voice authentication, which Microsoft will no longer natively support after February 1, 2027. If SMS or voice authentication remains necessary, organizations must select and configure supported third-party telecom providers through the Microsoft Security Store before the retirement date. Microsoft provides detailed deployment guidance and user communication resources to facilitate this transition.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/","fetched":true,"fetchedAt":"2026-07-14T11:18:16.572Z","wordCount":1784}

Threat ID: 6a561afa68715ace4363d715

Added to database: 07/14/2026, 11:18:18 UTC

Last enriched: 07/14/2026, 11:18:35 UTC

Last updated: 08/25/2026, 00:41:25 UTC

Views: 53

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses