Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog .
AI Analysis
Technical Summary
Microsoft Entra ID is updating its authentication experience by making passkeys the default sign-in method starting September 1, 2026. Passkeys use public-key cryptography, providing phishing-resistant authentication compared to SMS and voice methods, which rely on shared secrets vulnerable to interception and social engineering. Microsoft will retire its native SMS and voice authentication delivery on February 1, 2027. Organizations must transition users to passkeys or configure third-party telecom providers via the Microsoft Security Store for SMS/voice if required. This change responds to the evolving threat landscape, including AI-powered phishing campaigns and MFA bypass tactics, to enhance identity security.
Potential Impact
The update reduces reliance on phishable authentication methods (SMS and voice) that are vulnerable to interception, SIM swapping, and social engineering. By making passkeys the default, Microsoft Entra ID strengthens protection against credential theft and phishing attacks. Organizations continuing to use SMS or voice authentication must contract with third-party telecom providers and bear associated costs. Users will be required to register passkeys for MFA sign-in after the transition, improving overall authentication security posture.
Mitigation Recommendations
A fix is effectively available as Microsoft is rolling out passkeys as the default authentication method starting September 1, 2026. Organizations should plan and execute migration to passkeys promptly to avoid reliance on SMS and voice authentication, which Microsoft will no longer natively support after February 1, 2027. If SMS or voice authentication remains necessary, organizations must select and configure supported third-party telecom providers through the Microsoft Security Store before the retirement date. Microsoft provides detailed deployment guidance and user communication resources to facilitate this transition.
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Description
Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft Entra ID is updating its authentication experience by making passkeys the default sign-in method starting September 1, 2026. Passkeys use public-key cryptography, providing phishing-resistant authentication compared to SMS and voice methods, which rely on shared secrets vulnerable to interception and social engineering. Microsoft will retire its native SMS and voice authentication delivery on February 1, 2027. Organizations must transition users to passkeys or configure third-party telecom providers via the Microsoft Security Store for SMS/voice if required. This change responds to the evolving threat landscape, including AI-powered phishing campaigns and MFA bypass tactics, to enhance identity security.
Potential Impact
The update reduces reliance on phishable authentication methods (SMS and voice) that are vulnerable to interception, SIM swapping, and social engineering. By making passkeys the default, Microsoft Entra ID strengthens protection against credential theft and phishing attacks. Organizations continuing to use SMS or voice authentication must contract with third-party telecom providers and bear associated costs. Users will be required to register passkeys for MFA sign-in after the transition, improving overall authentication security posture.
Mitigation Recommendations
A fix is effectively available as Microsoft is rolling out passkeys as the default authentication method starting September 1, 2026. Organizations should plan and execute migration to passkeys promptly to avoid reliance on SMS and voice authentication, which Microsoft will no longer natively support after February 1, 2027. If SMS or voice authentication remains necessary, organizations must select and configure supported third-party telecom providers through the Microsoft Security Store before the retirement date. Microsoft provides detailed deployment guidance and user communication resources to facilitate this transition.
Technical Details
- Article Source
- {"url":"https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/","fetched":true,"fetchedAt":"2026-07-14T11:18:16.572Z","wordCount":1784}
Threat ID: 6a561afa68715ace4363d715
Added to database: 07/14/2026, 11:18:18 UTC
Last enriched: 07/14/2026, 11:18:35 UTC
Last updated: 08/25/2026, 00:41:25 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.