CyberSecurity SEE

Microsoft Sets Passkeys as Default in Entra ID, Phases Out SMS and Voice Authentication

Microsoft Sets Passkeys as Default in Entra ID, Phases Out SMS and Voice Authentication

Microsoft Announces Transition to Passkeys as Default Authentication in Entra ID

In a significant shift in authentication strategy, Microsoft has announced that beginning September 1, 2026, passkeys will become the default authentication method in Entra ID. This move is accompanied by the decision to fully retire Microsoft’s native SMS and voice multifactor authentication (MFA) services, set to conclude on February 1, 2027. This decision underscores the company’s ongoing commitment to enhancing security as enterprises increasingly adopt cloud technologies, remote access solutions, and workflows driven by artificial intelligence.

The transition toward passkeys aligns with Microsoft’s broader initiative to eliminate phishable credentials, which have become prevalent targets for various cyber threats, including credential phishing, man-in-the-middle attacks, SIM swapping, social engineering schemes, and replay attacks. By addressing these vulnerabilities, Microsoft aims to bolster the security posture of organizations utilizing its platforms.

Under the new policy, users currently relying on SMS or voice authentication within the Entra ID ecosystem will automatically have their accounts configured for passkeys through the Authentication Methods Policy. When these users log in and are prompted for multifactor authentication, they will be directed to register a passkey. Microsoft plans to manage this registration campaign, targeting eligible users to facilitate a smoother transition while minimizing the administrative workload for organizations.

Passkeys utilize public-key cryptography, a methodology that eliminates the need for shared secrets. In this system, a private key is kept securely on the user’s device or authenticator, while the corresponding public key is maintained by the service. This architecture significantly enhances security since no reusable passwords or one-time codes are transmitted during the authentication process, reducing the likelihood of credential theft or phishing attempts that could lead to unauthorized account access. Entra ID will support both synced and device-bound passkeys.

Synced passkeys can be stored in credential management solutions such as iCloud Keychain and Google Password Manager, enabling users to access their credentials across various devices seamlessly. In contrast, device-bound passkeys are tethered to a specific platform or authenticator, preventing misuse across different devices.

Various device-bound authentication options are expected, including Windows Hello for Business and Microsoft Authenticator, as well as FIDO2 hardware security keys. Organizations with heightened security needs may find device-bound credentials or hardware-backed keys preferable, particularly for users managing privileged accounts, administrators, and other sensitive business operations.

As the retirement date for Microsoft-provided SMS and voice MFA services approaches, organizations should take necessary measures to adapt to the new policies. After February 1, 2027, users who continue to rely solely on SMS or voice authentication will encounter a mandatory passkey registration prompt, a barrier obstructing their access to Entra-protected applications and resources. Microsoft has emphasized that this enforcement is non-negotiable and applies to all tenants, eliminating any opt-out alternatives.

To facilitate a smooth transition, administrators are encouraged to proactively identify affected users via the Entra Authentication Methods Policy and legacy MFA settings. Microsoft has made available a PowerShell-based usage analyzer designed to help organizations evaluate their reliance on SMS and voice MFA. In order to run this assessment, users must possess Global Reader, Authentication Policy Administrator, or Security Reader permissions.

A well-planned migration strategy is advisable, encompassing steps to enable FIDO2 passkeys, establish security groups for impacted users, initiate a registration campaign, and effectively communicate with end-users. While users might initially postpone enrollment prompts, organizations should implement internal deadlines and provide clear directives on how to register and recover passkeys.

In the interim period from September 1, 2026, through February 1, 2027, it will be possible for administrators to temporarily defer automatic passkey enablement and registration campaigns. Utilizing Microsoft Graph beta, administrators with the appropriate permissions can set the passkeyDynamicMigration opt-out property to true. However, it should be noted that this setting does not extend the deadline for the retirement of SMS and voice authentication.

For enterprises that still require out-of-band telecom authentication after February 2027, it is imperative to secure a customer-managed provider before the retirement date. Meanwhile, most organizations should prioritize the implementation of passkeys, Windows Hello, or other phishing-resistant methods to mitigate disruption for users.

As the cybersecurity landscape evolves, the transition to passkeys represents a proactive strategy for addressing current security challenges while fostering a more resilient authentication framework for users and organizations alike.

Source link

Exit mobile version