{"id":17788,"date":"2026-08-16T01:16:10","date_gmt":"2026-08-16T01:16:10","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17788"},"modified":"2026-08-16T01:16:10","modified_gmt":"2026-08-16T01:16:10","slug":"microsoft-makes-passkeys-default-in-entra-id-retires-sms-and-voice-authentication","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17788","title":{"rendered":"Microsoft Makes Passkeys Default in Entra ID, Retires SMS and Voice Authentication"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">Microsoft will make passkeys the default authentication expertise in Entra ID starting September 1, 2026, and can absolutely retire its native SMS and voice multifactor authentication (MFA) supply companies on February 1, 2027.<\/p>\n<p class=\"wp-block-paragraph\">Based on Microsoft, the transition is a part of Microsoft\u2019s broader effort to remove phishable credentials as enterprises broaden cloud utilization, distant entry, and AI-enabled workflows.<\/p>\n<p class=\"wp-block-paragraph\">Passwords, one-time SMS codes, and voice-based verification stay frequent targets of<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/threat-actors-exploit-com-tld-to-host\/\" target=\"_blank\" rel=\"noreferrer noopener\"> credential phishing<\/a>, adversary-in-the-middle assaults, SIM swapping, social engineering, and replay assaults.<\/p>\n<h2 id=\"h-microsoft-entra-id-makes-passkeys-default\" class=\"wp-block-heading\"><strong>Microsoft Entra ID Makes Passkeys Default<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Beneath the brand new coverage, Entra ID tenants with customers presently enabled for SMS or voice authentication can have these customers mechanically enabled for passkeys via the Authentication Strategies Coverage. When an affected consumer subsequently indicators in and is prompted for MFA, Entra ID will immediate them to register a passkey.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft will configure the Registration Marketing campaign in a Microsoft Managed state and mechanically goal eligible customers. This strategy is meant to scale back administrative effort whereas accelerating adoption of phishing-resistant authentication throughout enterprise tenants.<\/p>\n<p class=\"wp-block-paragraph\">Passkeys use public-key cryptography reasonably than shared secrets and techniques. A personal key stays protected on the consumer\u2019s gadget or authenticator, whereas the service retains the corresponding public key. <\/p>\n<p class=\"wp-block-paragraph\">As a result of no reusable password or one-time code is transmitted throughout authentication, passkeys are designed to withstand credential theft and phishing-based account takeover. Entra ID helps each synced and device-bound passkeys. <\/p>\n<p class=\"wp-block-paragraph\">Synced passkeys could be saved in credential managers, together with iCloud Keychain and Google Password Supervisor, permitting customers to entry credentials throughout supported gadgets. Machine-bound passkeys stay related to a selected platform or authenticator.<\/p>\n<p class=\"wp-block-paragraph\">Examples of device-bound authentication choices embrace Home windows Good day for Enterprise, Microsoft Authenticator, Entra Passkey on Home windows, and FIDO2 {hardware} safety keys. <\/p>\n<p class=\"wp-block-paragraph\">Organizations with increased assurance necessities might choose device-bound credentials or hardware-backed keys, significantly for privileged accounts, directors, and delicate enterprise techniques.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft-provided SMS and voice MFA companies shall be retired on February 1, 2027. Organizations that also require telecom-based MFA after that date should use a customer-managed supplier accessible via the Microsoft Safety Retailer. Microsoft plans to publish data on supported suppliers starting September 18, 2026. <\/p>\n<p class=\"wp-block-paragraph\">Buyer choice and configuration capabilities are anticipated to change into accessible on October 30, 2026, leaving enterprises with solely a restricted interval to guage, procure, check, and deploy an alternate telecom supplier earlier than the native service\u2019s retirement.<\/p>\n<p class=\"wp-block-paragraph\">The retirement creates a major operational danger for organizations that defer migration. After February 1, 2027, customers relying solely on SMS or voice authentication will obtain a blocking passkey-registration immediate. <\/p>\n<p class=\"wp-block-paragraph\">They have to register a passkey to keep up entry to Entra-protected purposes and sources. Microsoft has said that this enforcement will apply to all tenants and that no opt-out choice shall be accessible after the retirement date.<\/p>\n<p class=\"wp-block-paragraph\">Directors ought to subsequently establish affected customers within the Entra Authentication Strategies Coverage and legacy MFA settings as early as potential.<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/authentication\/concept-sms-voice-retirement\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft has printed<\/a> a PowerShell-based utilization analyzer to assist organizations assess their dependence on SMS and voice MFA. Working the evaluation requires World Reader, Authentication Coverage Administrator, or Safety Reader permissions.<\/p>\n<p class=\"wp-block-paragraph\">A staged migration ought to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/microsoft-entra-id-adds-passkey-fido2-support\/\" target=\"_blank\" rel=\"noreferrer noopener\">embrace enabling FIDO2 passkeys<\/a>, creating safety teams for affected customers, launching a registration marketing campaign, and issuing focused end-user communications.<\/p>\n<p class=\"wp-block-paragraph\">Though customers can initially snooze enrollment prompts indefinitely, organizations ought to set up inside deadlines and supply clear directions for passkey registration and restoration.<\/p>\n<p class=\"wp-block-paragraph\">Directors can quickly postpone computerized passkey enablement and registration campaigns between September 1, 2026, and February 1, 2027. <\/p>\n<p class=\"wp-block-paragraph\">Utilizing Microsoft Graph beta, directors with the <code>Coverage.ReadWrite.AuthenticationMethod<\/code> permission can set the <code>passkeyDynamicMigration<\/code> opt-out property to <code>true<\/code>. Nevertheless, that setting doesn&#8217;t delay the SMS and voice retirement deadline. <\/p>\n<p class=\"wp-block-paragraph\">Enterprises needing out-of-band telecom authentication should deploy a customer-managed supplier earlier than February 2027, whereas most organizations ought to prioritize passkeys, Home windows Good day, or different phishing-resistant strategies to keep away from consumer disruption.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><code><strong><strong><strong><strong><strong>Cease new phishing &amp; malware earlier than they compromise your corporation.\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn&amp;utm_medium=link+placement&amp;utm_campaign=stop+new+phishing&amp;utm_content=ti+feeds+sales&amp;utm_term=050826#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Combine dwell intel from 15K SOCs world wide<\/a><\/strong><\/strong><\/strong><\/strong><\/strong><\/code><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Microsoft will make passkeys the default authentication expertise in Entra ID starting September 1, 2026, and can absolutely retire its native SMS and voice multifactor authentication (MFA) supply companies on February 1, 2027. Based on Microsoft, the transition is a part of Microsoft\u2019s broader effort to remove phishable credentials as enterprises broaden cloud utilization, distant [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17790,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3369,2064,2032,618,10190,10191,1177,2571],"class_list":["post-17788","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-authentication","tag-default","tag-entra","tag-microsoft","tag-passkeys","tag-retires","tag-sms","tag-voice"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17788"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17788\/revisions"}],"predecessor-version":[{"id":17789,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17788\/revisions\/17789"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17790"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-16 09:54:59 UTC -->