Microsoft is making passkeys the default sign-in method in Entra ID. Starting September 1, 2026, the company will gradually introduce the change: users who have so far authenticated via SMS or voice call will then be automatically enabled for passkeys and prompted to register during their MFA login. Microsoft recommends that companies switch to passkeys or other phishing-resistant methods as early as possible.
Passkeys are cryptographic login keys that replace passwords. Instead of a password, users authenticate themselves, for example, via fingerprint, facial recognition, or device PIN. The technology is based on the FIDO2 and WebAuthn standards and is considered significantly more resistant to phishing. Entra ID – formerly Azure Active Directory – is Microsoft's cloud service for identity and access management.
In parallel, Microsoft is expanding support for device-bound and synchronized passkeys and enhancing management functions for administrators. This is intended to make passwordless logins easier to implement and control via policy.
The background, according to the company's statements , is the growing threat from AI-powered phishing attacks. According to Microsoft, such campaigns achieve click-through rates of up to 54 percent, while conventional phishing attacks are around 12 percent.
In the step, Microsoft will discontinue its own SMS and voice service for multi-factor authentication. From February 1, 2027, these methods will no longer be natively offered in Entra ID. Companies that continue to require them will have to integrate a third-party provider at their own expense via the Microsoft Security Store.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
