Theregister Microsoft Phases Out SMS Authentication for Personal Accounts
Article Content
- •Microsoft is ending SMS authentication for personal accounts due to security vulnerabilities.
- •Users will transition to passwordless methods, including passkeys and verified email.
- •The UK’s National Cyber Security Centre has endorsed passkeys as a standard.
Microsoft has announced the discontinuation of SMS codes for personal account authentication and recovery, citing security vulnerabilities such as phishing and SIM-swap attacks. The company is transitioning to passwordless authentication methods, including passkeys and verified email, to enhance security and user experience. This change affects all personal Microsoft account users, aiming to reduce fraud risks associated with SMS-based methods. Users will be guided to create passkeys during the login process, which utilize biometrics or device PINs for secure access. The UK’s National Cyber Security Centre has endorsed passkeys as a standard, indicating a broader industry shift. Microsoft has been implementing passwordless accounts since 2025, making this announcement a formal confirmation of a trend already in progress. The exact timeline for the complete removal of SMS authentication has not been disclosed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical RCE Vulnerability in F5 BIG-IP APM Exploited in the Wild A severe heap-based buffer overflow vulnerability, tracked as CVE-2026-94127, has been identified in F5 BIG-IP Access Policy Manager (APM), allowing unauthenticated remote code execution (RCE) on the Traffic Management Microkernel (TMM) data plane. This vulnerability is triggered when both an APM access policy and an…