In a significant move to bolster account security and reduce reliance on vulnerable authentication methods, Microsoft has announced that passkeys will become the default authentication method for its Entra ID enterprise identity service starting September this year. This change is expected to impact millions of users worldwide who currently rely on phone-based SMS and voice authentication.
As part of this shift, users who are still using these legacy methods will be automatically enrolled in passkey registration when they next perform multifactor authentication. Those who have already adopted more secure methods, such as Windows Hello for Business or FIDO2 security keys, will be able to continue using their preferred approach without interruption. However, organizations that rely on phone-based authentication should take immediate action to ensure all users are transitioning to a phishing-resistant method.
To facilitate this transition, Microsoft has provided guidance on deploying and managing passkeys through its Entra ID documentation page. Administrators can also use the Entra SMS/Voice Policy Scanner PowerShell script to identify users still relying on SMS or voice authentication. For organizations that cannot switch immediately, Microsoft recommends configuring third-party telecom providers through the Microsoft Security Store.
The shift towards passkeys is a response to growing concerns about identity attacks and credential theft. Recent SaaS data-theft attacks have targeted Entra single sign-on (SSO) accounts with stolen credentials. According to Microsoft Threat Intelligence, AI-enabled phishing campaigns are achieving click-through rates as high as 54%, compared to around 12% for traditional campaigns. By making passkeys the default authentication experience, organizations can reduce reliance on vulnerable methods and strengthen their defenses against phishing and credential theft.
While this change is a positive step forward in improving account security, it’s essential for users to understand that no single solution can guarantee complete protection. A layered approach to security remains crucial in today’s threat landscape. To stay ahead of potential attacks, organizations should regularly test their security controls and ensure they are prepared to respond quickly in the event of an incident.
In conclusion, Microsoft’s decision to default to passkeys for Entra ID authentication marks a significant milestone in the quest for more secure account management. As users and administrators transition to this new method, it’s essential to remember that ongoing vigilance and testing remain critical components of a robust security posture.
Source: Bleeping Computer — 2026-07-14