Microsoft Entra ID gets passkeys default authentication starting September

A major shift in authentication methods is underway at Microsoft, with passkeys set to become the default for Entra ID users starting September 2026. This move aims to strengthen security and reduce reliance on vulnerable phone-based authentication methods that have been exploited by threat actors.

For those who may not be familiar, passkeys are a type of authentication that uses public-key cryptography to secure user identities without relying on passwords or other phishable factors. Microsoft’s decision to adopt passkeys as the default comes in response to growing concerns about the security risks associated with traditional authentication methods like SMS and voice-based verification.

As part of this transition, Entra ID users who currently rely on phone-based SMS and voice authentication will be automatically enabled for passkeys by September 2026. However, those who have already adopted phishing-resistant methods such as Windows Hello for Business, FIDO2 security keys, or smart cards will be able to continue using their preferred method.

While Microsoft is taking steps to retire its own telecom delivery service for SMS and voice authentication in February 2027, organizations are advised to ensure that all users are making the switch to a more secure authentication method. This can be done by running a PowerShell script provided by Microsoft or by configuring third-party telecom providers through the Microsoft Security Store.

The shift towards passkeys is not just a technical update – it’s also a response to the growing threat landscape. According to Microsoft, threat actors have heavily targeted Entra single sign-on (SSO) accounts in recent SaaS data-theft attacks using stolen credentials. By making passkeys the default authentication experience, organizations can significantly reduce their reliance on phishable authentication methods and strengthen protection against credential theft and phishing.

As with any major change to an organization’s security posture, it’s essential for administrators to plan ahead and ensure a smooth transition. Microsoft provides detailed guidance on deploying and managing Entra ID phishing-resistant passwordless authentication, which can be found on its dedicated documentation page.

In the face of increasingly sophisticated threats, it’s more crucial than ever that organizations prioritize robust security measures. By adopting passkeys as the default authentication method, Entra ID users will not only improve their account security but also stay ahead of the curve when it comes to protecting against identity attacks.


Source: Bleeping Computer — 2026-07-14