Microsoft is making Passkeys the default for Entra ID – what it means for your business
- saramilne
- Jul 28
- 3 min read
Passwords have long been one of the weakest links in cybersecurity. Despite years of awareness campaigns and increasingly complex password policies, compromised credentials remain one of the most common ways attackers gain access to business systems.
That's why Microsoft is continuing its move towards a passwordless future.
From 1 September 2026, Microsoft will begin making Passkeys the default authentication method for Microsoft Entra ID. As part of this transition, users who currently verify their identity using SMS or voice authentication will be prompted to register a Passkey the next time they complete multi-factor authentication (MFA).
The move is another significant milestone in Microsoft's drive to improve account security while making authentication faster and easier for users.
Why is Microsoft moving away from SMS authentication?
Traditional MFA methods, such as text messages and phone calls, have provided an important layer of security for many years. However, they are increasingly vulnerable to modern attacks, including phishing, SIM swapping and social engineering.
Passkeys offer a far more secure alternative.
Rather than relying on passwords or one-time codes, Passkeys use public key cryptography and the security built into your device. Users simply verify their identity using a fingerprint, facial recognition or device PIN, making the sign-in process both simpler and significantly more resistant to credential theft.
Because the authentication key never leaves the user's device, Passkeys can dramatically reduce the risk of phishing attacks and stolen credentials.
Key dates to know
Microsoft has confirmed two important milestones:
1 September 2026 – Passkeys become the default authentication method for Microsoft Entra ID. Users relying on SMS or voice authentication will begin receiving prompts to register a Passkey.
1 February 2027 – Microsoft will retire its built-in SMS and voice authentication services for Microsoft Entra ID. Organisations that wish to continue using these methods will need to integrate with a third-party telecommunications provider, which may introduce additional costs.
Microsoft is encouraging organisations to begin adopting Passkeys or another phishing-resistant authentication method well ahead of these deadlines.
What does this mean for organisations?
Although there is no immediate action required, organisations should begin preparing now.
Reviewing existing MFA policies, ensuring employees have suitable authentication methods available and planning a phased rollout of Passkeys can help avoid disruption as Microsoft's changes take effect.
For many businesses, this also presents an opportunity to modernise their identity security strategy and reduce reliance on legacy authentication methods that are becoming less effective against today's cyber threats.
The benefits of Passkeys
Moving to Passkeys isn't just about meeting Microsoft's requirements - it also delivers tangible security and usability benefits.
Some of the key advantages include:
Strong protection against phishing and credential theft.
Faster, passwordless sign-ins.
Improved user experience with biometric authentication or device PINs.
Reduced reliance on passwords and one-time verification codes.
Better alignment with Microsoft's long-term passwordless strategy.
Preparing for the transition
If your organisation uses Microsoft Entra ID, now is a good time to review your authentication strategy.
Employees will begin seeing genuine Microsoft prompts to register a Passkey as the rollout progresses, so it's important they're aware of the change and understand why they're being asked to register.
Ensuring the Microsoft Authenticator app is deployed where required, providing user guidance and communicating the benefits of Passkeys can help make the transition smooth and minimise support requests.
Stay informed
Changes like these highlight how quickly the cybersecurity landscape continues to change. Keeping up with the latest guidance from Microsoft and other technology providers can help organisations make informed decisions about their security strategy and avoid last-minute changes when new requirements come into effect.
We'll continue to share updates and insights on the latest developments in cybersecurity, cloud services and modern workplace technology as they emerge.




Comments