Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods.
The company will also retire Microsoft-provided SMS and voice authentication for multifactor authentication, pushing organizations toward phishing-resistant credentials.
Beginning September 1, 2026, users currently enabled for SMS or voice authentication will be automatically enabled for passkeys. During a future MFA sign-in, these users will see prompts encouraging them to register a passkey.
Microsoft will manage the passkey registration campaign by default. However, users can repeatedly postpone the registration prompt during the transition period. The change is designed to reduce risks associated with SMS and voice-based authentication.
Attackers can target these methods through phishing kits, SIM swapping, social engineering, number porting, and interception. Passkeys instead use cryptographic credentials tied to a device or credential manager.
Because there is no reusable shared secret to enter on a fake website, passkeys are intended to resist phishing and replay attacks. Microsoft Entra ID supports synced and device-bound passkeys.
Microsoft Passkeys Default in Entra ID
Synced passkeys can be stored in credential managers such as iCloud Keychain or Google Password Manager and used across a user’s devices.
Device-bound passkeys remain on a specific device and can include Windows Hello for Business, Microsoft Authenticator passkeys, Entra Passkey on Windows, and FIDO2 hardware security keys.
The next major deadline is February 1, 2027. On that date, Microsoft will fully retire its native telecom delivery for SMS and voice in Entra ID.
Organizations that continue relying on these channels must use a customer-managed telecom provider available through the Microsoft Security Store.
Microsoft plans to publish provider information from September 18, 2026, while customers are expected to be able to select and configure providers from October 30, 2026.
After the retirement date, users whose only MFA option is SMS or voice will face a blocking passkey registration prompt during sign-in. They will have to register a passkey before accessing their account.
Microsoft says there will be no opt-out from this enforcement, making early migration essential to avoid account access disruptions.
Administrators should first identify users who are still enabled for SMS or voice in the Entra Authentication Methods Policy or in legacy MFA configurations. Microsoft provides a PowerShell-based analyzer to help organizations find affected users.
Security teams should then enable Passkey (FIDO2), create targeted user groups, and launch a staged registration campaign before the automatic migration.
Microsoft is also offering a temporary opt-out for the automatic passkey enablement phase between September 1, 2026, and February 1, 2027. Administrators can use Microsoft Graph to set the passkeyDynamicMigration property in the authentication methods policy.
However, this setting only delays the transition. It does not prevent the February 2027 retirement and mandatory passkey registration requirement.
For enterprises, the announcement means that SMS and voice MFA should now be treated as legacy fallback options rather than long-term authentication controls.
Organizations should prioritize passkeys, Windows Hello for Business, and FIDO2 security keys, while reserving customer-managed telecom services only for limited regulatory or operational requirements.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication appeared first on Cyber Security News.


