- Beginning September 1, 2026, passkeys will become the default for Entra ID
- Microsoft is retiring SMS/phone call authentication from February 1, 2027
- Victims are more likely to open AI-assisted phishing emails
Microsoft has confirmed plans to make passkeys the default or preferred authentication method for Entra ID beginning September 1, 2026, announcing further changes to account authentication in a bid to combat sophisticated attacks.
A few months later from February 1, 2027, the company will also stop providing its own SMS and voice call authentication codes for Entra ID in the hope that business users fully adopt passwordless sign-in.
While passkeys don’t promise to totally stop attacks, they make phishing attempts far less effective because attackers would need access to victims’ hardware to gain access.
Microsoft continues its drive for passkeys
While the company may be ending support for its own SMS and phone call authentication methods, passkeys won’t be the only sign-in method after the change. Windows Hello for Business (biometrics) and FIDO2 security keys will still be available, for example.
“The AI era demands stronger, phishing-resistant authentication,” a company notice seen by Windows Latest reads. “We are making passkeys the default authentication experience in Microsoft Entra to help customers securely adopt AI at scale.”
Though AI hasn’t exactly made attacks better at breaking through traditional authentication methods, it has made attacks more convincing. According to the company’s own information, the click-through rate for phishing emails stands at 54% for AI-assisted campaigns, compared with just 12% for conventional ones.
With more people opening up malicious links, the effects are compounded, hence the push to improve general security.
Looking ahead, Microsoft’s suggested plan for impacted organizations includes identifying users who still use SMS/voice authentication, planning a company-wide passkey rollout and keeping workers up-to-date.
“SMS and voice have served their purpose well, bringing multifactor authentication to billions of users who otherwise would have had none,” Microsoft concluded, declaring that “the threat environment has evolved beyond their capabilities.”
