Microsoft transitions Entra ID to passkey authentication

By Joshua Gliddon on Jul 22, 2026 10:37AM
Microsoft transitions Entra ID to passkey authentication

Beginning September 1, 2026, Microsoft will begin rolling out passkeys as the default authentication experience in Microsoft Entra ID.

As the rollout reaches each organisation, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey.

Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability.

Organisations that still require SMS or voice authentication methods due to regulatory, technical, or business requirement will have the option to select, configure, and manage a third-party telecom provider through the Microsoft Security Store, a partner marketplace where customers can contract directly with supported carriers. 

Customers will be responsible for any associated telecom-related costs charged by those telecom partners, however.

Shifting to passkeys for Entra ID is free, with Microsoft set to issue documentation on September 18 providing guidance for customers who remain on SMS and voice verification.

As justification for the change, Microsoft stated that authentication methods that use SMS or voice rely on shared secrets or channels that attackers increasingly intercept, phish, or manipulate, whereas passkeys use public-key cryptography rather than shared secrets, making them "phishing-resistant" by design.

They also provide a faster, simpler sign-in experience for users, Microsoft claimed.

"An AI-powered cyberattack can use a compromised identity to automate discovery, privilege escalation, and lateral movement much faster than a human attacker working manually. This is why phishing-resistant authentication methods are so important," said Nadim Abdo, CVP of identity and network access engineering for Microsoft, said in a blog post announcing the news.

"By making passkeys the default authentication experience, organizations reduce reliance on phishable authentication methods and strengthen protection against credential theft and phishing."

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?