Microsoft Entra ID Is Making Passkeys the Default

Microsoft Entra ID Is Making Passkeys the Default

Microsoft Entra ID Is Making Passkeys the Default: What Security Teams Need to Know

For years, multifactor authentication (MFA) has been sold as the antidote to weak passwords.

But not all MFA is created equal and Microsoft just signaled, in the clearest terms yet, that the SMS and voice codes millions of organisations still lean on are no longer good enough.

Starting September 1, 2026, passkeys will become the default authentication experience across Microsoft Entra ID, Microsoft’s cloud identity and access management platform.

It’s one of the most consequential identity security changes Microsoft has rolled out in years, and IT and security teams should start planning now.

Why Now? Blame the Robots

Microsoft’s reasoning comes down to one uncomfortable trend: phishing has gotten dramatically better at fooling people, largely thanks to AI. According to Microsoft’s own threat intelligence, AI-enabled phishing campaigns are now hitting click-through rates as high as 54%, compared to roughly 12% for more traditional phishing attempts.

That’s not a marginal improvement for attackers, — it’s a different category of threat.

SMS and voice-based MFA, while better than passwords alone, were never designed to withstand this level of sophistication.

They’re vulnerable to SIM swapping, real-time phishing proxies, and social engineering tactics that can trick users into handing over a one-time code within seconds of receiving it. Attackers have taken notice: groups like ShinyHunters have been actively targeting Entra ID single sign-on accounts in recent waves of SaaS data-theft campaigns built around stolen credentials and phishable second factors.

Passkeys close that gap. Built on public-key cryptography rather than shared secrets, a passkey can’t be phished, intercepted, or reused the way a code can — there’s no six-digit number for an attacker to trick someone into typing into a fake login page. Microsoft says it has already achieved phishing-resistant authentication across more than 99% of its own internal users and devices by eliminating legacy methods, and now it’s pushing the rest of its customer base to follow.

What’s Actually Changing

This isn’t a feature release buried in a changelog — it’s a default behavior change that will touch nearly every Entra ID tenant. Here’s the rollout as Microsoft has laid it out:

September 1, 2026 — Passkeys become the default authentication experience in Entra ID. As the rollout reaches each tenant, any user currently enabled for SMS or voice authentication will be automatically enabled for passkeys as well. The next time that user completes an MFA challenge, they’ll see a prompt to register a passkey. Microsoft’s registration campaign feature will be set to “Microsoft-managed,” meaning this rollout happens largely on its own unless admins intervene.

September 18, 2026 — Microsoft will publish details on supported third-party telecom providers, along with pricing, commercial terms, and deployment guidance through the Microsoft Security Store, for organizations that need to keep SMS or voice authentication running.

October 30, 2026 — Admins who need to retain telephony-based MFA (for regulatory, technical, or business reasons) can begin selecting and configuring a supported telecom provider through the Microsoft Security Store.

February 1, 2027 — This is the hard cutoff. Microsoft-provided SMS and voice authentication will be fully retired. Native telecom delivery goes away entirely; from this point forward, SMS and voice MFA will only function if an organization has configured a third-party telecom provider. Users whose only MFA method is SMS or voice will be blocked from signing in until they register a passkey.

Notably, a temporary opt-out will be available during the transition window, letting organizations delay enforcement while they sort out their migration plan — but that flexibility disappears once the February 2027 deadline hits.

It’s also worth noting these dates apply specifically to Entra ID in the public cloud. Government and other sovereign cloud environments will follow on a separate, still-unannounced timeline.

Which Passkeys Does Entra ID Support?

Organizations aren’t locked into a single passkey format. Entra ID supports:

  • Synced (cloud-based) passkeys — stored in platform credential managers like iCloud Keychain or Google Password Manager, and synced across a user’s devices.
  • Device-bound passkeys — including Microsoft Authenticator passkeys, Entra passkeys on Windows, and FIDO2 security keys, which stay tied to a specific piece of hardware.

The right mix depends on your environment. Regulated industries or high-security roles may lean toward device-bound options, while general knowledge workers might get more value from the convenience of synced passkeys across their phone and laptop.

What Security and IT Teams Should Do Right Now

Microsoft has been direct in urging organizations not to simply wait for the automatic rollout to hit. Recommended steps include:

  1. Audit current authentication methods. Identify exactly which users and groups are still relying on SMS or voice MFA — this is your at-risk population once the retirement date arrives.
  2. Enable and configure passkey support now, deciding between synced and device-bound passkeys based on the devices your workforce actually uses.
  3. Use Entra ID’s registration campaign feature to proactively drive adoption during MFA sign-in, rather than leaving it entirely to Microsoft’s managed rollout.
  4. Communicate early and often. Tell users what’s changing, when they’ll see a registration prompt, and how to complete it — a surprise blocking prompt during sign-in is a recipe for help desk tickets.
  5. If you have a genuine need to keep SMS or voice (compliance requirements, specific regional constraints, legacy systems), start evaluating third-party telecom providers through the Microsoft Security Store as soon as details are published, and pilot the configuration with a small group before rolling it out broadly.

Microsoft recommends having any telecom provider fallback fully configured at least four weeks ahead of the February 2027 enforcement date, to leave room for testing.

The Bigger Picture

This move builds on a broader passwordless push Microsoft has been making throughout 2026 — including making passkey profiles the default sign-in configuration for enterprise tenants back in March, and expanding system-preferred authentication to cover first-factor sign-in globally in May. Taken together, the direction is unmistakable: Microsoft is trying to engineer phishable credentials out of the picture entirely, not just add more layers on top of them.

For organisations, the practical implication is that “passkeys later” is no longer really an option — Entra ID is moving there by default whether or not you’ve built a formal rollout plan. The good news is that Microsoft is giving a long runway and clear milestones, and moving to passkeys costs nothing extra unless you specifically need to preserve SMS or voice. The smart move is to treat September 2026 as a deadline for having your own migration underway, not as the day you start thinking about it.

 

Related Posts