Snapshot from Aug 02, 2026 at 07:00 UTC. For live data and tracking: View Live
Tech security policy change

Microsoft mandates passkeys in Entra ID

Analysis based on 7 articles · First reported Jul 13, 2026 · Last updated Jul 16, 2026

Sentiment
15
Attention
3
Articles
7
Market Impact
General
Live prominence charts, article sentiment distribution, and event development timeline available on the Ergen Dashboard

The shift strengthens Microsoft's security posture and may reduce fraud-related costs for enterprises, but could increase short-term administrative burden. Third-party telecom providers may see new revenue streams from organizations retaining SMS/voice authentication.

cybersecurity cloud computing identity management

Microsoft announced that passkeys will become the default authentication method in Microsoft Entra ID starting September 1, 2026. Users currently using SMS or voice for multifactor authentication will be automatically enabled for passkeys and prompted to register one. Microsoft will retire its native SMS and voice authentication delivery on February 1, 2027, after which organizations needing those methods must contract with third-party telecom providers via the Microsoft Security Store. The move responds to a surge in AI-enabled phishing campaigns, with United States — Google Threat Analysis Group reporting click-through rates as high as 54% for AI-powered attacks. Passkeys use public-key cryptography, making them phishing-resistant. The change builds on earlier passwordless initiatives and aligns with regulatory pressures like NIS2 in the EU. Microsoft's Corporate Vice President Nadim Abdo emphasized the need to evolve beyond phishable credentials. The UK's National Cyber Security Centre also urged passkey adoption. Jean Kaseya research indicated that 83% of phishing emails now use AI.

70 Microsoft announced passkey default
50 United States — Google Threat Analysis Group observed AI phishing surge
stock
Microsoft is driving the policy change, enhancing its security reputation and potentially reducing support costs from phishing incidents. The move may also increase adoption of its Entra ID and related security products.
Importance 100.0 Sentiment 15.0
govactor
Provided data on AI phishing click-through rates that justified the policy change, reinforcing its role in informing Microsoft's security strategy.
Importance 40.0 Sentiment 0.0
per
As Corporate Vice President, he communicated the company's reasoning and timeline, representing Microsoft's leadership in identity security.
Importance 30.0 Sentiment 0.0
govactor
The NCSC's endorsement of passkeys adds regulatory weight to the industry shift, though it is not directly involved in Microsoft's decision.
Importance 20.0 Sentiment 0.0
per
As NCSC CTO, his public urging for passkey adoption supports the broader trend but has limited direct impact on Microsoft's specific rollout.
Importance 10.0 Sentiment 0.0
per
Jean Kaseya's research on AI phishing prevalence is cited as supporting context, but the company is not an active participant in the event.
Importance 10.0 Sentiment 0.0
ERGEN INTELLIGENCE
Track this event live

Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.

Open Dashboard

About Ergen

Ergen is a news intelligence platform that converts raw news articles into structured data. It tracks events, entities, and the relationships between them, with sentiment and attention metrics derived from thousands of articles. Pages on this site are daily static snapshots from the platform's live database. For real-time tracking, search, and alerts, the full dashboard is at app.ergen.ai.