Microsoft mandates passkeys in Entra ID
Analysis based on 7 articles · First reported Jul 13, 2026 · Last updated Jul 16, 2026
The shift strengthens Microsoft's security posture and may reduce fraud-related costs for enterprises, but could increase short-term administrative burden. Third-party telecom providers may see new revenue streams from organizations retaining SMS/voice authentication.
Microsoft announced that passkeys will become the default authentication method in Microsoft Entra ID starting September 1, 2026. Users currently using SMS or voice for multifactor authentication will be automatically enabled for passkeys and prompted to register one. Microsoft will retire its native SMS and voice authentication delivery on February 1, 2027, after which organizations needing those methods must contract with third-party telecom providers via the Microsoft Security Store. The move responds to a surge in AI-enabled phishing campaigns, with United States — Google Threat Analysis Group reporting click-through rates as high as 54% for AI-powered attacks. Passkeys use public-key cryptography, making them phishing-resistant. The change builds on earlier passwordless initiatives and aligns with regulatory pressures like NIS2 in the EU. Microsoft's Corporate Vice President Nadim Abdo emphasized the need to evolve beyond phishable credentials. The UK's National Cyber Security Centre also urged passkey adoption. Jean Kaseya research indicated that 83% of phishing emails now use AI.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard