{
  "id": 1264767,
  "title": "Microsoft shifts Entra ID towards passkey-first authentication",
  "url": "https://urgent.news/2026/08/16/microsoft-shifts-entra-id-towards-passkey-first-authentication",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-16T11:40:44.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/microsoft-shifts-entra-id-towards-passkey-first-authentication/"
  },
  "original_language": "en",
  "account": "Microsoft is set to make passkeys the default authentication method in Entra ID from September 1, 2026, before phasing out SMS and voice authentication by February 1, 2027. This shift impacts organizations whose employees still use text messages or phone calls for multi-factor authentication (MFA). When Microsoft's rollout reaches individual organizations, users with existing SMS or voice authentication options will automatically become eligible for passkeys and be prompted to register one during their next MFA challenge. However, Microsoft will no longer provide native telecom delivery for SMS and voice authentication after February 1, 2027. Organizations retaining these methods due to operational, regulatory, or accessibility reasons will need to use customer-managed telecom providers available through the Microsoft Security Store. Microsoft's migration plan includes providing further details on customer-managed telecommunications options in September 18, giving administrators ample time to identify affected accounts, evaluate alternatives, and revise authentication policies before the native service is withdrawn. Passkeys employ public-key cryptography, offering enhanced security against phishing compared to traditional passwords or MFA methods. While SMS and voice authentication are safer than passwords, attackers have developed increasingly effective techniques to defeat them, including SIM swapping, social engineering, interception of messages, and AI-assisted phishing campaigns. Microsoft has observed higher interaction rates for AI-assisted phishing compared to conventional campaigns, emphasizing the need for authentication mechanisms that do not rely on user recognition of fraudulent prompts or websites. The Entra ID change is part of a broader industry trend towards passwordless authentication, with Apple, Google, and Microsoft promoting passkeys through FIDO2 and WebAuthn standards. Microsoft has already been expanding passkey deployment across its consumer and enterprise products, with new Microsoft consumer accounts becoming passwordless by default in 2025, and Entra administrators gaining additional tools to encourage workforce users to register passkeys. However, migrating to passkeys requires more than just enabling a new authentication button; administrators must identify users dependent on SMS and voice, ensure compatible devices are available, establish account-recovery procedures, and address situations involving shared devices, contractors, or employees who cannot use biometric authentication. Passkeys do not transmit biometric information to Microsoft; instead, fingerprint or facial recognition occurs locally on the user’s device, unlocking the cryptographic credential. Organizations can also continue using Windows Hello for Business and FIDO2-compatible hardware security keys alongside passkeys, tailoring authentication policies based on workforce and security requirements.",
  "summary": "Microsoft is preparing a major change to enterprise identity security, making passkeys the default authentication experience in Entra ID from September 1, 2026, before ending its own SMS and voice authentication delivery services on February 1, 2027. The shift will affect organisations whose employees still rely on text messages or telephone calls for multifactor authentication. As Microsoft’s…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}