Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Entra ID to Default to Passkeys, Retiring SMS and Voice MFA
August 15, 2026
AI Agents Persist, Rewrite Tools to Continue Attacks After Initial Malware Fails
August 14, 2026
Critical Citrix NetScaler Heap Overflow (CVE-2023-3519) Allows Remote Code Execution
August 14, 2026
Home/CyberSecurity News/Microsoft Entra ID to Default to Passkeys, Retiring SMS and Voice MFA
CyberSecurity News

Microsoft Entra ID to Default to Passkeys, Retiring SMS and Voice MFA

Key Takeaways Microsoft is transitioning Microsoft Entra ID to use passkeys as the default authentication method. SMS and voice-based multifactor authentication (MFA) provided by Microsoft will be...

Sarah simpson
Sarah simpson
August 15, 2026 3 Min Read
4 0

Key Takeaways

  • Microsoft is transitioning Microsoft Entra ID to use passkeys as the default authentication method.
  • SMS and voice-based multifactor authentication (MFA) provided by Microsoft will be retired, with a full cessation of native telecom delivery by February 1, 2027.
  • This change aims to enhance security by moving away from phishing-susceptible authentication methods.
  • Organizations must proactively migrate users to passkeys or other phishing-resistant MFA options to avoid service disruption.

Microsoft is making a significant shift in its authentication strategy for Microsoft Entra ID, designating passkeys as the new default sign-in experience. This move is part of a broader initiative to phase out authentication methods vulnerable to phishing, such as SMS and voice-based multifactor authentication (MFA).

Table Of Content

  • Key Takeaways
  • Phasing Out Vulnerable MFA Methods
  • Understanding Passkey Implementations
  • What You Should Do

Phasing Out Vulnerable MFA Methods

The company will discontinue its direct provision of SMS and voice authentication for MFA, steering organizations toward more robust, phishing-resistant credentials. This change will commence on September 1, 2026, when users currently configured for SMS or voice authentication will automatically have passkeys enabled for their accounts. During subsequent MFA sign-ins, these users will receive prompts encouraging them to register a passkey.

Microsoft will manage this passkey registration campaign by default, though users will have the option to defer the registration prompt during the transition period. The primary motivation behind this change is to mitigate the security risks associated with SMS and voice-based authentication, which are susceptible to various attack vectors including phishing kits, SIM swapping, social engineering, number porting, and interception.

In contrast, passkeys leverage cryptographic credentials tightly bound to a specific device or a secure credential manager. This design eliminates the need for a reusable shared secret that could be entered on a malicious website, thereby providing robust protection against phishing and replay attacks. Microsoft Entra ID supports both synced and device-bound passkeys.

Understanding Passkey Implementations

Synced passkeys offer flexibility, as they can be stored within credential managers like Apple’s iCloud Keychain or Google Password Manager, allowing users to access them across multiple devices. Device-bound passkeys, on the other hand, remain resident on a single device. Examples include Windows Hello for Business, Microsoft Authenticator passkeys, Entra Passkey on Windows, and FIDO2 hardware security keys.

A critical deadline for this transition is February 1, 2027. By this date, Microsoft will fully retire its native telecom delivery services for SMS and voice MFA within Entra ID. Organizations that still require these channels post-retirement will need to engage a customer-managed telecom provider, which can be sourced through the Microsoft Security Store. Microsoft plans to publish information regarding available providers starting September 18, 2026, with customer selection and configuration expected to be possible from October 30, 2026.

After the February 2027 retirement date, any user whose sole MFA option remains SMS or voice will encounter a mandatory passkey registration prompt during sign-in. Account access will be blocked until a passkey is successfully registered. Microsoft has confirmed there will be no opt-out from this enforcement, underscoring the importance of early migration to prevent disruptions to account access.

What You Should Do

  • Identify Affected Users: Administrators should immediately identify users within their organization who are still relying on SMS or voice authentication. Microsoft provides a PowerShell-based analyzer tool to assist in locating these users via the Entra Authentication Methods Policy or legacy MFA configurations.
  • Enable Passkey (FIDO2): Activate Passkey (FIDO2) as an available authentication method within your Entra ID tenant.
  • Create Targeted User Groups: Organize users into groups to facilitate a phased rollout and registration campaign for passkeys.
  • Launch Staged Registration: Initiate a proactive, staged passkey registration campaign for users before the automatic enablement phase begins on September 1, 2026.
  • Consider Temporary Opt-Out (with caution): While Microsoft offers a temporary opt-out for the automatic passkey enablement phase (September 1, 2026, to February 1, 2027) via Microsoft Graph’s passkeyDynamicMigration property, this merely delays the inevitable. It does not circumvent the February 2027 retirement or the mandatory registration requirement. Use this only if absolutely necessary for short-term operational continuity.
  • Prioritize Phishing-Resistant Methods: Treat SMS and voice MFA as legacy fallback options, not long-term security controls. Prioritize the deployment of passkeys, Windows Hello for Business, and FIDO2 security keys. Customer-managed telecom services for SMS/voice should be reserved for specific regulatory or operational needs only.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

AI Agents Persist, Rewrite Tools to Continue Attacks After Initial Malware Fails

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Dysphoria Botnet Hijacks Routers, Cameras for DDoS Attacks and C2 Relays
August 14, 2026
DCRat Malware Campaign Uses HTML Smuggling in SVG Files
August 14, 2026
Malware Crypter Services Offer Windows Defender, EDR, SmartScreen Bypasses
August 14, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us