Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Craig Hale

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses

Microsoft passkey.
  • Beginning September 1, 2026, passkeys will become the default for Entra ID
  • Microsoft is retiring SMS/phone call authentication from February 1, 2027
  • Victims are more likely to open AI-assisted phishing emails

Microsoft has confirmed plans to make passkeys the default or preferred authentication method for Entra ID beginning September 1, 2026, announcing further changes to account authentication in a bid to combat sophisticated attacks.

A few months later from February 1, 2027, the company will also stop providing its own SMS and voice call authentication codes for Entra ID in the hope that business users fully adopt passwordless sign-in.

While passkeys don't promise to totally stop attacks, they make phishing attempts far less effective because attackers would need access to victims' hardware to gain access.

Microsoft continues its drive for passkeys

While the company may be ending support for its own SMS and phone call authentication methods, passkeys won't be the only sign-in method after the change. Windows Hello for Business (biometrics) and FIDO2 security keys will still be available, for example.

"The AI era demands stronger, phishing-resistant authentication," a company notice seen by Windows Latest reads. "We are making passkeys the default authentication experience in Microsoft Entra to help customers securely adopt AI at scale."

Though AI hasn't exactly made attacks better at breaking through traditional authentication methods, it has made attacks more convincing. According to the company's own information, the click-through rate for phishing emails stands at 54% for AI-assisted campaigns, compared with just 12% for conventional ones.

With more people opening up malicious links, the effects are compounded, hence the push to improve general security.

Looking ahead, Microsoft's suggested plan for impacted organizations includes identifying users who still use SMS/voice authentication, planning a company-wide passkey rollout and keeping workers up-to-date.

"SMS and voice have served their purpose well, bringing multifactor authentication to billions of users who otherwise would have had none," Microsoft concluded, declaring that "the threat environment has evolved beyond their capabilities."

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.