Passkeys have gained traction, yet their widespread adoption in enterprises has lagged due to various challenges. However, Microsoft's upcoming changes mean many organizations will soon be compelled to embrace this modern authentication method.
Beginning September 1, Microsoft will implement passkeys as the default authentication mechanism within its cloud identity and access management service, Entra ID. As part of a significant transition, the company plans to phase out SMS and voice-based authentication by February 1, 2027.
This initiative highlights the pressing need for stronger security measures as cyberattacks become increasingly sophisticated, especially with the integration of AI tools. Ensar Seker, Chief Information Security Officer at SOCRadar, characterizes this development as a pivotal milestone—transforming passwordless authentication from an optional enhancement to a critical standard. He notes, “That shift is significant as attackers increasingly rely on AI to automate phishing campaigns and conduct large-scale credential theft.”
Details of Microsoft's Passkey Roll-Out
Passkeys require users to verify identity through biometrics, such as fingerprints or facial recognition, or a device lock screen, rather than relying on traditional passwords. They can be stored on physical keys like YubiKey or within digital platforms, including computers and smartphones.
According to Microsoft, this method diminishes reliance on vulnerable SMS and voice authentication while enhancing defenses against credential theft. Nadim Abdo, Microsoft's corporate VP for identity and network access engineering, asserts that passkeys are advantageous because “they work better for users and worse for cyberattackers.”
Microsoft's timeline for this shift is aggressive:
- September 1, 2026: Users currently utilizing SMS or voice authentication will automatically be prompted to register a passkey during multifactor authentication (MFA) sign-in.
- September 18, 2026: Details regarding pricing and supported telecom providers for situations that still depend on SMS or voice due to regulations will be released.
- October 30, 2026: Organizations still using SMS and voice must select a telecom provider through the Microsoft Security Store and will be responsible for related costs moving forward.
- February 1, 2027: Microsoft will discontinue its provision of SMS and voice authentication as a native feature of Entra.
Post-February 1, enterprises that still require SMS or voice authentication for MFA will be mandated to have registered a passkey prior to sign-in, without any option to opt-out. It's crucial to note that these deadlines pertain specifically to public cloud-hosted Entra ID, while support for other deployment environments will follow a different schedule.
Abdo reflects on the evolution of MFA, acknowledging that while SMS and voice have been instrumental in broadening access for many, the current threat landscape—characterized by heightened speed and sophistication—necessitates this transition toward passkeys.
Understanding the Advantages of Passkeys
Seker underscores a fundamental shift in the attack surface due to passkeys: unlike passwords, which can be intercepted, passkeys require both possession of a user's device and biometric verification or a personal identification number. This dual requirement makes it challenging for cybercriminals for even the most sophisticated AI-generated phishing attempts to compromise the passkey system.
Despite this, a notable barrier has historically hindered adoption. The complexity of identity ecosystems can be daunting. Many enterprises still rely on legacy applications that only accommodate password-based systems, grappling with issues related to compatibility across platforms, lifecycle management, and user onboarding processes.
Seker also points out that organizations have traditionally viewed passkeys as more of a consumer play rather than a viable enterprise solution. With Microsoft’s decisive push, this perception is shifting; as Entra is integral to many organizations' identity infrastructures, mandating a move to passwordless authentication is likely to accelerate widespread deployment.
A significant reduction in credential-based attack vectors could be one of the most profound benefits of adopting passkeys, as Seker emphasizes. Credential theft—a leading method for breaches—often begins with stolen information sourced from phishing or malware. By removing passwords entirely from the equation, organizations can enhance their security posture while alleviating the stressors associated with password management.
However, it's important to remain vigilant: while passkeys offer robust enhancements to security, they don't address every vulnerability. Threats from malicious insiders, session token theft, and endpoint compromise are still concerns. Seker recommends that enterprises complement passkey adoption with comprehensive endpoint protection, continuous monitoring, and strict access control policies.
Preparing for the Transition
To facilitate the transition to passkeys, Microsoft advises organizations to reassess their authentication strategies and identify teams still using SMS or voice methods. It’s recommended that businesses select the most suitable authentication systems for their user devices and workflows, ensuring that all employees receive passkeys and security keys.
Entra ID accommodates both synced passkeys—those stored in platforms such as iCloud Keychain and Google Password Manager—and device-specific passkeys through applications like Microsoft Authenticator and FIDO2 security keys.
Seker suggests that organizations systematically review their support for FIDO2 and passkeys throughout their identity infrastructure. Clear enrollment and recovery protocols are essential, alongside educating users about the transition and functionality of passkeys. Secure device management practices and the enforcement of least privilege, conditional access, and risk-based authentication should be integral throughout this shift.
Seker concludes with a cautionary note: organizations relying on outdated password infrastructures may find themselves facing increased operational risks as attackers further leverage AI to refine credential-based attacks in the coming years.
This article originally appeared on Computerworld.