$ techbeacon
Phishing

Microsoft Entra ID to Phase Out SMS and Voice MFA in Major Shift Toward Passkeys

Microsoft Entra ID to Phase Out SMS and Voice MFA in Major Shift Toward Passkeys

Microsoft is set to fundamentally change how enterprise users secure their digital identities by making passkeys the default authentication method in Microsoft Entra ID. The tech giant announced that this transition will begin on September 1, 2026, marking a significant step toward a passwordless future for corporate environments.

Following the shift to passkeys as the standard experience, Microsoft plans to fully retire its native SMS and voice-based multi-factor authentication (MFA) delivery services on February 1, 2027. This timeline provides organizations with a window of roughly two years to adapt their security architectures and transition their workforces away from legacy verification methods.

The decision to phase out telephone-based authentication stems from the inherent security vulnerabilities of SMS and voice protocols. While phone-based MFA was once considered a reliable layer of defense, modern cyber threats have exposed its weaknesses. Attackers frequently bypass these systems using sophisticated techniques such as SIM swapping, social engineering, and telephony interception, making SMS and voice codes increasingly unreliable for securing sensitive corporate data.

Passkeys, by contrast, offer a robust and phishing-resistant alternative. Built on FIDO2 and WebAuthn standards, passkeys utilize cryptographic key pairs that are bound to a specific device and service. Because they require local user verification—such as biometric scans or device PINs—and do not transmit credentials over the network, they are virtually immune to the credential harvesting and remote attacks that plague traditional passwords and SMS codes.

For IT administrators managing Microsoft Entra ID—the cloud-based identity and access management service formerly known as Azure Active Directory—the upcoming changes will require proactive planning. Organizations will need to assess device compatibility, update security policies, and guide employees through the registration of physical security keys or platform-based passkeys before the 2027 cutoff.

This strategic shift by Microsoft aligns with a broader industry-wide movement toward passwordless standards, supported by major technology providers and the FIDO Alliance. By eliminating legacy MFA channels, the industry aims to establish a more resilient baseline of defense against the evolving landscape of global cyber threats.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related