CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 185

As cited

Copy frozen at (site build).

identity access

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Microsoft is discontinuing SMS-based multi-factor authentication for personal accounts, pushing users to adopt passkeys instead. The company cited SMS as a primary vector for account takeover and fraud. Users will be prompted to register passkeys upon their next login.

Why it matters: Personal Microsoft account holders must transition to passkey-based authentication to maintain account security and avoid friction during login. Security teams should track this shift as a model for reducing SMS-dependent authentication across their own organizations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Microsoft is discontinuing SMS-based multi-factor authentication for personal accounts, pushing users to adopt passkeys instead. The company cited SMS as a primary vector for account takeover and fraud. Users will be prompted to register passkeys upon their next login.

Why it matters: Personal Microsoft account holders must transition to passkey-based authentication to maintain account security and avoid friction during login. Security teams should track this shift as a model for reducing SMS-dependent authentication across their own organizations.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary