As cited
Copy frozen at (site build).
identity access
Risky Bulletin: Microsoft ends SMS MFA for personal accounts
Microsoft is discontinuing SMS-based multi-factor authentication for personal accounts, pushing users to adopt passkeys instead. The company cited SMS as a primary vector for account takeover and fraud. Users will be prompted to register passkeys upon their next login.
Why it matters: Personal Microsoft account holders must transition to passkey-based authentication to maintain account security and avoid friction during login. Security teams should track this shift as a model for reducing SMS-dependent authentication across their own organizations.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
identity access
Risky Bulletin: Microsoft ends SMS MFA for personal accounts
Microsoft is discontinuing SMS-based multi-factor authentication for personal accounts, pushing users to adopt passkeys instead. The company cited SMS as a primary vector for account takeover and fraud. Users will be prompted to register passkeys upon their next login.
Why it matters: Personal Microsoft account holders must transition to passkey-based authentication to maintain account security and avoid friction during login. Security teams should track this shift as a model for reducing SMS-dependent authentication across their own organizations.
- Source published
- First seen by Cybersecurity Tracker