CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2441

As cited

Copy frozen at (site build).

cloud saas

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Microsoft Entra ID will make passkeys the default authentication method beginning September 1, 2026, automatically enrolling users currently using SMS or voice authentication. SMS and voice authentication will be retired as native Microsoft Entra capabilities on February 1, 2027, though organizations can continue using these methods through third-party telecom partners via the Microsoft Security Store at additional cost.

Why it matters: Identity and access practitioners must plan user migration to passkeys before September 2026 to avoid service disruptions and reduce phishing and credential theft risk, particularly as AI-enabled attacks grow more effective.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Microsoft Entra ID will make passkeys the default authentication method beginning September 1, 2026, with users currently on SMS or voice automatically enrolled. On February 1, 2027, Microsoft will retire its native SMS and voice delivery, though organizations can still use these methods through third-party telecom partners at additional cost.

Why it matters: Identity and access teams must plan passkey deployment now for all Entra ID users, as SMS and voice authentication will cease to be natively available in five months, and delayed preparation risks user friction during the transition.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Microsoft Entra ID will make passkeys the default authentication method beginning September 1, 2026, with users currently on SMS or voice automatically enrolled. On February 1, 2027, Microsoft will retire its native SMS and voice delivery, though organizations can still use these methods through third-party telecom partners at additional cost.

Why it matters: Identity and access teams must plan passkey deployment now for all Entra ID users, as SMS and voice authentication will cease to be natively available in five months, and delayed preparation risks user friction during the transition.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary