Observed Signal · Jul 15, 2026 · Policy Update · Source: t3n · Impact: 4/5 · Sentiment: Positive
Microsoft makes Passkeys default in Entra ID
Microsoft announced that passkeys will become the default authentication method in its Entra ID identity system starting September 1, 2026. Users who currently rely on SMS or voice call codes for multi-factor authentication (MFA) will be required to switch; Microsoft will continue to support SMS and voice codes only for companies that explicitly request it until February 2027. The change will be rolled out gradually, prompting affected users to register passkeys at their next MFA sign-in. Microsoft is also expanding support for device-bound and synchronized passkeys and adding administrative management controls. The company cited rising success rates of AI-powered phishing (reported up to 54% click rates versus ~12% for conventional phishing) as a key reason for the shift. Passkeys are based on FIDO2 and WebAuthn standards and replace passwords with cryptographic credentials tied to biometric or PIN-based device authentication.
A major platform (Microsoft) changing default authentication to passkeys affects enterprise identity, reduces phishing/account-takeover risk, and impacts identity/SSO strategies used across MarTech and AdTech ecosystems.
Track Microsoft Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Microsoft will make passkeys the default authentication method in Entra ID from 2026-09-01.
- SMS and voice-code MFA methods will be deprecated; they remain optionally supported for companies until February 2027.
- Affected users will be prompted to register passkeys on their next MFA sign-in as the change is rolled out.
- Microsoft is expanding support for device-bound and synchronized passkeys and adding administrative management functions.
- Microsoft cited AI-driven phishing campaigns with click rates up to 54% (versus ~12% for traditional phishing) as motivation for the change.
Connected Companies & Entities
3 Entities mapped“Microsoft announced changes to sign-in within its Entra ID system, making passkeys the default authentication method and deprecating SMS and...”
“The article notes that external content from TargetVideo GmbH supplements t3n's editorial offering and may be displayed on the site....”
“t3n is the publisher of the article (appears as 't3n – digital pioneers' in the site header)....”
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Microsoft warns against SMS-based 2FA over AI phishing
Microsoft has warned IT administrators that SMS- and voice-based two-factor authentication (2FA) are increasingly vulnerable due to AI-assisted phishing and easier SIM-swapping. In an internal email, the company recommended migrating to phishing-resistant methods such as passkeys. Microsoft said it has observed a strong rise in AI-driven attacks with higher click-through rates that aim to capture passwords and MFA codes. As a consequence, Microsoft will disable SMS- and voice-based authentication for Entra ID accounts starting February 1, 2027; a timeline for personal Microsoft accounts has not yet been announced.
Passkeys Explained Simply
This explainer describes passkeys — a passwordless authentication method built on asymmetric cryptography (public/private key pairs) and standardized by WebAuthn and FIDO2. Private keys remain on the user device (Secure Enclave, TPM, or hardware tokens like YubiKey), while servers store only public keys; authentication uses signed challenges, making passkeys resistant to phishing and server-side credential leaks. Major platform vendors (Apple, Google, Microsoft) now support passkey synchronization (iCloud Keychain, Google Account/Password Manager, Windows Hello) to aid device recovery. Many consumer services already offer passkeys (Google, Apple, GitHub, Microsoft, PayPal, Amazon, X). The article notes standards bodies (W3C, FIDO Alliance) and mentions implementation helpers and libraries used by developers.
Decision Guide: Should Your App Adopt Passkeys?
This technical decision guide explains how product, engineering, and security teams should evaluate whether to adopt passkeys for user authentication. It defines passkeys, passwords, and MFA; describes what passkeys protect (phishing and credential-stuffing) and what they don't (stolen session tokens, device malware, coercion, insider threats); and provides a 10‑item readiness checklist (scored 0–2, weighted) plus clear show‑stoppers (notably recovery and enterprise SSO). The article recommends piloting passkeys with narrow cohorts, keeping password fallbacks, measuring registration/sign‑in success and support metrics, and using a one‑page template to present a recommendation to leadership.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
