Passkeys Are the Default Authentication Method in Entra ID
Microsoft, Monday, July 13th, 2026
Microsoft is making passkeys the default in Entra ID and will retire native SMS and voice authentication on February 1, 2027.
Microsoft is making passkeys the default authentication method in Entra ID in response to increasingly sophisticated identity attacks.
Starting September 1, 2026, users relying on SMS or voice authentication will be automatically enabled for passkeys and prompted to register at their next multifactor authentication.
Microsoft will retire native SMS and voice delivery on February 1, 2027, after which organizations needing those channels must use third-party telecom providers via the Microsoft Security Store at their own cost.
The post argues passkeys use public-key cryptography rather than shared secrets, making them phishing-resistant by design, and cites AI-enabled phishing reaching click-through rates as high as 54% versus roughly 12% for traditional campaigns.