Microsoft to Make Passkeys Default for Enterprise Identity by September 2026
AI-generated from multiple sources. Verify before acting on this reporting.
REDMOND, Wash. — Microsoft announced on Monday that it will make passkeys the default authentication method for its Entra ID enterprise identity service starting in September 2026. The technology giant simultaneously confirmed plans to retire SMS and voice-based two-factor authentication by February 2027.
The strategic shift aims to reduce reliance on phishable authentication methods, which remain a primary vector for credential theft and targeted attacks against Microsoft Entra single sign-on accounts. By mandating passkeys as the standard, Microsoft intends to strengthen protection mechanisms across its enterprise ecosystem, moving organizations away from traditional passwords that are susceptible to interception.
Passkeys utilize public-key cryptography to verify user identity without requiring users to remember or type complex credentials. Unlike SMS codes sent via text message or voice calls, which can be intercepted through SIM-swapping attacks or social engineering, passkeys rely on biometric data such as fingerprints or facial recognition stored securely within a device.
Under the new timeline, Microsoft will begin transitioning its enterprise customers over an 18-month period. Starting in September 2026, any new user accounts created for Entra ID services will default to passkey authentication. Existing users will be prompted to adopt the technology during their next sign-in or through administrative configuration updates.
The retirement of SMS and voice authentication is scheduled for February 2027. Once this deadline passes, these legacy methods will no longer function as a secondary verification step within the Entra ID framework. Organizations that have not transitioned by that date may face disruptions to their access protocols unless they implement alternative non-phishable factors.
Microsoft stated that the move aligns with broader industry efforts led by groups such as the FIDO Alliance, which promotes passwordless standards to combat rising cyber threats. The company noted that phishing attacks targeting enterprise credentials have increased significantly in recent years, often bypassing traditional multi-factor authentication when SMS codes are compromised.
While Microsoft has set firm dates for these changes, it acknowledged that some legacy systems and specific regulatory environments may require extended transition periods or customized compliance pathways. Enterprise administrators will need to audit their current security infrastructure to ensure compatibility with the new default settings before the 2026 deadline takes effect.
The announcement leaves open questions regarding how smaller businesses without dedicated IT teams will manage the migration, particularly those relying heavily on SMS for remote workforce access. Additionally, it remains unclear whether Microsoft will offer extended grace periods for organizations facing technical hurdles in deploying passkey infrastructure across global networks before the February 2027 cutoff.
As of Monday's announcement, no specific exceptions to the timeline have been publicly detailed, though enterprise support channels are expected to provide guidance on migration strategies in the coming months.