Skip to content

Microsoft Establishes Passkeys as Standard Sign-In Method in Entra ID

At a glance: Microsoft prioritizes passkeys in Entra ID and discontinues support for SMS and voice call-based authentication.

Microsoft is establishing passkeys as the preferred authentication method in Microsoft Entra ID and phasing out outdated, less secure procedures incrementally. In doing so, the company is systematically displacing SMS and voice-based methods in favor of modern cryptographic standards.

Microsoft is introducing passkeys – a phishing-resistant authentication method based on asymmetric cryptography – as the standard sign-in procedure in Microsoft Entra ID. This change affects the company’s central identity and access management platform and thus potentially millions of enterprise identities across the entire Microsoft ecosystem.

In parallel, SMS-based one-time passwords (OTP) and sign-in via voice calls will be phased out incrementally. These methods are considered vulnerable in security practice to SIM swapping, brute-force attacks, and other attack scenarios. By standardizing on passkeys, Microsoft substantially reduces the attack surface for common attack vectors in the IAM context.

CISOs should factor this development into their management planning: migrating existing systems and user bases from legacy authentication methods to passkeys requires planning, testing, and change management. At the same time, convergence on a phishing-resistant standard significantly lowers the risk profile, as passkeys do not transmit sign-in credentials over insecure out-of-band channels.


Source: www.heise.de · Published 14 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification through Lumi News Pipeline v1.7.3.

Share on: