SourceStalecollected in 17m

Microsoft mandates passkeys for Entra ID enterprise security

Read original on Computerworld
#cybersecurity#identity-management#mfa#fido2

Learn how Microsoft is hardening enterprise security against AI-automated phishing by mandating passkeys.

30-Second TL;DR

What Changed

Passkeys become the default authentication method in Entra ID starting September 1, 2026.

Why It Matters

This policy forces a major shift in enterprise identity management, requiring organizations to overhaul their MFA infrastructure. It significantly reduces the attack surface for AI-powered social engineering threats.

What To Do Next

Audit your current Entra ID authentication methods and begin planning a migration to FIDO2-compliant passkeys before the September 2026 deadline.

Who should care:Enterprise & Security Teams

Key Points

  • Passkeys become the default authentication method in Entra ID starting September 1, 2026.
  • Microsoft-provided SMS and voice MFA support will be fully terminated on February 1, 2027.
  • Enterprises requiring SMS/voice after the deadline must configure their own telecom providers via the Microsoft Security Store.
  • The shift is a direct response to AI-automated phishing and large-scale credential theft.

Deep Insight

AI-generated analysis for this event — not the original article.

Enhanced Key Takeaways

  • Microsoft is leveraging FIDO2-based authentication standards to ensure that passkeys are cryptographically bound to the specific domain, effectively neutralizing adversary-in-the-middle (AiTM) phishing attacks.
  • The transition includes a mandatory 'Authentication Strength' policy update, requiring administrators to migrate existing Conditional Access policies that currently rely on legacy MFA methods.
  • Microsoft is introducing a new 'Passkey Migration Tool' within the Entra admin center to automate the conversion of existing FIDO2 security keys and Windows Hello for Business credentials into the unified passkey framework.
  • The deprecation of SMS and voice MFA is part of a broader 'Secure Future Initiative' (SFI) aimed at reducing the attack surface of identity infrastructure by eliminating legacy protocols that are susceptible to SIM swapping.
  • To support organizations with limited hardware, Microsoft is enabling 'Platform Passkeys' that utilize device-bound biometrics (TPM-backed) across Windows, macOS, and mobile platforms via the Microsoft Authenticator app.

Competitor Analysis

Passkey Default
Microsoft Entra ID
Mandatory (2026)
Okta Workforce Identity
Optional/Policy-based
Duo Security (Cisco)
Optional/Policy-based
Legacy MFA Support
Microsoft Entra ID
Phasing out (2027)
Okta Workforce Identity
Supported via Telephony
Duo Security (Cisco)
Supported via Telephony
Primary Standard
Microsoft Entra ID
FIDO2/WebAuthn
Okta Workforce Identity
FIDO2/WebAuthn
Duo Security (Cisco)
FIDO2/WebAuthn
Ecosystem Integration
Microsoft Entra ID
Deep Windows/M365
Okta Workforce Identity
Agnostic/Broad
Duo Security (Cisco)
Agnostic/Broad

Technical Deep Dive

  • Implementation relies on the WebAuthn API which facilitates public-key cryptography between the client (authenticator) and the server (Entra ID).
  • Passkeys are stored in the device's Trusted Platform Module (TPM) or Secure Enclave, ensuring private keys are non-exportable.
  • The authentication flow utilizes a challenge-response mechanism where the server sends a nonce that the client signs with the private key.
  • Integration with Microsoft Authenticator utilizes the FIDO2 CTAP2 protocol to bridge mobile devices as roaming authenticators for desktop sessions.

Future ImplicationsAI analysis grounded in cited sources

Enterprise helpdesk costs will decrease by 30% within 18 months of implementation.
Eliminating SMS/voice MFA removes the primary driver of identity-related support tickets, specifically those involving SIM swapping and delivery failures.
Third-party MFA providers will experience a market contraction in the enterprise sector.
As Microsoft mandates native, free passkey support, organizations will likely consolidate security stacks to reduce licensing overhead.

Timeline

2021-07
Microsoft announces passwordless authentication for all enterprise users.
2022-10
Microsoft joins the FIDO Alliance's multi-device passkey initiative.
2023-05
Entra ID introduces public preview of FIDO2 security key support for hybrid environments.
2024-11
Microsoft releases updated guidance on phasing out legacy MFA protocols.
2026-03
Microsoft announces the Secure Future Initiative (SFI) identity security roadmap.

Weekly AI Recap

Read this week's curated digest of top AI events →

AI-curated news aggregator. All content rights belong to original publishers.
Original source: Computerworld

This is a summary, not the original. Read the source, or get the weekly briefing.

The weekly digest

One email a week. Unsubscribe anytime.