Home Blog Microsoft Entra ID Makes Passkeys the Default

Microsoft Entra ID Makes Passkeys the Default

 2026/09/30   Microsoft Cloud Solutions   9 visit(s)  2 min to read

Ctelecoms_Character    
 By:Ctelecoms

 Ctelecoms

Ctelecoms-Microsoft-Entra-KSA

Passwords and SMS-based authentication have been used for years to protect business accounts.

Microsoft is now moving further toward passwordless and phishing-resistant authentication.

Starting September 1, 2026, Microsoft began rolling out passkeys as the default authentication experience in Microsoft Entra ID.

The change is part of Microsoft's wider effort to reduce dependence on authentication methods that can be targeted through phishing and social engineering.

What Is a Passkey?

A passkey is a passwordless sign-in method based on public-key cryptography.

Instead of asking users to enter a password or receive a code by SMS, the user can authenticate using a method supported by their device.

Depending on the setup, this can include a device-based passkey, Microsoft Authenticator, Windows authentication or a FIDO2 security key.

Passkeys are designed to resist phishing because there is no password or shared secret that can simply be entered into a fake website.

What Changed on September 1?

Microsoft began rolling out passkeys as the default authentication experience in Entra ID.

As the change reaches an organization, users who are enabled for SMS or voice authentication can be prompted to register a passkey during multifactor authentication.

This means organizations should not wait until the end of the transition to review their authentication policies.

What Happens to SMS and Voice Authentication?

Microsoft has also announced a longer-term change.

On February 1, 2027, Microsoft-provided SMS and voice authentication will end as a native Microsoft Entra capability.

Organizations that still have a business, technical or regulatory requirement for SMS or voice will have the option to work with supported telecom providers through the Microsoft Security Store.

For most organizations, however, Microsoft recommends moving users toward passkeys or another phishing-resistant authentication method.

Why Is Microsoft Making This Change?

SMS and voice authentication can be targeted through different forms of social engineering and account attacks.

Passkeys use a different security model.

Because they rely on cryptographic credentials rather than a code that a user reads and enters, they can provide stronger protection against phishing while also making sign-in easier for users.

Microsoft has also reported that AI-assisted phishing is increasing the scale and sophistication of attacks, making stronger authentication more important.

What Should Businesses Do Now?

Organizations using Microsoft Entra ID should start with a review of their current authentication methods.

Key steps include:

  1. Identify users using SMS or voice

Review which users and groups still depend on these methods.

  1. Plan passkey deployment

Choose the passkey types that fit your users, devices and security requirements.

  1. Test with a pilot group

Start with a small group before expanding the deployment across the organization.

  1. Communicate the change

Users should know what will change and how to register their passkey.

  1. Review recovery methods

Strong authentication should be supported by a clear account recovery process that does not depend entirely on easily phished credentials.

Passkeys and Zero Trust

The move to passkeys also fits into a broader Zero Trust approach.

Identity is increasingly treated as a central security layer because users can access cloud applications, business data and services from many locations and devices.

Strong authentication helps organizations reduce the risk of compromised credentials becoming a path into business systems.

How Ctelecoms Can Help

Ctelecoms helps Saudi businesses strengthen identity and access security using Microsoft technologies.

Our experts can assess your Microsoft Entra environment, review authentication methods and help plan a practical transition toward stronger, passwordless authentication.

Need help preparing your Entra ID environment for the move to passkeys? Talk to Ctelecoms' experts.






Search the Blog

Subscribe Blog

Solutions

capling-icon

Computing & Hyper-converged Infrastructure Solutions

Upgrade your IT to be as agile and efficient ...

security-icon

IT & Cyber-Security Solutions

Best-in-class cyber security solutions to ...

microsoft-icon

Microsoft Cloud Solutions

Explore Ctelecoms extensive selection of ...

capling-icon

Datacenter Solutions

Solve issues, streamline operations, promote ...

backup-icon

Cloud Backup & Disaster Recovery Solutions

Keep your data, apps, emails and operations ...

networking-icon

Unified Communications & Networking Solutions

Ensure you are securely connected with all ...

meraki-icon

Meraki Networking Solutions

Quickly deploy a reliable, secure, cloud-managed ...