Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft to Default Passkeys in Entra ID by 2026

Microsoft to Default Passkeys in Entra ID by 2026

Posted on August 15, 2026 By CWS

Microsoft is set to revolutionize its authentication protocols by making passkeys the standard for Microsoft Entra ID by September 1, 2026. This strategic move signifies a shift from traditional SMS and voice multifactor authentication (MFA) methods, which are more susceptible to phishing attacks.

Transition to Passkeys

From September 2026, users currently relying on SMS or voice authentication will transition to passkeys. Microsoft will initiate an automatic enablement process for these users, who will encounter prompts to register a passkey during their future MFA sign-ins. This transition aims to enhance security by minimizing the vulnerabilities associated with SMS and voice authentication.

Passkeys offer a more secure alternative by utilizing cryptographic credentials linked to a user’s device or credential manager. Unlike traditional methods, they do not involve shared secrets, thus mitigating risks of phishing and replay attacks. Supported by Microsoft Entra ID, these passkeys can be synced across devices using credential managers like iCloud Keychain or remain device-bound with options such as Windows Hello for Business.

Key Dates and Deadlines

Microsoft has outlined significant dates in this transition. By February 1, 2027, the company will discontinue its native telecom support for SMS and voice in Entra ID. Organizations planning to continue using these methods must switch to a customer-managed telecom service through the Microsoft Security Store, with provider details available from September 18, 2026.

Post-February 2027, users without passkeys will encounter a mandatory registration prompt to access their accounts. Organizations are encouraged to migrate early to avoid disruptions, as there will be no opting out of this enforcement.

Implementation and Preparation

Administrators are advised to identify users utilizing SMS or voice methods through the Entra Authentication Methods Policy or legacy MFA settings. Microsoft offers a PowerShell-based tool to assist in locating these users. Security teams should enable Passkey (FIDO2), form targeted user groups, and execute a phased registration campaign before automatic migration begins.

Despite a temporary opt-out available between September 1, 2026, and February 1, 2027, through Microsoft Graph settings, this does not circumvent the eventual requirement. Enterprises must treat SMS and voice MFA as backup options and prioritize the adoption of passkeys and FIDO2 security keys.

This transition underscores the importance of proactive security measures and the adoption of robust authentication mechanisms to safeguard against evolving cyber threats.

Cyber Security News Tags:Authentication, Cybersecurity, device-bound passkeys, Entra ID, MFA, Microsoft, Passkeys, phishing resistance, Security, Technology

Post navigation

Previous Post: AI Agents Adapt and Persist in Cyberattacks
Next Post: Hackers Target Critical SAP Commerce Cloud Vulnerability

Related Posts

Windows Server 2016 Bug Affects Domain Controllers Windows Server 2016 Bug Affects Domain Controllers Cyber Security News
New Wave of Steganography Attacks: Hackers Hiding XWorm in PNGs  New Wave of Steganography Attacks: Hackers Hiding XWorm in PNGs  Cyber Security News
Hackers Exploit Qinglong RCE Vulnerabilities Hackers Exploit Qinglong RCE Vulnerabilities Cyber Security News
Microsoft 365 PDF Export LFI Vulnerability Allows Access to Sensitive Server Data Microsoft 365 PDF Export LFI Vulnerability Allows Access to Sensitive Server Data Cyber Security News
Chrome Type Confusion 0-Day Vulnerability Code Analysis Released Chrome Type Confusion 0-Day Vulnerability Code Analysis Released Cyber Security News
NVIDIA NeMo AI Curator Enables Code Execution and Privilege Escalation NVIDIA NeMo AI Curator Enables Code Execution and Privilege Escalation Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zimbra Mail Server Vulnerability Exploited by Hackers
  • Hackers Exploit Zimbra Flaw Before Official Disclosure
  • Modernizing Software Supply Chains in Finance
  • TeamViewer Urges Update Due to Critical Security Flaws
  • Armadin Secures $255 Million, Now Valued at $2.5 Billion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zimbra Mail Server Vulnerability Exploited by Hackers
  • Hackers Exploit Zimbra Flaw Before Official Disclosure
  • Modernizing Software Supply Chains in Finance
  • TeamViewer Urges Update Due to Critical Security Flaws
  • Armadin Secures $255 Million, Now Valued at $2.5 Billion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark