14/08/2026
π The Future of Authentication is Phishing-Resistant
Microsoft has announced a major shift in authentication security for Microsoft Entra ID. As cyber threats continue to evolve, traditional SMS and voice-based MFA methods are being phased out in favour of more secure, phishing-resistant authentication methods such as Passkeys.
π
Key Dates to Know β’ 1 September 2026: Users currently using SMS or voice authentication will begin receiving prompts to register a passkey. β’ 1 February 2027: Microsoft-provided SMS and voice authentication will be retired. β’ After this date, users relying solely on SMS or voice for MFA will be required to register a passkey to continue signing in.
Why the change? Passkeys provide significantly stronger protection against phishing, SIM-swap attacks, and credential theft, helping organisations strengthen their security posture.
β
Now is the time to review your Microsoft Entra ID authentication policies, identify affected users, and begin planning your transition to phishing-resistant authentication.
Need help preparing for the change? Our team can help you assess your environment, implement passkeys, and ensure a smooth migration before the deadlines arrive.