Microsoft is making passkeys the default authentication experience for Microsoft Entra ID public-cloud users beginning September 1, 2026 and will retire Microsoft-provided SMS and voice authentication. SMS first-factor sign-in and native Microsoft SMS/voice capabilities for workforce tenants will end on February 1, 2027; Global Administrators and external users have until July 1, 2027. SMS first-factor authentication has already been retired for Entra ID Free tenants.
Organizations must migrate affected users to phishing-resistant authentication to avoid sign-in disruptions. Users relying only on Microsoft-provided SMS or voice will have to register a passkey before they can sign in after the applicable deadline, with no opt-out from enforcement; a temporary opt-out only defers the initial passkey-default rollout until February 1, 2027. Microsoft also supports QR-code authentication, FIDO2 security keys, and other Entra methods, while organizations needing SMS or voice must use a supported customer-managed telecom provider through the Microsoft Security Store.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft began rolling out passkeys as the default Entra ID public-cloud authentication experience. Users enabled for SMS or voice authentication are automatically enabled for passkeys and prompted to register one during a subsequent MFA sign-in.
Microsoft retired SMS first-factor sign-in for Microsoft Entra ID Free tenants. The company also no longer enables SMS sign-in for newly created Entra ID tenants.
Microsoft announced that passkeys would become the default authentication experience for Microsoft Entra ID in the public cloud, replacing reliance on phishable authentication methods.
Microsoft plans to block SignInNoPassword SMS first-factor authentication across Microsoft Entra ID workforce tenants worldwide, including US Government Community Cloud tenants. The change will remove related configuration controls and does not apply to Azure AD B2C or Entra External ID customer identity scenarios.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.