Microsoft Security logo enlarged through a magnifying glass on a laptop screen
time 3 minute read

Microsoft Is Moving to Passkeys: What It Means for Your Identity Strategy

Microsoft is taking another major step toward phishing-resistant authentication. 

In a recent Microsoft Security announcement, Microsoft confirmed that beginning September 1, 2026, it will start rolling out passkeys as the default authentication experience in Microsoft Entra ID. As the rollout reaches each organization, users currently enabled for SMS or voice authentication will automatically be enabled for passkeys and prompted to register a passkey the next time they complete multifactor authentication. 

Then, on February 1, 2027, Microsoft will retire its native telecom delivery for SMS and voice authentication. Organizations that continue to require SMS or voice will need to use a supported third-party telecom provider. Microsoft’s recommendation is straightforward: organizations should move users to passkeys or another phishing-resistant authentication method as soon as possible. 

For organizations using Microsoft 365 and Microsoft Entra, this raises an important question: Is your identity and authentication strategy aligned with where Microsoft security is going? 

Traditional MFA Is No Longer the End Goal 
Multifactor authentication remains an important security control, but attackers have evolved. 

Microsoft Threat Intelligence has observed AI-enabled phishing campaigns reaching click-through rates as high as 54%, compared with roughly 12% for more traditional campaigns. Microsoft also points to increasingly accessible techniques such as SIM swapping and MFA bypass as reasons organizations need stronger authentication. 

Passkeys use public-key cryptography rather than shared secrets, making them phishing-resistant by design. They can also provide users with a faster and simpler sign-in experience. 

Microsoft Entra supports both synced and device-bound passkeys, giving organizations flexibility based on their users, devices, and security requirements. 

The identity conversation is changing from: 
“Do our users have MFA?” 
to: 
“Are our users protected with authentication that can resist modern phishing attacks?” 

Modern Identity Security Goes Beyond Authentication 

Attackers are increasingly targeting more than passwords and MFA prompts. Modern attacks can abuse authentication flows or attempt to steal an authenticated session after a user successfully signs in. 

Microsoft Entra provides additional capabilities organizations should evaluate as part of a modern identity security strategy:

  • Conditional Access and Identity Protection to make access decisions using identity, device, application, location, and risk signals

  • Authentication Strengths to require specific authentication methods, including phishing-resistant authentication, for sensitive users, applications, and resources

  • Device Code Flow controls to restrict a high-risk authentication flow that can be abused in phishing attacks

  • Authentication Transfer controls to evaluate and restrict cross-device authentication transfer where it is not required

  • Token Protection to help prevent supported authentication tokens from being replayed from another device

Together, these capabilities illustrate Microsoft’s broader security direction: protect the authentication method, evaluate the context and risk of the sign-in, control how authentication occurs, and protect the resulting session. 

Why Native Microsoft Entra Authentication Matters 
As organizations move toward phishing-resistant authentication, they should evaluate whether their current MFA approach can fully support that direction. 

Third-party MFA can satisfy general MFA requirements in Microsoft Entra. However, third-party authentication used through Microsoft’s External MFA framework currently cannot satisfy Conditional Access Authentication Strengths. 

This distinction matters. Authentication Strengths allow organizations to require specific authentication methods—including phishing-resistant authentication—rather than simply accepting any method that satisfies a general MFA requirement. 

For organizations already invested in Microsoft 365 and Microsoft Entra, native Microsoft authentication provides the most direct path to phishing-resistant authentication through methods such as passkeys, Windows Hello for Business, FIDO2 security keys, and certificate-based authentication. 

The question is no longer simply whether MFA is enabled. It is whether the authentication strategy can meet today’s identity security requirements. 

What Does This Mean for Organizations Using Third-Party MFA? 
Organizations using third-party MFA providers such as Duo or Okta should evaluate whether their current authentication architecture aligns with Microsoft’s evolving identity security strategy. 

Where Microsoft Entra provides the native authentication path, organizations should consider transitioning applicable users toward phishing-resistant Microsoft Entra authentication. This can help organizations take advantage of Microsoft’s native authentication capabilities while potentially reducing overlapping licensing, administration, and complexity. 

Modernizing authentication with Microsoft Entra provides an opportunity to: 

  • Deploy passkeys and enforce phishing-resistant Authentication Strengths
  • Modernize Conditional Access and identity risk protections
  • Simplify identity architecture and potentially reduce overlapping third-party MFA licensing and administration
  • Better align identity security with Microsoft’s Zero Trust architecture 

Third-party MFA may still have a specific role for server access or certain network infrastructure where native Microsoft Entra authentication does not apply. In those scenarios, organizations can retain an appropriate third-party solution for those requirements while modernizing Microsoft 365 and Entra authentication around Microsoft’s native security architecture. 

The objective is not simply to replace one MFA product with another. It is to build a phishing-resistant, Zero Trust identity architecture around Microsoft’s modern security controls, while retaining third-party authentication only where there is a specific requirement for it. 

Start Planning Now 
Microsoft recommends organizations begin preparing now by identifying users who still rely on SMS or voice, planning their passkey rollout, driving adoption through registration campaigns, and communicating the change to affected users. 

Organizations should also use this opportunity to evaluate their authentication methods, Conditional Access policies, phishing-resistant authentication readiness, identity risks, third-party MFA dependencies, privileged access, authentication flows, and session protections. 

Microsoft’s move toward passkeys is more than an authentication-method change. It is an opportunity to modernize the broader identity security architecture protecting Microsoft 365 and Microsoft Entra. 

Helient can help organizations assess their current Microsoft Entra identity and authentication environment, identify gaps against Microsoft’s evolving security direction, and develop a modernization roadmap that includes passkeys, phishing-resistant authentication, Conditional Access, and modern identity and session protections. 

To learn more or discuss how these changes may impact your organization, please contact our industry-leading experts at service@helient.com.