Goodbye SMS or Phone Calls — Microsoft Is Making Passkeys the Default Authentication Process for Businesses
6 Articles
6 Articles
Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses
Beginning September 1, 2026, passkeys will become the default for Entra IDMicrosoft is retiring SMS/phone call authentication from February 1, 2027Victims are more likely to open AI-assisted phishing emailsMicrosoft has confirmed plans to make passkeys the default or preferred authentication method for Entra ID beginning September 1, 2026, announcing further changes to account authentication in a bid to combat sophisticated attacks.A few months …
Why is Schwab using passkeys?
Why is Schwab using passkeys? skadia.guzman Thu, 07/23/2026 - 12:15 Why is Schwab using passkeys? Passkeys help protect you from fraud and make signing in to your account simpler. With passkeys:Once you've enrolled, there's login ID or password to remember. A passkey works behind the scenes with your device, so you don't have to think about it once it's set up.There is nothing for fraudsters to steal. Passkeys are bound to specific sites and wi…
Phishing campaign targets Microsoft authentication
Kaspersky has released a new report detailing a phishing campaign where attackers abuse Microsoft’s authentication mechanism. The campaign spanned from early April to mid-May 2026 and was styled as a notice from a law firm, aimed at stealing victims’ credentials and access their data. Microsoft’s authentication mechanism – the OAuth 2.0 Device Authorisation Grant – allows users to log into their Microsoft accounts on devices with limited input c…
After personal accounts, Microsoft attacks businesses. In Entra ID, access keys will become the preferred method of connection, before the (almost) definitive abandonment of SMS codes and voice calls supported by the publisher.
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session
Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over the resulting Microsoft 365 session without directly stealing credentials. The campaign abuses the OAuth device-code flow, a feature intended for devices such as smart TVs and meeting-room systems that cannot easily display a normal login page. Att…
Microsoft admits SMS and voice MFA can’t stop AI attacks, mandates passkeys in Entra by February 2027
Microsoft no longer believes SMS and voice are reliable MFA (Multi-Factor Authentication) and wants everyone to embrace passkeys. Starting February 2027, Microsoft Entra customers will be required to use passkeys, particularly because of AI-assisted threats. Microsoft’s research found that SMS and voice authentication become less of a security vault and more of a liability in the age of AI. In May 2026, Windows Latest reported that Microsoft is …
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium


