Entra · Security

Passkeys become the default phishing-resistant Entra method

Microsoft Entra ID is changing its authentication experience to make passkeys the default phishing-resistant method and reduce dependence on SMS and voice authentication.

What changed

The sign-in experience will guide users toward passkeys as the preferred method instead of treating phishable methods as the normal path.

Technical details

  • Passkeys promoted as the default method
  • Reduced reliance on SMS and voice
  • Stronger phishing-resistant sign-in baseline

Why it matters

Authentication-method changes affect registration, help-desk recovery, Conditional Access and user communication even when no application deployment is required.

Known limitations

  • Tenant rollout and user eligibility can be phased
  • Recovery and break-glass methods still require deliberate planning

Now check

  • Review Authentication Methods policy and passkey eligibility
  • Pilot registration and recovery with representative users
  • Update help-desk guidance before broad rollout