Entra · Security
03.08.2026Action requiredSecurity
Passkeys become the default phishing-resistant Entra method
Microsoft Entra ID is changing its authentication experience to make passkeys the default phishing-resistant method and reduce dependence on SMS and voice authentication.
What changed
The sign-in experience will guide users toward passkeys as the preferred method instead of treating phishable methods as the normal path.
Technical details
- Passkeys promoted as the default method
- Reduced reliance on SMS and voice
- Stronger phishing-resistant sign-in baseline
Why it matters
Authentication-method changes affect registration, help-desk recovery, Conditional Access and user communication even when no application deployment is required.
Known limitations
- Tenant rollout and user eligibility can be phased
- Recovery and break-glass methods still require deliberate planning
Now check
- Review Authentication Methods policy and passkey eligibility
- Pilot registration and recovery with representative users
- Update help-desk guidance before broad rollout