By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Microsoft Urges Entra ID Admins to Adopt Passkeys
Microsoft has issued a reminder to administrators of Microsoft Entra ID, formerly Azure Active Directory, to transition users away from SMS-based first-factor authentication methods. This proactive measure is crucial as Microsoft plans to retire SMS first-factor sign-in capabilities starting in February 2027. The company is strongly encouraging the adoption of phishing-resistant authentication methods, with passkeys being a primary recommendation. This migration aims to enhance security by moving away from less secure, easily phishable SMS codes towards more robust authentication protocols. The retirement of SMS sign-in is a significant step in Microsoft's ongoing efforts to bolster identity and access management security for its enterprise customers. Administrators are advised to begin the migration process promptly to ensure a smooth transition and avoid potential sign-in disruptions for their users. The move aligns with broader industry trends towards passwordless authentication and enhanced protection against sophisticated cyber threats. Microsoft has provided resources and guidance to assist administrators in implementing these new authentication methods. The company's commitment to improving security posture is evident in this directive, pushing organizations to adopt modern, secure authentication solutions. The transition to passkeys and similar technologies offers a more secure and user-friendly experience, eliminating the need for users to remember complex passwords and reducing the risk of credential stuffing attacks. By phasing out SMS authentication, Microsoft is addressing a known vulnerability that has been exploited by attackers through SIM-swapping and other social engineering tactics. The February 2027 deadline signifies a firm commitment to this security enhancement, giving organizations ample time to plan and execute the necessary changes. Administrators are encouraged to explore the various passkey options and other phishing-resistant methods supported by Entra ID to find the best fit for their organization's specific needs and security policies. This initiative underscores the evolving landscape of cybersecurity and the continuous need for organizations to adapt their security practices to stay ahead of emerging threats. The successful adoption of these new methods will contribute to a more secure digital environment for businesses relying on Microsoft's cloud services. The company's proactive communication aims to prevent widespread issues and ensure that all users can maintain secure access to their accounts and resources without interruption. The emphasis on phishing-resistant methods is a direct response to the increasing prevalence and sophistication of phishing attacks targeting user credentials. By migrating to passkeys, organizations can significantly reduce their attack surface and protect sensitive data from unauthorized access. The retirement of SMS as a primary sign-in method is a critical component of Microsoft's broader strategy to enhance the security and resilience of its identity platform.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.