- Starting September 1, 2026, passwords will become the default for Entra ID
- Microsoft removes SMS/phone call authentication from February 1, 2027
- Victims are more likely to open AI-assisted phishing emails
Microsoft has confirmed plans to make passwords the default or preferred authentication method for Entra ID starting September 1, 2026, announcing new changes to account authentication in an effort to combat sophisticated attacks.
A few months later, starting February 1, 2027, the company will also stop providing its own SMS and voice call authentication codes for Entra ID, in the hope that business users will fully embrace passwordless login.
While passkeys don’t promise to stop attacks entirely, they make phishing attempts much less effective because attackers would need access to victims’ hardware to gain access.
Microsoft continues its quest for passwords
Although the company is ending support for its own SMS and phone call authentication methods, passkeys will no longer be the only login method after the change. Windows Hello for Business (biometrics) and FIDO2 security keys will still be available, for example.
“The AI era demands stronger, phishing-resistant authentication,” says a company advisory seen by Latest versions of Windows bed. “We’re making access keys the default authentication experience in Microsoft Entra to help customers securely adopt AI at scale. »
While AI hasn’t really improved the ability of attacks to break traditional authentication methods, it has made attacks more convincing. According to the company’s own information, the click-through rate on phishing emails stands at 54% for AI-assisted campaigns, compared to just 12% for conventional campaigns.
As more people open malicious links, the effects are compounded, hence the desire to improve overall security.
Moving forward, Microsoft’s suggested plan for affected organizations includes identifying users who are still using SMS/voice authentication, planning to roll out a company-wide password, and updating employees.
“SMS and voice have served their purpose well, bringing multi-factor authentication to billions of users who otherwise would not have had it,” Microsoft concluded, saying that “the threat environment has evolved beyond their capabilities.”
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




