Goodbye text messages or phone calls: Microsoft makes passwords the default authentication process for businesses

goodbye-text-messages-or-phone-calls:-microsoft-makes-passwords-the-default-authentication-process-for-businesses

Goodbye text messages or phone calls: Microsoft makes passwords the default authentication process for businesses


  • Starting September 1, 2026, passwords will become the default for Entra ID
  • Microsoft removes SMS/phone call authentication from February 1, 2027
  • Victims are more likely to open AI-assisted phishing emails

Microsoft has confirmed plans to make passwords the default or preferred authentication method for Entra ID starting September 1, 2026, announcing new changes to account authentication in an effort to combat sophisticated attacks.

A few months later, starting February 1, 2027, the company will also stop providing its own SMS and voice call authentication codes for Entra ID, in the hope that business users will fully embrace passwordless login.

While passkeys don’t promise to stop attacks entirely, they make phishing attempts much less effective because attackers would need access to victims’ hardware to gain access.

Microsoft continues its quest for passwords

Although the company is ending support for its own SMS and phone call authentication methods, passkeys will no longer be the only login method after the change. Windows Hello for Business (biometrics) and FIDO2 security keys will still be available, for example.

“The AI ​​era demands stronger, phishing-resistant authentication,” says a company advisory seen by Latest versions of Windows bed. “We’re making access keys the default authentication experience in Microsoft Entra to help customers securely adopt AI at scale. »

While AI hasn’t really improved the ability of attacks to break traditional authentication methods, it has made attacks more convincing. According to the company’s own information, the click-through rate on phishing emails stands at 54% for AI-assisted campaigns, compared to just 12% for conventional campaigns.

As more people open malicious links, the effects are compounded, hence the need to improve overall security.

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!

Moving forward, Microsoft’s suggested plan for affected organizations includes identifying users who are still using SMS/voice authentication, planning to roll out a company-wide password, and updating employees.

“SMS and voice have served their purpose well, bringing multi-factor authentication to billions of users who otherwise would not have had it,” Microsoft concluded, saying that “the threat environment has evolved beyond their capabilities.”


Google logo on black background next to the text “Click to follow TechRadar”

Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.

Exit mobile version