← Back to feed
PhishingEmerging1 sourceSep 1, 2026 · 08:25via CSO Online

Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.

Brief

Today marks the beginning of the end of an era for enterprise Microsoft authentication.

As of Sept. 1, passkeys are now the default authentication method for Entra ID , Microsoft’s cloud-based identity and access management (IAM) service. By Feb. 1, 2027, Microsoft-provided SMS and voice authentication will be a thing of the past.

The move is seen as one aimed at pushing enterprises toward passwordless authentication — something security leaders are broadly on board with but often struggle to fully deploy .

Microsoft putting its weight behind passkeys in the enterprise may mark a watershed moment for the passwordless technology, but legacy applications and specialized use cases remain a sticking point.

Read more on CSO Online