
The requirements for IT security are constantly evolving. Especially when it comes to protecting user accounts, it is becoming clear that traditional passwords and SMS codes are no longer sufficient in the long term.
Microsoft is therefore taking another step towards modern and phishing-resistant authentication.
Since 1 September 2026 passkeys are becoming more firmly established as a standard authentication method in Microsoft Entra ID. Users who have previously used SMS or voice calls for authentication are gradually being prompted to set up a passkey.
From the 1 February 2027 Microsoft is to discontinue its own provision of SMS and voice calls for authentication. Organisations that still require these methods must use alternative solutions or supported telecommunications providers.
A passkey is a modern sign-in method that can replace traditional passwords.
Instead of having to enter a password every time and then confirm an SMS code, logging in can be done, for example, via:
take place.
In the background, this method is based on cryptographic keys. As a result, the actual login secret is not transmitted to the website or application like a classic password.
This is precisely what makes passkeys significantly more resilient to many classic phishing attacks. Microsoft explicitly describes passkeys as a phishing-resistant authentication method.
Many businesses use Microsoft 365 daily for core business processes:
This simultaneously makes the Microsoft account an important access point to the entire corporate IT.
If a user account is compromised, attackers may be able to access emails, files, internal information or other corporate resources, depending on the permissions available.
Modern authentication is therefore an important component of a comprehensive IT security strategy.
Although classic two-factor authentication via SMS offers additional protection compared to a single password, it is also vulnerable.
Microsoft now classifies SMS and voice calls as significantly weaker authentication methods compared to passkeys.
Companies should therefore review which authentication methods are currently in use and whether users are still solely reliant on passwords and SMS.
A meaningful security check can include the following points, amongst others:
Because IT security does not consist of a single measure. What matters is the interplay of identity protection, access control, backup, monitoring and regular system reviews.
The transition does not have to be complicated, but it should be carried out in a planned manner.
Which users are affected?
Which authentication methods are currently used?
Which devices already support passkeys?
And what additional security measures should be implemented?
This is precisely where we come in.
K&S NexTech analyses your existing IT environment together with you and develops a suitable solution for your company.
Comments are closed