Why Strong Authentication Is Becoming Essential: Preparing for Microsoft Entra ID’s Passkey Shift
27 August
Authentication is changing. Is your organisation ready?
Identity-based attacks are becoming increasingly accessible to cybercriminals. Techniques that once required significant technical expertise can now be carried out at greater speed and scale, with phishing, credential theft and social engineering continuing to put traditional authentication methods under pressure.
As the threat landscape evolves, organisations need to think beyond simply having multi-factor authentication (MFA) enabled. The focus is increasingly shifting towards phishing-resistant authentication.
Microsoft is moving towards passkeys
Microsoft has announced a significant change to authentication within Microsoft Entra ID.
From 1 September 2026, Microsoft will begin rolling out passkeys as the default authentication experience for Entra ID. Users currently enabled for SMS or voice authentication will be automatically enabled for passkeys and prompted to register one when they next complete MFA.
Microsoft has also announced that its own SMS and voice authentication service within Entra ID will end on 1 February 2027. Organisations that still have a requirement for SMS or voice will need to use a supported third-party telecom provider instead.
This represents a broader shift in cybersecurity: MFA alone is no longer enough if the authentication method itself can be phished or manipulated.
Why traditional authentication methods are increasingly vulnerable
A number of commonly used authentication methods rely on information or communication channels that can potentially be intercepted, captured or manipulated by attackers.
These include:
SMS and voice authentication
SMS and voice-based authentication have played an important role in improving account security, but they are increasingly recognised as vulnerable to attacks such as phishing and SIM swapping.
Microsoft is now encouraging organisations to move towards phishing-resistant alternatives.
One-time passcodes
Time-based or one-time passcodes, such as those generated by an authenticator application or hardware token, provide additional protection compared with passwords alone.
However, depending on the implementation, they can still be susceptible to phishing and real-time attacks where a user is manipulated into providing the code to an attacker.
Push notifications
Push-based MFA has significantly improved the user experience of MFA, but it can also be targeted through social engineering and repeated authentication requests.
The lesson is not that MFA is ineffective. Rather, organisations need to consider the strength and resistance of the authentication method they deploy.
Why passkeys are different
Passkeys use public-key cryptography rather than relying on users entering a secret code that can be captured by an attacker.
This makes them phishing-resistant by design and can also provide a simpler sign-in experience for users.
Microsoft Entra ID supports different types of passkeys, including:
- Synced passkeys stored in platform credential managers
- Device-bound passkeys
- Microsoft Authenticator passkeys
- Entra passkeys on Windows
- FIDO2 security keys
The right approach will depend on your organisation’s users, devices, security requirements and operational environment.
AI is increasing the scale of the threat
The development of generative AI is also changing the economics of cyberattacks.
Microsoft reports that AI-enabled phishing campaigns have achieved click-through rates of up to 54%, compared with approximately 12% for more traditional campaigns.
AI can help attackers create more convincing messages, automate reconnaissance and increase the speed at which compromised identities can be exploited.
This makes protecting the identity layer increasingly important.
What should organisations do now?
If your organisation uses Microsoft Entra ID, now is a good time to assess your authentication environment rather than waiting for the changes to take effect.
Microsoft recommends organisations:
- Identify users still relying on SMS or voice authentication.
- Review your authentication policies and determine which phishing-resistant methods are appropriate.
- Plan your passkey deployment around your users, devices and workflows.
- Use registration campaigns to encourage users to adopt passkeys.
- Prepare user communications so employees understand what is changing and what they need to do.
The transition doesn’t need to be disruptive. With the right planning, organisations can introduce stronger authentication while minimising user friction.
How ANSecurity can help
Moving to phishing-resistant authentication is more than a technology change. It requires consideration of people, processes, devices, security requirements and the practical user experience.
ANSecurity can help organisations assess their current position and develop a structured approach to adopting strong authentication.
Discovery and readiness assessment
We can help you understand your current authentication environment, identify potential gaps and assess your readiness for the move towards phishing-resistant authentication.
Strong Authentication Workshop
Our workshop provides a practical introduction to strong authentication and can include:
- Demonstrating how weaker authentication methods can be targeted
- Reviewing available authentication options
- Exploring different passkey and security-key form factors
- Considering implementation and user-experience requirements
- Identifying potential challenges and dependencies
- Developing a practical roadmap for adoption
Strong Authentication Adoption
For organisations ready to move forward, ANSecurity can provide professional services to support the adoption of strong authentication.
The approach can be tailored around your existing Microsoft environment, users, devices and business requirements.
Hardware Security Keys
For organisations requiring device-bound authentication, we can also provide and support hardware security keys, including solutions such as YubiKey.
We can help identify the appropriate form factor and deployment approach based on your organisation’s requirements.
Don’t wait for the change to arrive
The move towards passkeys is part of a wider shift towards phishing-resistant identity security.
For organisations using Microsoft Entra ID, the time to understand your current authentication position is now.
Preparing early gives you the opportunity to test your approach, communicate the changes to users and introduce stronger authentication on your own terms — rather than responding to the change at the last minute.
Want to understand how prepared your organisation is?
Speak to ANSecurity about a Strong Authentication Discovery Call and start planning your move towards phishing-resistant authentication.