It’s indispensable for businesses running cloud applications but irresistible to cybercriminals, which is why millions of users of Microsoft’s Entra ID authentication server are about to see a major change to the way they log in as Microsoft blocks any type of authentication but passkeys.

Entra ID – previously known as Azure Active Directory – is a cloud identity and access management (IAM) tool that manages the digital identity and access privileges of every device and user on a company network, controlling how they interact with outside services and with each other.

A close relative of the Microsoft Active Directory system used on internal networks Entra ID – used at over 720,000 businesses – provides single sign-on (SSO) services that let users log on once, then be logged into Office 365 and other cloud systems they’re authorised for.

To strengthen user verification, Entra ID currently supports multi factor authentication (MFA) using both SMS and phone-based authentication as well as passkeys, which are encrypted codes that are locked to a password manager like iCloud Keychain or Google Password Manager, or to a specific device.

Because cybercriminals often target the access credentials stored in the system by sending scam SMS messages or phone calls – including the use of AI voices that can now have startlingly realistic conversations with victims – Microsoft is cutting support for SMS and phone authentication.

“SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID,” the company explains, adding that “it is imperative for users to use secure authentication and move from phishable authentication methods.”

From 1 September, Microsoft will begin a five-month transition period in which it will push users to use passkeys rather than existing SMS or voice based authentication methods – which will no longer work from 1 February next year.

All users relying on SMS or voice authentication will automatically be set up to use passkeys from 1 September, and will be prompted to register a passkey the next time they sign in.

Companies that rely on SMS verification for specific reasons do have the option to send SMS over a different telco message that Microsoft will publish more details on this on 18 September but for everyone else, the change means millions of users worldwide can no longer ignore passkeys.

Protecting the keys to the kingdom

The change follows a similar move last year to strike user passwords from Microsoft Authenticator and force users to adopt passkeys instead.

Because Entra ID manages the so-called ‘keys to the kingdom’ that control access to every cloud system the company uses, it’s a perennial target for cybercriminals.

In 2024, the Australian Cyber Security Centre and other Five Eyes security agencies issued a general warning about 17 “common techniques” that had been observed for targeting companies’ Active Directory.

Credential abuse now provides initial access to victims’ systems in 13 per cent of data breaches, according to Verizon’s latest Data Breach Investigations Report (DBIR), down over half since generative AI (genAI) hit the mainstream in 2023, but still a major problem for businesses.

Mobile users are 40 per cent more likely to fall for SMS and voice-based attacks than emailed phishing messages, Verizon found, which explains why Microsoft and other tech giants have moved aggressively to support and promote – and, now, require – use of passkeys tied to users’ devices.

Passkey advocate the FIDO Alliance, which surveyed 11,000 consumers and 1,400 business decision-makers in 10 countries, recently reported that over 5 billion passkeys are now in use worldwide, with 68 per cent of companies using or deploying passkeys for employee sign-ins.

Concrete steps towards passkey ubiquity

Yet passkeys are not without their challenges, and the major change to a key enterprise application like Entra ID will force businesses to run user education campaigns so helpdesks aren’t inundated with support requests come 1 September.

Deployments of passkeys to date have shown that “deployment is not the end state,” FIDO Alliance CMO Megan Shamas said, noting that many adopters of the technology “see strong initial uptake but need clearer guidance to drive sustained, everyday usage.”

“Getting from rollout to habitual use remains a work in progress,” she said, with organisations “looking for clear implementation guidance on how to roll out across environments, manage devices and recovery, and ensure employees use passkeys in daily sign-ins.”

Microsoft has moved to offer such guidance, with the company offering clear advice on passkey rollout strategies, user education campaigns, and related security infrastructure that can further lock down critical IAM systems.

For the millions of users that use Entra ID every day, the message from Microsoft is clear: from 1 February, the company warns, “users must register a passkey before they can continue signing into their account…. there is no opt out.”