Social EngineeringBleeping Computer
8.0 — CRITICAL
Microsoft Entra ID gets passkeys default authentication starting September
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Microsoft Entra ID is transitioning to passkeys as the default authentication method, replacing phone-based SMS and voice authentication starting September 2026, in an effort to strengthen protection against credential theft and phishing.
⚙️Technical Details
Affected Systems
Microsoft Entra ID enterprise identity service
Attack Vectors
phishingcredential theft
💥Impact Assessment
Severity: high
Who Is at Risk
Organizations using Microsoft Entra ID with phone-based SMS and voice authentication
🛡️Recommended Actions
1Ensure all users are using a phishing-resistant method before the transition date.
2Configure third-party telecom providers through the Microsoft Security Store for organizations still required to use phone-based authentication.
3Monitor Entra ID accounts for suspicious activity and implement breach and attack simulation tests with SIEM and EDR rules.
📦Affected Products
Microsoft Entra ID enterprise identity service
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
