HomeIntelligenceBrief
BREACH BRIEF🟠 High Advisory

Microsoft Entra ID to Make Passkeys Default and Retire SMS/Voice MFA Starting September 2026

Microsoft will roll out passkeys as the default MFA method for Entra ID on 1 Sept 2026 and retire native SMS/voice authentication. The change forces organizations to adopt stronger, phishing‑resistant credentials, directly impacting SOC 2 access‑control compliance.

LiveThreat™ Intelligence · 📅 July 14, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

Microsoft Entra ID to Make Passkeys Default and Retire SMS/Voice MFA Starting September 2026

What Happened — Microsoft announced that, beginning 1 Sept 2026, passkeys will become the default multi‑factor authentication (MFA) method for Entra ID in the public cloud. SMS and voice‑based MFA will be phased out, with automatic passkey registration prompts for all users and no opt‑out option. Organizations that still need SMS/voice for regulatory or business reasons must configure third‑party telecom providers via the Microsoft Security Store.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Logical Access) requires documented, strong authentication mechanisms; the shift to passkeys provides a defensible control that reduces reliance on phishable factors.
  • Continuous‑compliance programs must capture the change‑over as evidence of control implementation and update access‑control policies, user‑provisioning workflows, and audit logs.
  • Verisq’s SOC 2 Access Controls capability can help map the new passkey workflow to existing trust‑service criteria and generate audit‑ready evidence.

Who Is Affected

  • Cloud‑based SaaS providers, enterprise IT departments, and any organization that uses Microsoft Entra ID for identity management (technology, finance, healthcare, etc.).

Recommended Actions

  • Review and update your IAM policy to reference passkey‑based MFA as the primary authentication factor.
  • Capture the configuration change (passkey enrollment prompts, third‑party telecom provider contracts) in your control evidence repository.
  • Conduct a gap analysis against SOC 2 CC6.1 to ensure the new workflow satisfies the “least‑privilege” and “strong authentication” requirements.
  • Train users on passkey enrollment and usage to maintain security awareness.

Technical Notes – The rollout will automatically enable passkey registration during the next MFA prompt; SMS/voice will be disabled for native Entra ID on 1 Feb 2027. Organizations can select supported telecom providers from the Microsoft Security Store starting 30 Oct 2026. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →