HomeIntelligenceBrief
BREACH BRIEF🟠 High Advisory

Microsoft Entra ID Makes Passkeys Default Authentication, Retiring SMS/Voice MFA in 2027

Microsoft will default to passkey‑based MFA for Entra ID in September 2026 and retire SMS/voice MFA on 1 Feb 2027. The move is aimed at eliminating phishable second factors and has direct implications for SOC 2 logical‑access controls.

LiveThreat™ Intelligence · 📅 July 15, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Microsoft Entra ID Makes Passkeys Default Authentication, Retiring SMS/Voice MFA in 2027

What Happened — Microsoft announced that, starting September 2026, passkeys will be the default multi‑factor authentication (MFA) method for Entra ID. SMS and voice‑based MFA will be retired on 1 February 2027, and any user still relying on those methods will be forced to adopt a phishing‑resistant credential.

Why It Matters for Compliance & Audit Readiness

  • The shift directly impacts SOC 2 CC6 (Logical Access) and CC7 (System Operations) controls that require “phishing‑resistant” authentication mechanisms.
  • Organizations must capture the change in their access‑control policy, update evidence of MFA method usage, and retain audit logs showing the migration to passkeys.
  • Failure to transition before the February 2027 deadline can result in non‑compliant MFA configurations, exposing the audit trail to gaps and increasing the risk of credential‑theft findings during a SOC 2 audit.

Who Is Affected – Enterprises that use Microsoft Entra ID for identity management across SaaS, cloud‑infrastructure, and internal applications (technology, finance, healthcare, retail, etc.).

Recommended Actions

  • Run the Entra SMS/Voice Policy Scanner to inventory users still on telephony‑based MFA.
  • Update IAM policies to require passkey enrollment for all accounts; document the policy change as part of your SOC 2 control evidence.
  • Capture PowerShell script output and enrollment logs as audit artifacts for CC6 compliance.
  • If phone‑based MFA is still required for legacy workflows, provision a third‑party telecom provider via the Microsoft Security Store and record the justification.

Source: BleepingComputer

Technical Notes – The rollout automatically prompts users of SMS/voice MFA to register a passkey on their next sign‑in. Microsoft cites AI‑enabled phishing campaigns with click‑through rates up to 54 % as the driver for this change. No new CVEs are disclosed; the change is a preventive control upgrade. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →