Microsoft Entra ID Makes Passkeys Default Authentication, Retiring SMS/Voice MFA in 2027
What Happened — Microsoft announced that, starting September 2026, passkeys will be the default multi‑factor authentication (MFA) method for Entra ID. SMS and voice‑based MFA will be retired on 1 February 2027, and any user still relying on those methods will be forced to adopt a phishing‑resistant credential.
Why It Matters for Compliance & Audit Readiness
- The shift directly impacts SOC 2 CC6 (Logical Access) and CC7 (System Operations) controls that require “phishing‑resistant” authentication mechanisms.
- Organizations must capture the change in their access‑control policy, update evidence of MFA method usage, and retain audit logs showing the migration to passkeys.
- Failure to transition before the February 2027 deadline can result in non‑compliant MFA configurations, exposing the audit trail to gaps and increasing the risk of credential‑theft findings during a SOC 2 audit.
Who Is Affected – Enterprises that use Microsoft Entra ID for identity management across SaaS, cloud‑infrastructure, and internal applications (technology, finance, healthcare, retail, etc.).
Recommended Actions
- Run the Entra SMS/Voice Policy Scanner to inventory users still on telephony‑based MFA.
- Update IAM policies to require passkey enrollment for all accounts; document the policy change as part of your SOC 2 control evidence.
- Capture PowerShell script output and enrollment logs as audit artifacts for CC6 compliance.
- If phone‑based MFA is still required for legacy workflows, provision a third‑party telecom provider via the Microsoft Security Store and record the justification.
Source: BleepingComputer
Technical Notes – The rollout automatically prompts users of SMS/voice MFA to register a passkey on their next sign‑in. Microsoft cites AI‑enabled phishing campaigns with click‑through rates up to 54 % as the driver for this change. No new CVEs are disclosed; the change is a preventive control upgrade. Source: same as above