- From 1 September 2026, access keys will become the standard for Entra ID
- Microsoft is withdrawing text/phone call authentication from February 1, 2027
- Victims are more likely to open AI-assisted phishing emails
Microsoft has confirmed plans to make access keys the default or preferred authentication method for Entra ID starting September 1, 2026, and is announcing additional changes to account authentication in an effort to combat sophisticated attacks.
A few months later from February 1, 2027, the company will also stop providing its own SMS and voice call authentication codes for Entra ID in the hope that business users will fully adopt the password-less login.
While passkeys don’t promise to stop attacks entirely, they make phishing attempts far less effective because attackers would need access to victims’ hardware to gain access.
Microsoft continues its drive for access keys
While the company may end support for its own SMS and phone call authentication methods, passkeys won’t be the only login method after the change. Windows Hello for Business (biometrics) and FIDO2 security keys will e.g. still be available.
“The AI era demands stronger, phishing-resistant authentication,” a company announcement seen by Windows Latest reader. “We’re making access keys the default authentication experience in Microsoft Entra to help customers securely deploy AI at scale.”
While AI hasn’t exactly made attacks better at breaking through traditional authentication methods, it has made attacks more convincing. According to the company’s own data, the click-through rate for phishing emails is 54% for AI-assisted campaigns, compared to just 12% for conventional ones.
As more people open up malicious links, the effects worsen, hence the pressure to improve overall security.
Looking forward, Microsoft’s proposed plan for affected organizations includes identifying users who still use SMS/voice authentication, planning an enterprise-wide rollout of access keys, and keeping employees updated.
“SMS and voice have served their purpose well, bringing multi-factor authentication to billions of users who would otherwise have had none,” Microsoft concluded, declaring that “the threat environment has evolved beyond their capabilities.”
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



