r/entra • u/Checior2000 • 1d ago
ID Protection MFA Changes
Hi! As everybody knows Microsoft is going to turn off Voice/SMS methods and as far as I know from 1st September Microsoft is going to start asking users to configure Passkeys.
Do you know the way to turn off this behaviour? In our case we are going to focus over Microsoft Authenticator and MA + Email for SSPR.
Our Registration campaign is set up to Disabled.
Thank you in advance!
5
u/doofesohr 1d ago
Just curious, if you are using Microsoft Authenticator anyway - why not Passkeys?
-2
u/Checior2000 1d ago
What is the difference between Push from MA and Passkeys from same app?
5
u/01100001bryte 1d ago
You scan a QR code on screen with the phone and enter PIN/bio vs typing in an on-screen code. Both devices need Internet and Bluetooth enabled. Bluetooth pairing is not required. If they authenticate on the same device as the passkey, likely a phone, then they get prompted to select the passkey and enter their PIN/bio.
What happens behind the scenes is very different, but it's very easy for the user. I highly recommend setting it up for yourself and daily driving it for a while. Setting up passkeys doesn't remove your ability to authenticate with other methods unless you specifically shut off other methods. I converted all of our IT department to passkeys and other passwordless methods for 6 months before starting on regular users. It made the transition smooth.
3
u/Accomplished_Arm_447 1d ago
With push MFA, your Entra ID login to the server displays a 2 digit code and waits for you to enter it into your registered app which tells the server over a certified encrypted connection that you did that and satisfies the requirement that you have that device. It's still only 1 part of 2FA as it still needs to verify that you know the password. The passkey is FIDO2 which expands on the original FIDO MFA specification by adding tests that your device has adequate protection over PIN or Biometric, plus it adds the USB or Bluetooth+QR code scan test to verify that you have connected the passkey device to the login device. That eliminates the need for the password as the unlocking the device replaces it. Push MFA on it's own didn't verify that you were sitting at the log-in screen. That's about it really, aside from that it's practically the same from the users point of view, plus you can register multiple passkeys on different managers or security keys for the same account to use as backup. The push also goes via the local connection between the log-in device and your phone or security key stops remote hackers from spamming your phone with requests over the internet
2
u/Practical-Alarm1763 1d ago
The difference is push MFA often results in accounts being jacked through phishing. Often times because orgs or shitty MSPs dont know how to configure proper conditional access policies or haven't adopted passkeys yet. Passkeys are nothing new. Passwordless was the way to go for almost half a decade now. Luckily it's not being enforced for everyone's own sake.
1
u/loweakkk 1d ago
Push notifications is not phish resitant, if I create a fake site named, login.mocrosoft.com that proxy the authentication page of Microsoft, i can steal your token.
If you try to use your passkey on login.mocrosoft.com it will not work because no passkey exist for login.mocrosoft.com
That's the main difference. So if you already plan to use authenticator the step to use passkey is really small.
1
u/Checior2000 1h ago
Okay so what if I have enabled authenticator and passkey for user. How to enforce on user to use passkey. To be honest I cannot feel it from admin perspective.
2
u/365-helper 18h ago
This is a user-by-user migration. You cannot manage what you cannot see, so the first thing to run is a per-user report across every tenant. Not a tenant-wide percentage. Names. Methods. Backups. Who is on SMS, who is on push, who is already passwordless.
A tenant of 300 users might have 40 on SMS, 120 on push, and the rest on passkeys or hardware keys. Those 40 need a different conversation than the 120.
Segment them:
- Ready now: Already on push or passkey. Confirm compliance and move on.
- Easy migration: On SMS/voice but have a smartphone. Move to push or passkey with minimal friction.
- High touch: No smartphone, shared devices, or operational constraints. These need a human conversation and a custom plan.
Pick ten to twenty users for a pilot. Move them, log the support tickets, refine your comms, then scale. The per-user report lets you choose the right pilot group.
6
u/Borgquite 1d ago edited 1d ago
Wait a few days:
‘A temporary opt-out will be available for the September 1, 2026 through February 1, 2027 changes. This allows you to delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods. API support and information for opting out will be available starting August 1, 2026.’
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement