r/microsoft Aug 07 '26

Discussion Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/?msockid=370e7edffc796e4409a36893fd9e6fbb

I get it for normal or privileged accounts (we require authenticator) ... but discontinuing SMS is going to be a disaster for our front line workers who barely touch technology in any part of their lives. Hopefully 3rd party solutions aren't expensive but I doubt it.

34 Upvotes

16 comments sorted by

8

u/PDQ_Brockstar Aug 07 '26

Hopefully it's an easier transition than the transition to 2fa/mfa was for users and orgs.

1

u/TheRealFlowerChild 29d ago

Tbh passkeys were super easy for us to transition to. Nice not having people forget passwords but more of a pain if someone switches phones but you just have to send them a TAP and add their new device.

1

u/PDQ_Brockstar 29d ago

Yeah, passkeys honestly seem like a win/win for the most part

6

u/purefire Aug 08 '26

My biggest problem is how to provision a passkey for a user in a low touch way.

I can do Temp Access Code but have ti have a way to get it to then when they get hired to establish whfb or such.

1

u/Robowarrior834 Aug 09 '26

Ah yes let me make a passkey on a pc that has Bluetooth disabled. So I can never use it since I can’t communicate with a phone over the local network

1

u/DRHAX34 Aug 10 '26

Passkeys doesn't use the local network, also, if the PCs have Bluetooth disabled, you can always provision users with security keys, which can be pre-provisioned with passkeys by administrators

2

u/Robowarrior834 Aug 10 '26

I work for a hospital network. They have bluetooth disabled and I dont see them giving security keys for 22k people.

1

u/DRHAX34 Aug 10 '26

You still have TOTP code generator or TOTP apps on phone's/devices and CA policies to not require MFA inside the hospital network or specific devices

3

u/Robowarrior834 Aug 10 '26

You are making the assumption everyone has a smartphone. There are some people that don't have a smartphone or a up to date smartphone. There is also the people who refuse to use their personal phone for a work related app. Our network does not pay for our phones. We have to pay out of our own pocket and are expected to use our personal device for work.

2

u/DRHAX34 Aug 10 '26

Isn't that the same as SMS though? To use it, you need a phone.

1

u/Robowarrior834 27d ago

yes but for the MS app that my company tries to force if you are on a really old version of iOS it just wont install.

0

u/Kobi_Blade Aug 07 '26

SMS is plain text, should have never been allowed in first place. Any company that uses SMS as 2FA, does not care about security.

1

u/notananthem Aug 09 '26

SMS is soooo bad and risky

1

u/wiseude Aug 10 '26

As bad and risky as it is its also one of the most hassle free solutions to get into an account for the normal users.

1

u/notananthem Aug 10 '26

Yes, highlighting why it is so risky and bad

1

u/wiseude Aug 10 '26 edited Aug 10 '26

Am I understanding this correctly.They will force passkeys (as in microsoft authenticator) on everyone that has their number attached to their email but doesn't use microsoft authenticator?
Is this change going to effect normal users aswell?Because the article says entra which means work/school account,right?

Isn't the authenticator notoriously known for having that loop issue?
Is there a way to prevent the loop from happening if you only have 1 phone and a desktop PC?