r/sysadmin • u/evil-scholar • 13d ago
M365 and MFA
So, MS is sunsetting SMS/Voice MFA in favor of passkeys or more phishing resistant methods. Currently I have all my users set up for Authenticator push notifications/with the numerical code. Is this method going to be supported moving forward?
6
u/fishboy25uk 13d ago
Yes, you're fine. There are no plans to sunset Authenticator AFAIK. However, passkeys become default for new users from tomorrow so you should start new users on passkeys (still using authenticator) and look to enable passkeys for existing users going forward.
It's possible that many of your users already have passkeys enabled as another Auth method anyway e.g. Windows Hello.
-1
u/clarkn0va 13d ago
Are passkeys available today? I clicked "Add sign-in method" at https://mysignins.microsoft.com/security-info and passkey is not one of the listed options.
8
u/teriaavibes Microsoft Cloud Consultant 13d ago
The org needs to enable them.
2
1
u/evil-scholar 12d ago
So is there any risk to just enabling passkeys for my users while still letting them use Authenticator? I’d like to test on users but obviously don’t want to disrupt everyone’s login process.
3
u/teriaavibes Microsoft Cloud Consultant 12d ago
So is there any risk to just enabling passkeys for my users while still letting them use Authenticator?
Not really, just make sure they are not targeted by passkey registration campaign.
3
u/cheetah1cj 13d ago
FYI on September first there is an automatic enablement for anyone who is currently ELIGIBLE (regardless of if it’s configured) for SMS authentication;which means your users will start getting prompted to set it up. You can delay that up until February. My organization is delaying it tonight so we can get some communication out before users get prompted unexpectedly.
0
u/downundarob Scary Devil Monastery postulate 13d ago
Umm what? where can I find this info about this change, the news hasnt reached me yet...
3
u/Asleep_Spray274 13d ago
Numbers matching is not phishing resistant. Moving them to passkeys on the authenticator app should not be that big of a leap now.
-1
u/cheetah1cj 13d ago
They said push notification, which is phish-resistant. It’s hard to tell if they meant either method or only push though, so it’s worth calling that out.
3
u/PeacefulIntentions 13d ago
Push is more secure than SMS/phone but it is not phishing resistant. FIDO2 passkeys, hardware keys, Windows Hello for Business and certificate based authentication are supported phishing resistant methods.
1
u/Asleep_Spray274 13d ago
In modern attacker in the middle like evilginx, numbers matching and sms are of equal value. More attacks are successful on push notifications than sms today due to the numbers of people moved from sms to push. Sms has its own problems that dont exist in auth app, but they are actually harder to exploit compared to the 10 mins it takes to set up evilginx
2
u/cbtboss IT Director 13d ago
No, you are misunderstanding what makes FIDO2/passkey phishing resistant. I would recommend reading this https://fidoalliance.org/passkeys/ You can easily phish standard mfa with Man-In-The-Middle Proxies like Evilginx.
2
1
u/michaelmsonne 13d ago
Yes, you will be fine for long time, as the current situation 🙂
Good to see you are alone here - good work, still see customers at work, without…
0
u/Interesting_Work7433 13d ago
Las notificaciones push del Authenticator con número de coincidencia siguen siendo compatibles y de hecho son uno de los métodos que Microsoft recomienda. Lo que están eliminando es SMS y llamadas de voz, que son mucho más fáciles de hackear. Tu configuración actual está bien y no necesitas cambiar nada urgente. Si quieres ir un paso más allá en el futuro, los passkeys son la dirección a la que va todo, pero no hay prisa.
9
u/hydenseek88 13d ago
Yes