Microsoft Just Proved the Passwordless Argument

passkey mandate

Schedule a Portnox Cloud demo today.

Contents

Six years ago, Microsoft’s own identity security lead wrote a blog post telling the industry to hang up on phone-based authentication for good. It didn’t land the way you’d expect a warning from the company that built the world’s most-used identity platform to land. SMS codes stuck around. Voice calls stuck around. “It’s better than nothing” won the argument, quietly, for years — right up until this summer, when Microsoft stopped asking and started enforcing.

Starting February 1, 2027, SMS and voice one-time passcodes will no longer work as an MFA or first-factor sign-in method in Entra ID — for every tenant, with no opt-out. Global Administrators and external guest users get until July 1, 2027, but that’s a grace period, not an exemption. Passkeys have already been the default authentication experience for SMS/voice users since September 1, 2026. By the time enforcement hits, this won’t feel sudden to anyone who’s been paying attention. It’ll feel overdue.

The Argument Passwordless Advocates Have Been Making All Along

This is the same argument security teams have been making for years — Microsoft just stopped letting anyone ignore it. SMS and voice codes travel over infrastructure nobody who relies on them actually controls: a phone number can be SIM-swapped by convincing a carrier rep, a code can be relayed through a real-time phishing kit, a text can be intercepted at the network level. These are decade-old, well-documented failure modes, not edge cases.

What’s different now is who’s saying it, and how bluntly. Microsoft’s own documentation doesn’t hedge: SMS and voice verification remain vulnerable to phishing, interception, and social engineering, and simply don’t offer the security passkeys do. A competitor could say that and you’d file it under marketing. Coming from the vendor that built the feature, it reads more like a confession.

Why a Deadline Changes the Conversation

Security guidance without a deadline is a recommendation. Security guidance with a hard cutoff and no opt-out is a mandate — and mandates move budgets in a way “best practice” articles never quite manage. For years, the passwordless pitch has competed against inertia: SMS mostly works, migrating takes effort, there’s always a more urgent fire. Microsoft just removed “it mostly works” as an option.

That’s a meaningful shift for teams building their internal case. “Our MFA is weaker than it should be” is a hard argument to prioritize. “Our MFA stops functioning on a date the vendor already announced” is not.

What Microsoft Is Actually Asking For

The detail that matters most isn’t the deprecation — it’s what organizations are being asked to move to. Not a different flavor of one-time code, not a push notification. Passkeys: cryptographically bound to a device, resistant by design to phishing, replay, and SIM-swapping, because there’s no shared secret traveling over a network to intercept. That’s not a lateral move from SMS — it’s a categorically different model, and Microsoft is right to draw the line there.

One more thing worth saying: this isn’t really an AI story. Microsoft ties part of its reasoning to AI-accelerated attacks, but SIM-swapping and real-time phishing relays aren’t new tricks — they’re old ones, just faster now. Passwordless authentication was making this case long before “AI threat” showed up in anyone’s deck.

Deadlines like this don’t come along often in identity security, and they rarely come from the platform vendor itself. Whatever internal case you’ve been building for stronger authentication, Microsoft just handed you the closing argument.

Share

About the Author

Picture of Kate Asaff

Kate Asaff

Kate Asaff is a Technical Product Marketing Manager at Portnox with more than two decades of experience spanning networking, enterprise IT, and cybersecurity. Before moving into product marketing, she spent over 15 years at SolarWinds in technical support and program management, helping bridge the gap between engineering and the people who rely on technology every day. Today, she writes about network access control, zero trust, AI, identity security, and passwordless authentication for the practitioners who implement them.

About the Author

Picture of Kate Asaff

Kate Asaff

Kate Asaff is a Technical Product Marketing Manager at Portnox with more than two decades of experience spanning networking, enterprise IT, and cybersecurity. Before moving into product marketing, she spent over 15 years at SolarWinds in technical support and program management, helping bridge the gap between engineering and the people who rely on technology every day. Today, she writes about network access control, zero trust, AI, identity security, and passwordless authentication for the practitioners who implement them.

Related Reading

Artificial IntelligenceSecurity Trends

NVIDIA’s New Agent Watchdog Can Quarantine an Agent. It Can’t Revoke Its Credentials.

September 29, 2026
Network Access ControlNetwork SecuritySecurity Trends

Visibility Isn’t Control

September 28, 2026
Network Access ControlNetwork SecurityPortnox Product Release

Your Firewall Doesn’t Know Who 10.1.45.112 Is

September 24, 2026

Portnox Closes the Gap on Shadow AI

X