<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v" -->

---
title: Microsoft nudges enterprise security closer to its...
description: As of September 1, passkeys became the default authentication method for Microsoft Entra ID, with Microsoft-provided SMS and voice authentication set to be...
canonical: https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive. | daily.dev
og:description: As of September 1, passkeys became the default authentication method for Microsoft Entra ID, with Microsoft-provided SMS and voice authentication set to be...
og:url: https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v
og:image: https://api.daily.dev/og/posts/gLjw3UX4v.png
og:image:alt: Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.

**[CSO Online](https://daily.dev/sources/csoonline)** · 6 min read · 0 upvotes · 0 comments

## Summary

As of September 1, passkeys became the default authentication method for Microsoft Entra ID, with Microsoft-provided SMS and voice authentication set to be discontinued by February 1, 2027. Security experts broadly welcome the push toward passwordless authentication for its phishing resistance, but warn that legacy applications, account recovery complexity, ecosystem lock-in, and cross-platform fragmentation mean most enterprises will run a hybrid password-plus-passkey model for the foreseeable future rather than eliminating passwords outright.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4215429/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive.html>

## Questions this post answers

### When did Microsoft make passkeys the default authentication method for Entra ID?

Passkeys became the default authentication method for Entra ID, Microsoft's cloud-based identity and access management service, starting September 1. Microsoft-provided SMS and voice authentication will be discontinued entirely by February 1, 2027, pushing enterprises toward passwordless sign-in for cloud application access.

_daily.dev helps identity teams track Entra ID authentication changes as they plan passkey rollouts._

### Why aren't passkeys a complete replacement for passwords in enterprise environments yet?

Passkeys struggle with legacy on-premise infrastructure, custom internal applications, and niche industrial workflows that rely on older authentication protocols. Additional blockers include account recovery complexity, compliance concerns over binding corporate credentials to personal consumer ecosystems like Apple ID or Google accounts, and fragmentation across platforms that makes cross-device passkey use inconsistent.

_security teams weighing passwordless migration strategies can follow enterprise authentication coverage on daily.dev._

### How should CISOs approach rolling out passkeys across an organization?

A phased rollout is recommended, starting with pilot groups or specific applications before expanding broadly, rather than attempting a full migration at once. Experts advise aggressively deploying passkeys for modern cloud apps for an immediate security boost while keeping phishing-resistant MFA or hardware tokens active as a bridge for legacy systems that can't yet support passkeys.

_daily.dev keeps CISOs current on passkey rollout strategies and identity management best practices._

## Similar posts on daily.dev

- [Microsoft to roll out Entra passkeys on Windows in late April](https://daily.dev/posts/microsoft-to-roll-out-entra-passkeys-on-windows-in-late-april-dcryfhs6k) · BleepingComputer · 0 upvotes · 0 comments
- [Microsoft is scrapping SMS 2-factor authentication because it's "a leading source of fraud"](https://daily.dev/posts/microsoft-is-scrapping-sms-2-factor-authentication-because-it-s-a-leading-source-of-fraud--o0ddh501l) · XDA Developers · 7 upvotes · 10 comments

---

Tags: [#cloud](https://daily.dev/tags/cloud), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing), [#passkeys](https://daily.dev/tags/passkeys)

[View this post on daily.dev](https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.","url":"https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v"},"datePublished":"2026-09-01T08:27:51.710Z","dateModified":"2026-09-01T09:08:24.521Z","description":"As of September 1, passkeys became the default authentication method for Microsoft Entra ID, with Microsoft-provided SMS and voice authentication set to be...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a034e872c96df9b5cbc4829d785ceda5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a034e872c96df9b5cbc4829d785ceda5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cloud,authentication,phishing,passkeys","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive."}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/microsoft-nudges-enterprise-security-closer-to-its-passwordless-future-but-123456-will-survive--gljw3ux4v#faq","mainEntity":[{"@type":"Question","name":"When did Microsoft make passkeys the default authentication method for Entra ID?","acceptedAnswer":{"@type":"Answer","text":"Passkeys became the default authentication method for Entra ID, Microsoft's cloud-based identity and access management service, starting September 1. Microsoft-provided SMS and voice authentication will be discontinued entirely by February 1, 2027, pushing enterprises toward passwordless sign-in for cloud application access. daily.dev helps identity teams track Entra ID authentication changes as they plan passkey rollouts."}},{"@type":"Question","name":"Why aren't passkeys a complete replacement for passwords in enterprise environments yet?","acceptedAnswer":{"@type":"Answer","text":"Passkeys struggle with legacy on-premise infrastructure, custom internal applications, and niche industrial workflows that rely on older authentication protocols. Additional blockers include account recovery complexity, compliance concerns over binding corporate credentials to personal consumer ecosystems like Apple ID or Google accounts, and fragmentation across platforms that makes cross-device passkey use inconsistent. security teams weighing passwordless migration strategies can follow enterprise authentication coverage on daily.dev."}},{"@type":"Question","name":"How should CISOs approach rolling out passkeys across an organization?","acceptedAnswer":{"@type":"Answer","text":"A phased rollout is recommended, starting with pilot groups or specific applications before expanding broadly, rather than attempting a full migration at once. Experts advise aggressively deploying passkeys for modern cloud apps for an immediate security boost while keeping phishing-resistant MFA or hardware tokens active as a bridge for legacy systems that can't yet support passkeys. daily.dev keeps CISOs current on passkey rollout strategies and identity management best practices."}}]}
```

