Publication Date
Identity Security Is Entering a New Era
At a Glance
- Passkeys are now the preferred method for securing identities because they ensure authentication is tied to the right service, the right device, and the right context.
- Compared to multi-factor authentication (MFA), passkeys are more secure, faster, and easier to use, while eliminating the risk of human error.
- Identity security should be incorporated into your processes at key moments, including onboarding, role changes, IT support interactions, etc.
Microsoft recently announced that it will soon discontinue SMS and voice call authentication in favor of passkeys. While passkeys are already the default authentication method in new Microsoft environments, legacy methods will be disabled starting February 1, 2027.
With so many authentication methods available, how can you ensure your accounts, users, and environments are properly protected? Here’s an overview of today’s best practices, according to our experts.
We rarely see a major vendor implement a change this decisively. Microsoft’s position sends a clear message: the level of risk associated with identities requires rapid action. SMS codes and voice-based authentication are no longer secure enough. Today, cyberattacks increasingly target users themselves, and mechanisms such as passkeys significantly reduce the risks associated with password theft, phishing, and social engineering. Passkeys strengthen security without requiring users to become cybersecurity experts.
Is Your Identity Management Actually Protecting You?
While multi-factor authentication (MFA) was until recently considered sufficient to provide a strong level of security, modern attacks can intercept authentication processes and use them for phishing purposes. Certain Adversary-in-the-Middle attacks attempt to trick users into authenticating through malicious infrastructure and then steal the resulting session. The solution is no longer simply adding another authentication step. Instead, organizations must prioritize authentication methods that are tied to the right service, device, and context.
MFA remains far superior to relying solely on passwords, but the authentication method itself must evolve.
Why Should You Adopt Passkeys Quickly?
Passkeys provide a modern way of proving identity without transmitting a password or reusable code to a website. For users, the experience often resembles unlocking a phone or computer using facial recognition, a fingerprint, a local PIN, or confirmation on a trusted device.
Behind the scenes, passkeys rely on a pair of cryptographic keys, making them highly resistant to phishing attacks:
- The private key remains securely stored on the user’s device or within a compatible credential manager.
- The public key is stored by the service, preventing sensitive authentication information from being provided to fraudulent websites.
Passkeys offer several advantages over other authentication methods:
- Enhanced security
- Elimination of human error
- Faster and simpler sign-in experiences
Examples of Passkeys
- Passkeys in Microsoft Authenticator: A familiar mobile-based option that many organizations can integrate into their security strategy.
- Windows Hello for Business: Authentication through facial recognition, fingerprint, or a device-bound PIN on a corporate device.
- FIDO2 Security Key: A physical device, typically USB or NFC-based, particularly useful when employees cannot use personal mobile devices.
When Was the Last Time You Reviewed Your Identities?
Microsoft’s shift toward passkeys highlights a broader reality: protecting digital identities should become an organizational reflex.
“Identity management is a lifecycle and should never be treated as a one-time project. Identity security must follow employees throughout their entire journey within the organization. It depends not only on technology, but also on human resources, governance, training, and day-to-day operations.”
– Alexandre Lusignan, Director, Consulting Services, Modern Workplace
Ask yourself: when do you review user identities and access rights?
Key Moments in the Identity Lifecycle
- During onboarding: Register a strong authentication method when accounts are created, before access is granted to data and applications.
- During role changes: Strengthen authentication requirements when employees gain additional privileges or access to more sensitive information.
- During IT support interactions: Verify identity before performing resets, ensuring that support processes do not become security bypasses.
- During offboarding: Revoke active sessions, remove registered authentication methods, and quickly disable access.
Moving to passkeys is an opportunity to modernize your foundation. Organizations that act now can turn a technical deadline into a lasting improvement to their security posture. Those that wait may find themselves managing the transition under pressure, when legacy methods no longer satisfy security requirements or platform support expectations.
MFA adds an important layer of protection compared to passwords alone, but it still exposes organizations to risks stemming from human behavior.
If change management is a concern within your organization, keep in mind that once configured, passkeys typically provide a faster sign-in experience than traditional MFA.
In Microsoft Entra, you can invite targeted users to configure a passkey or Microsoft Authenticator during the sign-in process.
Avoid starting with all users at once. Begin by testing devices, backup methods, support procedures, and selected user groups.
Ideally, implementation should be part of a broader action plan that starts with an inventory of authentication methods currently authorized and used across the organization.
No. MFA remains essential, but not all forms of MFA offer the same level of protection. The objective is to move away from authentication factors that can be phished and toward methods that are inherently resistant to phishing.
Not necessarily. Number-matching notifications improve security, but organizations must verify whether users truly have access to phishing-resistant authentication methods and whether SMS authentication is still being used for SSPR (Self-Service Password Reset) or account recovery.
Take This Opportunity to Modernize Your Identity Management
Microsoft’s announcement may be the catalyst, but the challenge goes far beyond any single vendor or product. Identities are the primary gateway to your data, applications, and operations. Protecting them requires stronger authentication methods, but also consistent processes, a well-designed user experience, and shared accountability across the organization.
Need Guidance?
Our experts can help you transition to passkeys and effectively integrate identity security into your business processes: