Microsoft Kills SMS MFA in Entra ID The Shift to Phishing-Resistant Passkeys Begins.
Microsoft to Phase Out SMS and Voice MFA on Entra ID in Favor of Phishing-Resistant Passkeys Microsoft has announced a major paradigm shift in enterprise identity security: the gradual retirement of SMS and Voice Call-based One-Time Passwords (OTPs) for Multi-Factor Authentication (MFA) across Microsoft Entra ID (formerly Azure AD). In its place, Microsoft is pushing Passkeys built on FIDO2/WebAuthn open standards as the new default, elevating organizational security to a Phishing-Resistant baseline. The decision stems from inherent cryptographic and architectural vulnerabilities in telecom-based authentication, such as SIM-swapping attacks, SS7/telecom interception, and adversary-in-the-middle (AiTM) phishing . By contrast, Passkeys bind authentication directly to the specific web domain and device, making them immune to standard credential-harvesting attacks. Enforcement & Transition Timeline Microsoft has outlined a multi-phase deprecation schedule to give IT administrat...