Microsoft's decision to make passkeys the default authentication method in Entra ID is a significant shift in the company's approach to identity security. This move, announced by Nadim Abdo, Corporate Vice President of Identity and Network Access Engineering, reflects a broader industry trend away from text message and voice-based checks, which security specialists have long viewed as weaker than methods based on cryptographic credentials. Personally, I think this is a smart move by Microsoft, as it addresses the evolving threat landscape and the limitations of traditional multifactor authentication methods. What makes this particularly fascinating is the company's focus on the threat environment, especially the use of AI by attackers to improve phishing and social engineering campaigns. In my opinion, this is a critical issue that needs to be addressed, and passkeys offer a more secure alternative. One thing that immediately stands out is the fact that Microsoft is ending its own telecom delivery for SMS and voice authentication, shifting customers to third-party providers available through the Microsoft Security Store. This raises a deeper question: how will this impact the security of users who still rely on these methods for regulatory, technical, or business reasons? From my perspective, this is a necessary step to ensure the security of users, but it also highlights the need for organizations to carefully consider their authentication strategies and the potential risks associated with older methods. The migration path to passkeys is well-defined, with clear dates and fallback options during migration. This is a positive development, as it ensures a smooth transition for most customers. However, it also raises the question of how organizations will manage the transition for users who still rely on SMS or voice for regulatory, technical, or business reasons. What many people don't realize is that passkeys are designed to resist phishing because they use public-key cryptography rather than shared secrets. This is a key advantage over traditional methods, which are more vulnerable to interception and manipulation. The data from Microsoft Threat Intelligence supports this, showing that AI-enabled phishing campaigns can reach click-through rates as high as 54%, compared with about 12% for more traditional campaigns. This increases the risk associated with stolen passwords and second factors that can be intercepted or manipulated. A detail that I find especially interesting is the fact that compromised identities can now allow attackers to automate discovery, privilege escalation, and lateral movement far faster than would be possible through manual intrusion. This is a significant threat, and the shift to passkeys is a necessary step to address it. In conclusion, Microsoft's decision to make passkeys the default authentication method in Entra ID is a smart move that addresses the evolving threat landscape and the limitations of traditional multifactor authentication methods. However, it also raises important questions about the security of users who still rely on older methods and the need for organizations to carefully consider their authentication strategies. If you take a step back and think about it, this is a critical issue that needs to be addressed, and passkeys offer a more secure alternative.