The FAQ needs expanding, lower level of detail. Big risk I can see right now (on paper). User has only SMS as MFA, ignores pressure to move to passkey as they have CA trusted IP location excludes for MFA prompt. Deadline comes in Feb and goes. User signs in to Entra on new mobile device which would normally prompt for SMS. No SMS is sent, but instead a registration prompt to enrol to passkeys appear. If this is the case, in effect some form of MFA was actually removed as protection. Hacker know the userid and pass - as such they could not register passkey instead! Slight mitigation if CA policy set to restrict registration, but 95% people do not have thus CA.
How does Microsoft envision organizations handling the transition for users who aren't issued corporate phones and refuse to use their personal devices for authentication? Furthermore, for frontline or restricted-environment workers who physically cannot carry a phone, FIDO2 security keys become the only viable option. Are there any upcoming plans to improve the lifecycle management and at-scale provisioning of FIDO2 keys in Entra to better support these mandatory use cases as SMS and Voice retire?
Will/when will Microsoft provide a way for tenants to estimate costs associated with current SMS/Voice MFA usage? We have hundreds of users using SMS+Hello or SMS+PSSO but we assume they're almost never prompted for SMS.
1. What sort of due diligence should customers be performing on passkey providers? For synced passkeys most users will likely use Apple or Google password manager, but should businesses be performing deeper assessments on other password managers users may use? 2. To help customers assess the effectiveness of registration campaigns will Microsoft be providing any audit log events to indicate when a user sees but skips a passkey registration nudge?
Does the passkey registration campaign only targets user accounts with SMS/voice auth methods registered? Or instead, is it any user account targeted by the authentication methods policy for SMS or Voice call?
Also what about users who have SMS/voice registered but also have other (more secure) methods. Will they get nagged?
@Ben Seaba Its for all users who are enabled for SMS or voice call (users doesn't need to be registered for them) Source - MS Learn page: https://learn.microsoft.com/en-us/entra/identity/authenticat…
Will the SMS retirement include External ID, which already provides so few options? Removal of SMS from External ID would leave only email OTP and passkeys which is particularly restrictive for customers
For customers who have already committed to and prepaid a 2–3 year Enterprise Agreement, should they not be allowed to continue using SMS services until their current EA term expires?
How would you expect companies to handle frontline workers without any company device ?
Should synced passkeys be the default recommendation? (given their reliance on the security of a 3rd party mobile/byod ecosystem)?
When will attestation for windows hello authenticator passkeys be supported (seems overdue if attestation and passkeys are mainstream best practice)?
Why was the timeline of February 21, 2027 chosen as the enforcement date? For large companies with large user bases impacted, this timeline is very aggressive and the has risk of causing major disruption in the business.
With Microsoft making passkey the default for MFA registrations, what about companies that have MS Authenticator configured for passwordless as the default. Why can’t companies continue to use a default like this that does meet the requirement to move away from SMS/Voice factors for their MFA instead of forcing them to a passkey default that doesn’t meet their requirements.
Are the accounts that has a utilize Microsoft Authenticator without passkey affected by this change?
1. What does MSFT Entra telemetry show for passkey adoption? 2. Timeline for them to be superseded by Verifiable Credentials 3. Is MSFT seeing uptake in FLW scenarios -Questions from Darren Robinson
There's no mention on how this affects External MFA methods-- will they get tagged too? We currently use Duo Security with some SMS users (also being phased out), is Duo reporting that they are performing SMS for MFA, even though it's outside of Microsoft? Will we have control over who gets tagged and who doesn't?