Passkeys Are Becoming the Default — Why Small Businesses Should Stop Treating SMS Codes as Strong Security

Passkeys Are Becoming the Default — Why Small Businesses Should Stop Treating SMS Codes as Strong Security

For years, businesses were told to turn on two-factor authentication, and many did exactly that by adding a six-digit SMS code. That was a major improvement over passwords alone, but attackers adapted. They learned to steal codes through phishing pages, SIM attacks, social engineering, adversary-in-the-middle kits, and convincing “security verification” calls. In September 2026, Microsoft began making passkeys the default authentication experience for eligible Entra ID users, another sign that the industry is moving away from authentication methods people can be tricked into handing over.

What Microsoft Changed

Microsoft’s Entra documentation says users enabled for SMS or voice authentication began being nudged toward passkey registration on September 1, 2026. Microsoft plans to retire its own native SMS and voice delivery for most Entra users in 2027, while organizations with specific requirements can use other providers. The company’s stated goal is to move organizations toward phishing-resistant authentication methods such as passkeys, Windows Hello for Business, and FIDO2 security keys.

Why Passkeys Resist Ordinary Phishing

A passkey is based on public-key cryptography and is associated with the legitimate website or service. Microsoft’s consumer guidance notes that a passkey created for one domain is not presented to a look-alike phishing domain. That removes one of the attacker’s favorite tricks: convincing a user to type a secret into the wrong page. There is no reusable password or six-digit code for the fake site to collect and immediately replay.

Attackers Are Already Adapting to the Passkey Transition

Security improvements do not make social engineering disappear. Microsoft published September research describing attackers using passkey-themed lures and account-recovery tactics in real cloud compromises. The lesson is important: an attacker may not be able to steal the cryptographic passkey itself, so they may instead trick a victim into registering an attacker-controlled authentication method, approving a device flow, or surrendering access through another route. Employees still need a trusted way to verify unexpected security prompts.

Start With the Accounts That Could Ruin Your Week

A small business does not have to convert every login in one afternoon. Start with email administrators, domain registrars, website hosting, banking and payment systems, password managers, cloud storage, accounting, social-media administration, and any account capable of resetting other accounts. Those are the keys to the kingdom. If passkeys or hardware security keys are available, use them and keep recovery options documented rather than relying on one employee’s phone.

Keep Recovery From Becoming the Weakest Link

Strong primary authentication is useless if account recovery only requires answering a weak question or convincing support to change the phone number. Review recovery email addresses, backup codes, secondary administrators, old phone numbers, departed employees, and emergency procedures. Store recovery codes securely offline or in an approved password manager. Test the process before an emergency so the first time anyone discovers it is not while the business email account is under attack.

Do Not Confuse Convenience With Carelessness

Passkeys are designed to be easier as well as safer, but businesses still need device security. Lock computers and phones, keep operating systems updated, use disk encryption, protect biometric unlock, and remove access promptly when a device is lost or an employee leaves. The authentication system may be phishing-resistant while the unlocked laptop sitting in a truck is not.

Bottom Line

SMS two-factor authentication is still better than a password alone, but it should no longer be the finish line. Microsoft’s September passkey rollout reflects a broader move toward authentication that cannot simply be typed into a fake login page. Small businesses should use the transition as an excuse to inventory their most important accounts, enable phishing-resistant sign-in where available, and fix recovery procedures before an attacker tests them first.

Valhalla Content Forge — consistent monthly content plans for small businesses

Leave a Reply

Your email address will not be published. Required fields are marked *