Why is Microsoft forcing me to use a passkey?

As we mentioned in our last article, passkeys are rapidly becoming the default authentication option in Microsoft Entra ID. The total retirement of Microsoft-provided SMS and voice-based MFA is set for February 1, 2027. However, a quick scroll through Microsoft’s support forums reveals this transition is not as smooth as we had hoped it to be. Everyday users are feeling blindsided, with many echoing the sentiment: "I was opted into this without my knowledge or without understanding how it works." Meanwhile, IT professionals argue that for users who already rely on strong, unique passwords alongside TOTP (Time-Based One-Time Passwords) via an authenticator app, a forced shift to a device-bound passkey feels like a step backward in security—and a massive leap forward in user friction.


Are Authenticator Apps Enough?

Power users often point out that a complex password stored in a vault plus a code generator app provides strong security. However, traditional multi-factor authentication is not automatically phishing-resistant.

Passkeys rely on the FIDO2 standard and public-key cryptography. The passkey is generated and stored locally in your device's hardware vault (the TPM) and never leaves it. When you log in, the device signs a mathematical challenge using a PIN or biometrics. Most importantly, passkeys are mathematically bound to the legitimate domain (e.g., login.microsoftonline.com). If a user is tricked into visiting a fake site, the passkey will not release the credentials. The cryptography protects the account, removing the need for the user to identify sophisticated phishing attempts.

The Rollout and User Experience The current frustration stems from how Microsoft is introducing the change. Users receive mandatory setup prompts immediately after authenticating with their existing methods, which disrupts their workflow. Additionally, using terms like "Passkeys," "Windows Hello," and "FIDO2" interchangeably confuses non-technical users about how their login works and what happens if their device breaks. While home users have workarounds, enterprise users on Entra ID must comply with the new requirements.
Preparing Your Organization for the 2027 Deadline Relying on Microsoft's automated prompts to migrate your employees will increase IT support tickets and lead to user lockouts by the February 2027 deadline. Organizations should manage the migration proactively:

  • Communicate early: Explain the upcoming changes and the security reasons behind them before users encounter the mandatory Microsoft prompts.

  • Provide hardware alternatives: Device-bound passkeys require smartphones or company laptops with biometric sensors. Hardware FIDO2 security keys (USB or NFC), such as the SpearID FIDO2, provide the exact same phishing resistance for users who cannot or prefer not to use personal devices.

  • Pre-register credentials: IT teams can seamlessly pre-register FIDO2 security keys in Microsoft Entra ID using SpearID Now before issuing them to employees, ensuring they are ready to plug in and use immediately.

  • Define the credential process: Establish clear procedures for how keys are distributed, how to replace lost devices, and how to instantly revoke access when an employee leaves the company. This entire lifecycle can be managed centrally using the SpearID One identity server.

Next
Next

Microsoft is retiring SMS and voice-based MFA: now is the time to move to phishing-resistant authentication