Microsoft mandates passkeys for Entra ID as legacy MFA faces retirement
Microsoft is transitioning its Entra ID enterprise identity platform to default to passkeys by September 2026, with the total retirement of legacy SMS and voice authentication services set for February 2027. This industry-wide shift toward phishing-resistant authentication frameworks directly impacts how media organizations secure their internal tools and CIAM infrastructure.
Key Takeaways
- September 1, 2026: Passkeys become the default Entra ID authentication experience with automatic registration nudges.
- February 1, 2027: Native SMS and voice authentication services will be fully retired within Microsoft Entra ID.
- Organizations requiring legacy telecom-based MFA must configure third-party providers via the Microsoft Security Store by October 2026.
- Microsoft reports AI-enabled phishing click-through rates reaching 54%, significantly outpacing the 12% average for traditional campaigns.
- Passkey users demonstrate sign-in speeds 8x faster than traditional MFA with a 98% success rate compared to 32% for passwords.
Why It Matters
The immediate move to phishing-resistant MFA shifts basic security from an optional configuration to a mandatory baseline for enterprise identity stacks. For the streaming ecosystem, this transition directly impacts internal production tools, developer environments, and content management systems where credential theft often leads to high-value leaks. Media organizations must now reconcile this workforce-level security push with their broader Customer Identity and Access Management (CIAM) strategies, where consumer friction remains a hurdle. Watch for the September 18, 2026, release of Microsoft's technical documentation for third-party telecom integration to see how organizations handling legacy device fleets navigate the post-SMS era.
Additional Context
The push for passkeys stems from a broader industry alignment to eliminate phishable factors. While Microsoft accelerates its enterprise timeline, consumer-facing giants like Amazon, Apple, and Google have been expanding FIDO-based support since 2022. Per the FIDO Alliance May 2026 report, over 5 billion passkeys are now in active use globally, with 48% of the top 100 websites offering them—a figure that has doubled since 2022. This momentum is further bolstered by the National Institute of Standards and Technology (NIST), which released the second public draft of its Digital Identity Guidelines (SP 800-63-4) in late 2024. These guidelines formalize 'syncable authenticators' and urge a pivot away from SMS codes, which NIST now classifies as restricted and unsuitable for high-assurance levels due to vulnerability to interception. In the media and entertainment sector, passkey adoption has historically lagged behind fintech and e-commerce. According to 2026 industry benchmarks from Dashlane and MojoAuth, active passkey usage in media sits at approximately 18%, compared to nearly 60% in fintech. This discrepancy is largely attributed to the technical complexity of implementing cryptographic sign-ins across fragmented Connected TV (CTV) environments. However, streaming providers are under pressure to act as they execute password-sharing crackdowns. Per Live Mint and Forbes reports from late 2025, Amazon Prime Video and Disney+ have increasingly linked identity security to account-sharing controls, with Amazon reporting that it accounted for 80% of brand impersonation attacks in late 2025. By making passkeys the default, Microsoft is forcing a standard that media organizations must eventually mirror at the consumer level to maintain parity between workforce security and subscriber account integrity.
Read full article at forrester.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source