Microsoft Makes Passkeys the Default Login for Business Accounts. Passwords Aren't Dead Yet.
From September 2025, Microsoft's business identity system defaults to passkeys instead of passwords. But experts say the shift will take years to complete, and most companies will run both systems side by side for a long time.

Key points
- As of 1 September 2025, Microsoft Entra ID, the cloud-based system companies use to manage who can log in to what, now defaults to passkeys instead of passwords.
- Microsoft will switch off its SMS and voice verification options entirely by 1 February 2027.
- Passkeys use built-in phone or laptop security (a fingerprint, face scan, or PIN) instead of a typed password, making them very hard to steal via fake websites.
- Security experts say a full switch away from passwords is unrealistic for most businesses right now; a slow, mixed rollout is the practical path.
- Employees who lose their device face a new headache: recovering a corporate login that is tied to a personal phone or account.
Microsoft has quietly crossed a significant line. Since 1 September 2025, any new account on Microsoft Entra ID, the service large organisations use to control employee access to apps and data, now relies on a passkey rather than a traditional password by default. Voice call and text-message verification codes will disappear from the platform entirely by February 2027.
What is a passkey, and why does it matter?
A passkey replaces the typed password with a small piece of encrypted code stored on your device, unlocked by your fingerprint, face, or a PIN you only use locally. Nothing gets typed into a website. Nothing travels across the internet that a criminal could intercept or reuse.
That design is what makes passkeys phishing-resistant. Phishing is the scam where criminals send fake emails or build fake websites to trick people into typing their passwords. With a passkey, the device checks that it is talking to the real website before it does anything, so a fake site gets nothing useful. The UK's National Cyber Security Centre backs the technology for exactly this reason.
Jason Soroko, senior fellow at digital-certificate company Sectigo, puts it plainly: traditional passwords, even with a second verification step, are still vulnerable to AI-assisted phishing and to criminals stuffing stolen password lists into login pages at scale.
Should ordinary employees be worried about losing access?
Yes, and this is the part the glossy announcements tend to skip. If a passkey lives on your personal iPhone or Google account and you get locked out of that account, recovering your work login becomes a real problem for both you and your IT department.
Dray Agha, senior manager of security operations at Huntress (a company that monitors business networks for threats), calls Microsoft's move a "tipping point" but is direct about the catch: handing key-recovery to Apple, Google, or Microsoft shifts the security burden while binding corporate access tightly to consumer platforms.
Cross-platform use is another gap. A passkey created on an iPhone does not move smoothly to a shared Windows desktop yet. Until that plumbing works reliably, some employees will find the experience frustrating.
How should companies actually roll this out?
The honest answer, based on what multiple security specialists told CSO Online, is: slowly and in stages.
| What to do first | Why |
|---|---|
| Deploy passkeys for cloud apps (Microsoft 365, Salesforce, etc.) | Quickest security gain; these apps already support the standard |
| Keep hardware security keys or app-based codes for older internal systems | Legacy software often cannot handle passkeys at all |
| Run a small pilot group before a company-wide switch | Finds problems before they hit everyone |
| Build a phishing-resistant account-recovery process | The recovery step is where weaker security can sneak back in |
| Phase out text-message codes before the 2027 deadline | SMS codes are easily intercepted; get ahead of the cut-off |
For bespoke internal software, factory-floor systems, or older applications that predate modern web standards, passkeys simply will not work today. A hybrid approach, where modern cloud tools use passkeys and older systems use other strong methods, is not a compromise. It is the only realistic plan.
The failure mode here is treating Microsoft's default change as a finish line rather than a starting gun, shipping passkeys to the CEO's laptop and leaving a thousand legacy apps running on passwords nobody reviews.
Operational takeaway: map every application your staff logs in to before you touch authentication settings, because the apps that cannot do passkeys will tell you exactly where the passwords will survive.



