Microsoft Making Passkeys the Default for Microsoft Accounts and Phasing Out SMS Authentication

Microsoft Making Passkeys the Default for Microsoft Accounts and Phasing Out SMS Authentication

Microsoft says they'll soon stop sending SMS codes for authentication for personal Microsoft accounts and will transition to "passwordless accounts, passkeys, and verified email."

SMS multi-factor authentication is a common way companies try to secure online accounts. The idea is that only you have access to your phone number, so only you should have access to any code sent there.

However, SMS was never designed to be secure. It's unencrypted so an attacker could intercept the message before it even gets to you. SIM swap attacks, where criminals transfer your number to a SIM card they control, can give them full control of all accounts that use SMS MFA. SS7 attacks can allow attackers to reroute your SMS messages by exploiting a protocol from the 1970's.

It's a wonder then that companies still insist on pushing SMS MFA as a secure option to lock down your accounts, sometimes even forcing you to give your phone number and allowing it to override your password and other authentication measures.

That's not to mention the privacy issues involved with providing your phone number to every account you have, something that doesn't change very often and is likely tied to your real-life identity.

Microsoft is finally looking to remove SMS authentication entirely from their accounts and embracing passkeys as an alternative to passwords:

SMS-based authentication is now a leading source of fraud, and by moving to passwordless accounts, passkeys, and verified email, we're helping you stay ahead of evolving threats while making account access simpler and more seamless.

Part of the reason why companies continue requiring things like SMS and email authentication is so you can still get into your account if your forget your password. Passkeys by default in most password managers sync and back up into the cloud, so you don't need to worry about forgetting a password.

Disappointingly, Microsoft is still requiring an email on signup. For now, both email account recovery and SMS account recovery are still available. Email isn't much better than SMS for authentication, itself being unencrypted (at least the account recovery emails are).

When I tried making an account, they actually tried to make me have two emails tied to my Microsoft account. Pretty ridiculous in my opinion.

Microsoft don't say if they'll eventually phase out passwords in the future, just that the plan is to make passkeys the default for now.

Community Discussion