
Episode 433: Passkeys, Passwords, and the End of SMS MFA
Welcome to Episode 433 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben and Scott discuss how Microsoft 365 authentication is moving from “make passwords safer with MFA” to “remove phishable authentication wherever possible.” The practical conversation for IT pros is no longer just whether MFA is enabled. It is which methods are allowed, which users are still on SMS or voice, how passkeys change the user experience, and how to balance security, accessibility, recovery, and support load.
Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options.
Show Notes
- Passkeys were supposed to replace passwords, but they’re failing for the most predictable reason
- Microsoft Entra authentication overview
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Plan a phishing-resistant passwordless authentication deployment in Microsoft Entra ID
- Run a registration campaign to set up a passkey or Microsoft Authenticator
- Practical Protection: Understanding Entra ID and Passkeys
- Important Change Coming for Entra ID Passkeys in November 2025
- Microsoft to Stop Providing Telephony-Based Authentication Methods for MFA in February 2027
- How to enable passkeys (FIDO2) in Microsoft Entra ID
Sponsors
Nasuni is a leading unstructured data platform for enterprises where file data is mission-critical for both people and AI. Nasuni powers the operational file layer where work happens — helping organizations manage, protect, and activate data so teams can work smarter, reduce costs, and operate securely without limits.
Intelligink — Would you like to become the irreplaceable Microsoft 365 resource for your organization? Let us know!
More episodes from "Microsoft Cloud IT Pro Podcast"



Don't miss an episode of “Microsoft Cloud IT Pro Podcast” and subscribe to it in the GetPodcast app.








