Passkeys are soon to be the default authentication method in Entra ID. At the start of 2027, SMS MFA is no longer included within Entra ID. The winds of change are moving through authentication in Entra, but what does this all really mean?
In this session, we’ll dive into what passkeys have looked like across the enterprise, giving you a taste of what’s ahead.
We’ll explore why enablement of passkeys is great, but without enforcement, attackers will shift, as we’ll explore downgrade attacks and how they can bypass passkeys. We’ll take a look at what the rollout experience was like from the admin and end-user perspective, the technical and business challenges faced, and how we solved them. We’ll take a look at the debate of device-bound vs synced passkeys, covering the technical and operational pros and cons in a Microsoft ecosystem. And speaking of a Microsoft ecosystem, we’ll examine if Active Directory is really a blocker to their enablement. The session will wrap with an exploration of other adjacent technologies needed to bring an enterprise fully phishing-resistant – changing up your Conditional Access policies for Identity Protection, and the challenges and adoption of technology like Verified ID and self-service account recovery.