azureblog.co.uk
← cd ~/learn
// learning path · intermediate

Passwordless rollout

Move users from passwords and text messages to passkeys, from the first sign-in to retiring SMS.

0 of 6 read · about 14 minutes in total
start with part 1 →
  1. 01Temporary Access Pass: onboarding users without a passwordA Temporary Access Pass lets a new starter, or someone who's lost their phone, sign in once and set up a passkey or Authenticator. No temporary passwords sent by email.2 min✓ read
  2. 02Synced passkeys and passkey profiles are now GA in Entra IDEntra ID now supports passkeys stored in password managers and phone platforms, and lets you set different passkey rules for different groups. Here's how to use both sensibly.2 min✓ read
  3. 03System-preferred authentication now picks the first factor tooUsers with a passkey may now sign in without being asked for a password at all, and registration campaigns can prompt for passkeys. Two changes that quietly push tenants towards passwordless.2 min✓ read
  4. 04Authentication strengths: requiring the right kind of MFARequiring MFA treats an SMS code and a passkey as equals. Authentication strengths let you say which methods are good enough for which resources.2 min✓ read
  5. 05Microsoft Authenticator now blocks jailbroken and rooted devicesAuthenticator now refuses to add or use work and school accounts on jailbroken or rooted phones. There's nothing to configure, but your service desk should know.2 min✓ read
  6. 06Microsoft is retiring its own SMS and voice MFA. Here's your plan.Microsoft-provided text and phone call authentication in Entra ID ends for most users on 1 February 2027. Passkeys are already being switched on. What changes, when, and what to do now.4 min✓ read

Progress is saved in this browser only. A post counts as read once you've scrolled most of the way through it.