Jump to content

Passkeys by default and retirement of Microsoft SMS and voice authentication


Recommended Posts

Posted

Hi All,

 

I thought it would be interesting to see what people are assessing the impact to them will be.

 

I know we've got a few people who rely on SMS/Voice for various reasons (of varying validity!).

The vast majority of our users use authenticator push notifications. I've not given it enough (any) thought yet to see how these users might be impacted and what training and actions we'll need to put in place, if anything.

 

Thanks,

Posted

I'm aiming to push our users towards passkeys as quickly as we can. We've had multiple successful phishing attacks despite authenticator based MFA.

 

Issues for us (not a school):

1) A mostly universal solution for an alternative second factor when they lose/change/forget/drown their phone 

 

2) An option for people who want to login to desktop computers that they haven't used before, e.g. presenting at a venue that has a PC as part of the hosts AV setup. 

 

There's a third internal issue for us: the team that runs the tenancy is not the team that runs active directory. I haven't yet persuaded them to talk to each other and run the command that will allow it as authentication for logins to domain PCs.

 

Posted

Good luck getting the different departments to talk. 

 

What’s you preferred form factor for storing passkeys?

Posted

Happily, we banned SMS and voice auth more than a year ago and moved the handful of SMS users to a physical token or an authenticator app.

 

The interesting part comes when the (token-using) person needs N+1 authenticators for different work-related websites that can't use an existing source of truth.

 

You can get physical tokens that can hold N+1 authenticators (https://www.token2.com/products/token2-molto-1-i-multi-profile-totp-hardware-token) but setup isn't straightforward for an end-user.

Posted
23 minutes ago, gsk said:

Good luck getting the different departments to talk. 

 

What’s you preferred form factor for storing passkeys?

Most people use laptops and for the last four years I've specified fingerprint readers and most of the new ones have Windows Hello capable cameras, so for convenience I think most people will have a passkey on their main device. I have one on my phone in the MS Authenticator app which I find works well. 

 

The user experience with a hardware token on the machine you're logged in on is much better than even simple passwords. I'm sure it'll be broken at some point but I think they're a genuine upgrade for users and admins.

Posted
3 hours ago, jmak said:

Most people use laptops and for the last four years I've specified fingerprint readers and most of the new ones have Windows Hello capable cameras, so for convenience I think most people will have a passkey on their main device. I have one on my phone in the MS Authenticator app which I find works well. 

 

The user experience with a hardware token on the machine you're logged in on is much better than even simple passwords. I'm sure it'll be broken at some point but I think they're a genuine upgrade for users and admins.

I’d like to understand this better. So you issue them with a laptop, they enrol into windows hello on that device and then what’s the process to get them using passkeys on there? 

Posted
On 11/08/2026 at 23:06, gsk said:

I’d like to understand this better. So you issue them with a laptop, they enrol into windows hello on that device and then what’s the process to get them using passkeys on there? 

When you go to enrol or use a passkey on a website, it just asks for your WHfB credentials (e.g. PIN, Face, Fingerprint).

 

Entra will enrol the passkey automatically, so you won't need to manually enrol for any services with SSO.

Posted
13 minutes ago, itskdog said:

When you go to enrol or use a passkey on a website, it just asks for your WHfB credentials (e.g. PIN, Face, Fingerprint).

 

Entra will enrol the passkey automatically, so you won't need to manually enrol for any services with SSO.

How is this looking/working across multiple devices. One of my biggest frustrations with WHfB is that it doesn’t sync those authentication methods back to entra so that you can enrol a face onto one laptop and then log in on another laptop without re-enrolling. 

Posted
29 minutes ago, gsk said:

How is this looking/working across multiple devices. One of my biggest frustrations with WHfB is that it doesn’t sync those authentication methods back to entra so that you can enrol a face onto one laptop and then log in on another laptop without re-enrolling. 

 

WHfB is bound to the device, they can use their password still on other devices.

 

So far only my machine has WHfB enabled, to test. Haven't done a wider rollout as so many devices are shared.

Posted

@itskdog Once you setup the WHfB passkey, do you see it as one of your authentication methods on the Security info section on your account? We have rolled out WHfB but with the SMS depreciation happening soon, we are not sure if staff can only have WHfB it looks like they will also need another form i.e a passkey in the authenticator app. So we have to target getting those with SMS and those with only SMS + WHfB

Posted
2 hours ago, itskdog said:

 

WHfB is bound to the device, they can use their password still on other devices.

 

So far only my machine has WHfB enabled, to test. Haven't done a wider rollout as so many devices are shared.

How does they passkey situation work if you log in on another device?

Posted
2 hours ago, itskdog said:

 

WHfB is bound to the device, they can use their password still on other devices.

 

So far only my machine has WHfB enabled, to test. Haven't done a wider rollout as so many devices are shared.

Also, what method are you using to target WHfB? I’d like to target it to users rather than devices if possible. 

Posted
2 hours ago, gsk said:

Also, what method are you using to target WHfB? I’d like to target it to users rather than devices if possible. 

 

Disabled in the enrollment configuration and also on a default policy that applies to all devices (with the WHfB device group excluded), then a second policy that enables it, targeting the same group, and a third custom policy to disable Post-logon provisioning (as that CSP is not in the Settings Catalog).

 

I'm sure if you used a user group instead, and the User version of the policies rather than the Device version, it might work.

Posted

Oooh disabling the post-login provisioning would be good. With the result being that users can enrol to WHfB but aren’t prompted to?

 

Any chance of sharing that custom policy please?

Posted

How are you managing to get students/parents to move over to the Authenticator app?

 

I would say the vast majority of students/parents use SMS when accessing emails etc off site (despite info being sent out for MS Authenticator)

Posted

^ Most students who have the Bromcom MIS app on their phones also have the Outlook Mobile app on their phones (due to *interesting* design choices in the initial authentication setup for the student MIS app).

 

Outlook mobile can function as a (not particularly great) second factor.  If it's working, great.  If it breaks and it's the only second factor it's annoying to resolve compared to standard MFA reset.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...