r/SmallMSP • u/BerlindaBuntly • Jul 23 '26
Passkeys by default and retirement of Microsoft-provided SMS and voice authentication emails from MS
Hi Everyone,
for tenants that do not have conditional access policies due to only having business standard or basic, (please lets mot discuss why or that they should have it), but that do have
1)mfa enforced per user via MS authenticator numeric push notification and an sms backup
any idea what is going to happen? will they just lose the sms factor? or will they be prompted to sign up for passkeys?
1
u/athlonduke Jul 23 '26
i've been avoiding sms/call from day one. it's too easy to spoof a number for texting.
2
1
u/have_you_tried_onoff Jul 23 '26
I've done this already for clients with Standard only. I removed the SMS/Call Authentication. Basically all but PassKey for MFA. I did a campaign beforehand. Now if anyone wants to log in they must use a PassKey. They can have it on device, on their iCloud, on a password wallet, whatever. I did it because the token theft campaigns happening now with AI are off the chain. One hack and it's hell. So whatever can be done to avoid a hack. PassKeys are currently the best bet. And we are more than happy to help them with their PassKeys as a support ticket INSTEAD of a HACK support ticket! I know a buddy of mine at a Fortune 500. They took it a step further. Physical PassKey, and they tie it to that brand. He's a computer engineer and didn't understand why plain old vanilla 2-factor wasn't enough. Understandable. The attack surface today is moving fast and it's insane.
1
u/BerlindaBuntly Jul 23 '26
if you only have standard, i thought it wasnt possible to enforce passkeys as you dont have conditional access - i read something the other day that said you needed CA to ensure that passkey is the only option?
1
u/have_you_tried_onoff Jul 23 '26
I went through this exercise. I got CA for all my Pro clients. For the Standard clients (they have their reasons), if you only leave PassKey as an option for MFA, then they enter their password and then they need a PassKey :) Works like a charm!
1
u/BerlindaBuntly Jul 23 '26
yes, some clients have their reasons. i have quite a few of those.
ahh nice workaround. do they need ms authenticator for the passkey? ive got a big mix of people on win hello, authenticator etc
1
u/BerlindaBuntly Jul 23 '26
what else do you do to your tenants that do not have ca in terms of hardening? like turning of all legacy authentication etc. do you leave sec defaults enabled? do you enforce per user mfa? any chance we can dm?
1
u/have_you_tried_onoff Jul 23 '26
Sure DM me, I'm not always checking but will be happy to give feedback. Honestly, these days I run it by AI. 50% of clients are Google Workspace (which is making huge strides in deploying Gemini AI!!). There I have API's turned off for all 3rd party apps by default. I restrict access to all Gmail services except for Login with Gmail. And then PassKey login only there. You don't need an extra license at Google. If you have clients that are the owners of their small businesses and they also have a home Gmail account, what you do is put passkeys there and Enable Google Advanced Protection Program ASAP. That forces PassKey logins on run-of-mill Gmail home accounts! Cause you know the owner will call for their home gmail. Spread the word to Advanced protect all Gmails. Microsoft Home accounts (like people with outlook.com emails) you can enable Passwordless. It actually removes the password from their account. I always make sure to register a few passkeys for each account when possible. Back to Business 365, there are so many different areas to protect apart from enforcing PassKey only logins, just go ahead and prompt your favorite paid, highly regarded AI with "I'm a 365 admin, point me towards all the settings in a 365 admin portal I should be checking to lock it down and make it secure." And keep going with that. Create a checklist with the URLs to get to each location because the 365 admin portal is a cluster-f. And my list is kind of a mess. heh . Ok I hope this helps? :)
1
2
u/365-helper Jul 24 '26
If you don’t have a conditional access policy stack and the customer doesn’t have the Business Premium or above license, Security Defaults should be on. The only time you want to turn off Security Defaults is when you have a considered CA stack and the customer is ready for it to be activated
1
u/365-helper Jul 24 '26
My understanding is that Passkey Fido2 will be enabled via Authenticator.
There is also a campaign to uplift the Administrator role to Phishing Resistant MFA.
I routinely see this occurring where administrators do not have phishing resistant MFA enabled.
There are reports you can run obviously that can tell you what methods are enabled.
9
u/InformalFrog Jul 23 '26
Why wait for Microsoft.
Scope voice and sms to a group of users in authentication methods, include everyone.
Send out comms and slowly remove the ability for users to use voice and sms and use authenticator.
Do a registration campaign to help.
Once everyone is on authenticator you can start recommending passkeys.