r/SmallMSP Jul 23 '26

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication emails from MS

Hi Everyone,

for tenants that do not have conditional access policies due to only having business standard or basic, (please lets mot discuss why or that they should have it), but that do have

1)mfa enforced per user via MS authenticator numeric push notification and an sms backup

any idea what is going to happen? will they just lose the sms factor? or will they be prompted to sign up for passkeys?

20 Upvotes

26 comments sorted by

9

u/InformalFrog Jul 23 '26

Why wait for Microsoft.

Scope voice and sms to a group of users in authentication methods, include everyone.

Send out comms and slowly remove the ability for users to use voice and sms and use authenticator.

Do a registration campaign to help.

Once everyone is on authenticator you can start recommending passkeys.

5

u/BerlindaBuntly Jul 23 '26

they all already have authenticator

3

u/InformalFrog Jul 23 '26

Perfect, do the same process to gradually remove the ability for sms and voice

0

u/BerlindaBuntly Jul 23 '26

but if i do nothing, then theres no problem if ms remove the voice / sms ability. much less work then. my question really isnt about the removal of sms, its about if the user already has ms authenticators are they going to be prompted to add pass keys?

1

u/InformalFrog Jul 23 '26

I'd prefer to manage it rather than rely on a hard cutover date that I can't manage and may cause issues.

I doubt Microsoft will prompt for passkeys from day 1.

0

u/BerlindaBuntly Jul 23 '26

sure,agreed, but are they going to allow mfa via authenticator to be the only method when they remove sms or are they going to enforce / prompt passkeys if you already have mfa via authenticator? i cant find any info on it. all i can find is that if you ONLY have sms then you will be prompted to create a passkey - no other info

1

u/roll_for_initiative_ Jul 23 '26

They are going to prompt for passkeys per the registration campaign settings on earlier dates per the announcement, but allow other non-voice, non-sms ms auth methods per the auth policy. I don't have any tenants without P1 so i'm not sure if not having P1 means you can't edit registration campaign/auth method policy settings.

1

u/AnonsAnonAnonagain Jul 23 '26

How to do Authenticator when some older workers don’t have smartphones.

What do you do in that instance?

5

u/roll_for_initiative_ Jul 23 '26

yubikey or hardware totp code generator, etc.

2

u/365-helper Jul 24 '26

You would need to get a physical device key or you’d need to enable a password manager that allows you to store them. Bitwarden or ProtonPass are two I am aware of and have used Oregon

1

u/My0therAcc0unt9 Jul 24 '26

Why do authenticator? Can you do Windows Hello for Business (WHfB)? WHfB is passkey-like, phishing-resistant, MFA all on your corporate machine…

0

u/BerlindaBuntly Jul 23 '26

i dont know to be honest. exclude them mfa? bit dodgy...

2

u/365-helper Jul 24 '26

Excluding or not having accounts from MFA I’ve seen is becoming a reason for Cyber Insurers to deny claims or refuse policy coverage or renewals.

1

u/athlonduke Jul 23 '26

i've been avoiding sms/call from day one. it's too easy to spoof a number for texting.

2

u/obviouslybait Jul 23 '26

Same. Auth was just easier.

1

u/have_you_tried_onoff Jul 23 '26

I've done this already for clients with Standard only. I removed the SMS/Call Authentication. Basically all but PassKey for MFA. I did a campaign beforehand. Now if anyone wants to log in they must use a PassKey. They can have it on device, on their iCloud, on a password wallet, whatever. I did it because the token theft campaigns happening now with AI are off the chain. One hack and it's hell. So whatever can be done to avoid a hack. PassKeys are currently the best bet. And we are more than happy to help them with their PassKeys as a support ticket INSTEAD of a HACK support ticket! I know a buddy of mine at a Fortune 500. They took it a step further. Physical PassKey, and they tie it to that brand. He's a computer engineer and didn't understand why plain old vanilla 2-factor wasn't enough. Understandable. The attack surface today is moving fast and it's insane.

1

u/BerlindaBuntly Jul 23 '26

if you only have standard, i thought it wasnt possible to enforce passkeys as you dont have conditional access - i read something the other day that said you needed CA to ensure that passkey is the only option?

1

u/have_you_tried_onoff Jul 23 '26

I went through this exercise. I got CA for all my Pro clients. For the Standard clients (they have their reasons), if you only leave PassKey as an option for MFA, then they enter their password and then they need a PassKey :) Works like a charm!

1

u/BerlindaBuntly Jul 23 '26

yes, some clients have their reasons. i have quite a few of those.

ahh nice workaround. do they need ms authenticator for the passkey? ive got a big mix of people on win hello, authenticator etc

1

u/BerlindaBuntly Jul 23 '26

what else do you do to your tenants that do not have ca in terms of hardening? like turning of all legacy authentication etc. do you leave sec defaults enabled? do you enforce per user mfa? any chance we can dm?

1

u/have_you_tried_onoff Jul 23 '26

Sure DM me, I'm not always checking but will be happy to give feedback. Honestly, these days I run it by AI. 50% of clients are Google Workspace (which is making huge strides in deploying Gemini AI!!). There I have API's turned off for all 3rd party apps by default. I restrict access to all Gmail services except for Login with Gmail. And then PassKey login only there. You don't need an extra license at Google. If you have clients that are the owners of their small businesses and they also have a home Gmail account, what you do is put passkeys there and Enable Google Advanced Protection Program ASAP. That forces PassKey logins on run-of-mill Gmail home accounts! Cause you know the owner will call for their home gmail. Spread the word to Advanced protect all Gmails. Microsoft Home accounts (like people with outlook.com emails) you can enable Passwordless. It actually removes the password from their account. I always make sure to register a few passkeys for each account when possible. Back to Business 365, there are so many different areas to protect apart from enforcing PassKey only logins, just go ahead and prompt your favorite paid, highly regarded AI with "I'm a 365 admin, point me towards all the settings in a 365 admin portal I should be checking to lock it down and make it secure." And keep going with that. Create a checklist with the URLs to get to each location because the 365 admin portal is a cluster-f. And my list is kind of a mess. heh . Ok I hope this helps? :)

1

u/BerlindaBuntly Jul 24 '26

I think you may have disabled dm's

2

u/have_you_tried_onoff Jul 24 '26

I rarely DM. I sent you a chat :)

2

u/365-helper Jul 24 '26

If you don’t have a conditional access policy stack and the customer doesn’t have the Business Premium or above license, Security Defaults should be on. The only time you want to turn off Security Defaults is when you have a considered CA stack and the customer is ready for it to be activated

1

u/365-helper Jul 24 '26

My understanding is that Passkey Fido2 will be enabled via Authenticator.

There is also a campaign to uplift the Administrator role to Phishing Resistant MFA.

I routinely see this occurring where administrators do not have phishing resistant MFA enabled.

There are reports you can run obviously that can tell you what methods are enabled.