Back to Opinion Articles
Opinion #004•4 min read•11 August 2026 , Tuesday

The Password Is Dying — And That's Probably a Good Thing

Microsoft just gave Entra ID users who still rely on SMS or voice authentication a hard deadline to stop typing in codes sent by text message. The stated reason isn't convenience — it's that AI has made humans the easiest part of the system to fool.

Rajnish Kumar

Rajnish Kumar

Editor-in-Chief & Founder

The Password Is Dying — And That's Probably a Good Thing — Opinion article hero image

The Deadline Nobody Asked For

Starting 1 September 2026, Microsoft Entra ID will make s the default authentication experience for users currently enabled for SMS or voice — automatically enabling them for passkey registration and prompting them during sign-in, not forcing an instant switch. Microsoft says more information on customer-managed telecom providers will be available for review from 18 September, and beginning 30 October, organizations that genuinely need to keep SMS or voice will be able to select and configure one of those providers through Microsoft's Security Store. Then, on 1 February 2027, Microsoft's own SMS and voice authentication stops working entirely. There is no opt-out from that February enforcement itself — anyone still relying on it alone gets a blocking prompt demanding a passkey before they can sign in again.

Why a Text Message Was Never That Safe

None of this is really about text messages suddenly becoming dangerous — they always were. SIM swapping lets an attacker convince a carrier to move a victim's number onto a new SIM, silently rerouting every code meant for them. The SS7 protocol that routes phone traffic globally has known interception weaknesses that don't require touching the victim's phone at all. And plenty of "-protected" accounts have fallen to nothing more sophisticated than a fake login page that asks for the code the moment the real one arrives, then relays it before it expires. None of this needed artificial intelligence. It just needed patience, and there was always someone willing to supply it.

What Actually Changed Is the Economics

Passwords and SMS codes aren't disappearing because they're outdated — they're disappearing because humans have always been the weak point, and attackers finally have the tooling to exploit that at scale. AI has made voice phishing more convincing, more scalable, and cheaper to operate — cloning a voice now takes a few seconds of public audio, enough to hold a real-time conversation convincing enough to talk someone through reading out a code they were never supposed to share. Session-hijacking phishing kits do the same thing to login pages: sit invisibly between a victim and the real site, forward the traffic in both directions, and simply wait for a human to finish authenticating on the attacker's behalf. Microsoft's own justification for retiring SMS and voice is unusually blunt about this — it isn't that these methods are old, it's that they can't stop an attacker who's automated the one job a human used to be needed for: getting fooled.

What a Passkey Actually Changes

A passkey replaces "a secret you type" with a cryptographic key pair your device generates and never lets leave it. Signing in means your device proves it holds the private half of that pair — it never transmits anything a phishing site could steal or a human could be tricked into reading aloud. The part that actually matters here is narrower and more mechanical than most explanations make it sound: a passkey is bound to the exact origin it was created for, and the browser enforces that binding, not the user. A cloned voice can talk someone into reading out a code. It cannot talk a browser into handing a credential to a domain that doesn't match. That's not a bigger password — it's a different category of thing to attack.

The Catch Nobody's Advertising

Here's what gets left out of most of the celebration: passwords had an ugly but real safety net — forget one, and a reset link fixes it. Lose every device holding your passkeys, and there's no equivalent. A passkey's private key genuinely never leaves the hardware it was generated on, which is exactly what makes it unphishable and exactly what makes losing that hardware a real problem. The practical fix — Apple's iCloud Keychain, Google's Password Manager, Microsoft's own sync — backs passkeys up to the cloud so a lost phone doesn't mean a lost identity. But that fix works by making your access to everything depend on staying logged into one company's account. A suspended Google account, an Apple ID under review, a Microsoft account flagged by an automated system — any of those stops being an inconvenience and starts being the single point of failure for every account tied to it. Critics have been blunt about what this actually is: not just a security upgrade, but a deeper coupling of your digital identity to whichever platform you happened to pick.

So Is This Actually Progress?

Genuinely, yes — and the numbers back it up better than the marketing does. The FIDO Alliance puts active passkeys at roughly five billion worldwide in 2026, with three in four consumers having enabled one somewhere and nearly half using them regularly. Closer to home, Visa launched its Payment Passkey in India in July 2026 with IDFC FIRST Bank as its first issuing partner — built on the same FIDO standards, and aligned with the RBI's own September 2025 framework pushing Indian digital payments past OTPs entirely. This isn't a vendor experiment being forced on a reluctant public; it's a shift that was already happening, and Microsoft's deadline mostly just formalizes where the puck already went.

The Part Worth Remembering Before You Migrate

"Passwordless" was never the same promise as "risk-free," and it's worth being honest about which risk actually got traded for which. The old failure mode was a memory an attacker could extract from a person. The new one is a device — and the account that resurrects it when the device is gone — that now has to be protected instead. That's a smaller, better-shaped problem than the one it replaces. It just isn't a solved one, and anyone migrating this year deserves to hear that part too, not just the deadline.

Sources

The factual claims and data points in this article are traceable to the sources below. They are linked here rather than woven inline, so the argument reads clean and the underlying information stays checkable.

Found this useful? Share it