Microsoft is killing SMS codes for Microsoft account sign-in, aggressively pushes passkeys on Windows 11
AI-summarised brief · reviewed before publication
Microsoft is phasing out SMS codes for personal account sign-in, citing security concerns as the primary reason. The company will no longer send SMS codes for two-factor authentication and account recovery, instead transitioning to passwordless alternatives like passkeys, authenticator apps, and verified secondary email addresses. This change aims to address the vulnerability of text messages to interception and SIM-swap attacks. Microsoft believes the future of authentication is passwordless, secure, and user-friendly, with passkeys using device-built biometric hardware for authentication. The transition is part of Microsoft's effort to advance security standards and protect digital identities.
💡 Why It Matters
- · Microsoft's shift to passkeys tackles the inherent security flaws of SMS-based authentication, which has become a leading source of fraud.
- · By replacing SMS with passkeys, Microsoft significantly reduces the risk of phishing attacks and SIM-swap scams.