Microsoft Entra ID: Passkeys Become the Default in September 2026 — What Your Business Needs to Know

Microsoft just made a call that will land in every Microsoft 365 tenant sooner rather than later: passkeys are becoming the default authentication method in Microsoft Entra ID, and SMS and voice codes are being retired as native Entra capabilities in early 2027. If your business uses Microsoft 365 — and most do — this affects you.

Here’s the short version of the timeline Microsoft published:

  • September 1, 2026 — Microsoft begins rolling passkeys out as the default MFA experience in Entra ID. Users currently on SMS or voice will automatically be enabled for passkeys and prompted to register one the next time they sign in.
  • February 1, 2027 — Microsoft-provided SMS and voice authentication is retired. Organizations that still need text-message or phone-call codes will have to contract with a third-party telecom provider through the Microsoft Security Store, and pay separately for it.

“Passwords with a text-message code stopped being ‘good enough’ the moment AI-driven phishing kits started harvesting one-time codes in real time. Passkeys are the first MFA method built for the threat landscape we’re actually in.”

— Glenn Kupsch, President, Adaptive IT

Why Microsoft is doing this

SMS and voice codes were a huge step up from passwords alone, but they were never truly phishing-resistant. Attackers intercept text messages, socially engineer help desks into SIM-swapping numbers, and increasingly use AI-driven phishing kits that harvest one-time codes in real time. Microsoft Threat Intelligence says AI-assisted phishing campaigns are now hitting click-through rates as high as 54%, compared to about 12% for traditional phishing.

Passkeys sidestep the whole problem. They use public-key cryptography tied to a specific device, so there’s no shared secret to steal, no code to intercept, and no phone number for an attacker to hijack. They’re also faster for users — a face scan or fingerprint instead of waiting for a text and typing six digits.

What this means for your business

If your team signs in to Microsoft 365 with a text-message code today, that experience is going to change — and if you do nothing, it’ll change for you starting in September. A few things worth thinking about now:

  1. Inventory who’s still on SMS or voice. Anyone still using text-message MFA is on borrowed time and, more importantly, sitting on the weakest link in your security posture.
  2. Decide which passkey type fits your users. Entra supports synced passkeys (iCloud Keychain, Google Password Manager, etc.) that follow a user across their devices, as well as device-bound options like Microsoft Authenticator passkeys, Windows Hello, and FIDO2 security keys. Different roles may warrant different choices.
  3. Plan the rollout before Microsoft plans it for you. Automatic enrollment is convenient, but “surprise, you have a new sign-in method” is a support-ticket generator. A short user communication and a scheduled registration window prevents most of that noise.
  4. Update recovery paths. If SMS was your fallback for account recovery, that fallback is going away. Every user needs at least two working phishing-resistant methods.
  5. Budget for the exception cases. Shared mailboxes, service accounts, kiosk logins, and users without smartphones all need a plan. If you truly need SMS/voice after February 2027, you’ll be paying a third-party telecom for it.

The bigger picture

This is the direction the entire industry is moving. Google, Apple, and the FIDO Alliance have been pushing passkeys for years, and Microsoft flipping the default in Entra ID is the loudest signal yet that the password-plus-text-code era is ending. For most small and mid-sized businesses, the right move is to get ahead of the September rollout, not react to it after the first help-desk call.

Need help planning your passkey rollout?

If your business runs on Microsoft 365 and you’d rather not figure this out during the first Monday-morning support wave, Adaptive IT can plan and execute the passkey transition for you: audit your current MFA methods, pick the right passkey types for each group of users, set up a registration campaign, write the user comms, and clean up the edge cases (shared accounts, kiosks, users without smartphones). We do this every day so you don’t have to.

Contact us and we’ll walk through your tenant, flag the risky spots, and get a rollout on the calendar well before Microsoft’s September deadline.

Source: Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID (Microsoft Security Blog, July 13, 2026).

Adaptive IT

Russia’s Military Hackers Hijacked Home & Office Routers Across 23 States — Is Yours One of Them?

A unit of Russia’s military intelligence agency (the GRU group known as APT28 / Fancy Bear / Forest Blizzard — the same group behind the 2016 DNC hack) has been quietly compromising small-office/home-office (SOHO) routers across 23 U.S. states. The FBI disrupted the operation in April under court order, but the underlying vulnerabilities — outdated firmware and unchanged default passwords — are still sitting on thousands of devices waiting to be exploited again. Microsoft tied the campaign to more than 200 organizations and 5,000 consumer devices.

This was a DNS hijacking operation: the attackers changed the routers’ DNS settings so all internet traffic passing through the device got silently redirected through Russian-controlled servers. That gave them passive, persistent visibility into traffic and the ability to harvest credentials at scale. The router sits in the most privileged position on your network — every packet you send goes through it — which is exactly why nation-state actors keep going after them.

Why this matters for your business

The FBI specifically called out the TP-Link TL-WR841N, a Wi-Fi 4 router originally released in 2007. The UK’s National Cyber Security Centre published a broader list of 23 TP-Link models known to have been targeted (and warned the list is likely not exhaustive). TP-Link has confirmed every affected model is past End-of-Life — meaning no more security updates, ever.

If one of these devices is sitting in a closet at your office, the front door of your network is effectively unlocked. Every day it stays plugged in, the risk grows.

Affected routers

  • TP-Link LTE Wireless N Router [MR6400]
  • TP-Link Wireless Dual Band Gigabit Router [Archer C5, Archer C7, WDR3600, WDR4300]
  • TP-Link Wireless Dual Band Router [WDR3500]
  • TP-Link Wireless Lite N Router [WR740N, WR740N/WR741ND, WR749N]
  • TP-Link Wireless N 3G/4G Router [MR3420]
  • TP-Link Wireless N Access Point [WA801ND, WA901ND]
  • TP-Link Wireless N Gigabit Router [WR1043ND, WR1045ND]
  • TP-Link Wireless N Router [WR840N, WR841HP, WR841N, WR841N/WR841ND, WR842N, WR842ND, WR845N, WR941ND, WR945N]

If you’re running any of these in a business setting, treat it as compromised until proven otherwise. Replace the hardware and rotate any credentials that may have crossed that network — email, VPN, RDP, banking, anything sensitive.

Five steps everyone should take right now

  1. Replace any End-of-Life router. If your router stopped getting firmware updates, no amount of tweaking will keep it safe.
  2. Update firmware regularly on any router still receiving support — enable automatic updates if the option exists.
  3. Change default usernames and passwords. Default credentials are the single most common way attackers get in. Make the admin password long and random.
  4. Disable remote management unless you specifically need it. This is one of the primary ways attackers reach into a router from the internet.
  5. Reboot routers, computers, and phones at least weekly. Per the NSA: regular reboots help flush implants that live only in memory.

Running one of these in your business? We can help.

If your office is still running a consumer TP-Link (or any other End-of-Life router) for business traffic, Adaptive IT can replace it with enterprise-grade Ubiquiti UniFi equipment — managed switches, access points, and security gateways that get continuous firmware updates, give us central visibility into your network, and are built for business use, not a teenager’s bedroom in 2007.

If you suspect your network may have been touched by this campaign, we can also come in and investigate the damage: DNS log review, credential exposure assessment, lateral-movement checks, and cleanup of any persistence the attackers left behind. The longer you wait, the more time the attackers have to use whatever they harvested.

This is the kind of nation-state-grade attack where waiting and hoping is the most expensive option. Contact us for assistance and we’ll get a network audit on the books this week.

Source: Russia’s Military Hackers Targeted Home Routers Across 23 States. Here’s What to Do (Yahoo Tech / CNET).

Adaptive IT

Adaptive IT Protects Clients After GoDaddy Email Phishing Incident

A recent wave of sophisticated email phishing attacks targeting GoDaddy customers put many small businesses at risk — but Adaptive IT clients were protected. Here is what happened, how our team responded, and what every business owner needs to know to stay safe.

What Happened

Cybercriminals launched a targeted phishing campaign impersonating GoDaddy — one of the world largest domain registrars and email hosting providers. The fraudulent emails appeared to come from official GoDaddy addresses and prompted recipients to click a link to “verify their account” or “update billing information.” Those who clicked were directed to convincing fake login pages designed to steal credentials.

For businesses that rely on GoDaddy for domain registration or email hosting, this type of attack can result in domain hijacking, email account compromise, and significant business disruption. The consequences can be devastating — from lost email access to having your company domain redirected to malicious websites.

How Adaptive IT Protected Our Clients

Clients protected under our Managed Security services were shielded through multiple layers of defense that were already in place:

  • Email Security Filtering: Our advanced email security solutions flagged and quarantined suspicious messages before they reached employee inboxes.
  • Real-Time Threat Monitoring: Our Security Operations Center (SOC) identified the phishing campaign early and issued proactive alerts to clients.
  • Employee Awareness Training: Clients enrolled in our Cybersecurity Training program had already been trained to recognize exactly this type of phishing attempt.
  • Multi-Factor Authentication (MFA): Even in cases where credentials were inadvertently entered, MFA prevented unauthorized account access.

What Every Business Owner Should Do Right Now

Whether you are an Adaptive IT client or not, here are immediate steps you should take to protect your business from phishing attacks like this one:

  1. Enable Multi-Factor Authentication on all email accounts, domain registrar accounts, and critical business applications.
  2. Never click links in unsolicited emails — always navigate directly to the vendor website by typing the address in your browser.
  3. Verify suspicious emails by calling the company directly using a phone number from their official website.
  4. Train your team with regular phishing simulations so they can recognize and report suspicious emails.
  5. Deploy email security software that filters malicious emails before they reach your employees.

Do Not Wait for an Incident to Act

The GoDaddy phishing incident is a powerful reminder that cybercriminals specifically target small and medium-sized businesses — often because they lack the security layers that larger enterprises have in place. Adaptive IT exists to close that gap, bringing enterprise-grade security to businesses of every size at a price that makes sense.

If you are concerned about your current email security posture, or if you want to ensure your team is prepared to handle phishing attempts, contact Adaptive IT today for a free security assessment.

Call us: 877-958-1248 | Email: [email protected]