Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method
🚨 The Signal: Users can now register phishing-resistant passkeys or passwordless Authenticator as their first MFA method. This simplifies onboarding to strong authentication, eliminating the need for weaker initial methods and improving overall security posture.
The Impact
Identity and security administrators are affected by improved user onboarding, reducing the risk of initial reliance on weaker MFA methods.
- Identity Administrators: Simplified user onboarding for strong authentication.
- Security Administrators: Reduced risk from users initially registering weaker MFA methods.
- New Users: Easier adoption of phishing-resistant sign-in methods.
- Existing Password-Only Users: Direct path to strong, passwordless authentication.
The Action
- Review Microsoft Entra ID Authentication Methods policy to ensure FIDO2 Security Keys and Microsoft Authenticator are enabled.
- Communicate the simplified passkey/passwordless registration process to users and helpdesk staff.
- Update user onboarding documentation to reflect the direct path to phishing-resistant MFA.
- Monitor user adoption of passkeys and Authenticator passwordless sign-in via Entra ID sign-in logs.
Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907