Welcome to the Identity Theft Resource Center's “Weekly Breach Breakdown” for Aug. 7, 2026. I'm Alex Achten, vice president of media relations for the ITRC. Thanks to Sentilink for supporting the ITRC and this podcast. Each week, we review the latest events and trends in data security and privacy. This week, we will discuss some major Microsoft updates.

Show Notes

Follow on LinkedIn: linkedin.com/company/idtheftcenter/
Follow on Instagram: instagram.com/idtheftcenter/
Follow on Facebook: facebook.com/IDTheftResourceCenter/
Follow on X: twitter.com/IDTheftCenter
Follow on TikTok: www.tiktok.com/@idtheftcenter_
Follow on YouTube: www.youtube.com/@IDTheftCenter

Show Transcript

Out of sight, out of mind…it’s a saying we have all heard before, whether it is forgetting that spinach you bought two weeks ago that has been sitting in the bottom drawer or the relief of not having to worry about work once you are off the clock. Microsoft is now taking this saying to a different level with Microsoft passkeys. 

Welcome to the Identity Theft Resource Center's “Weekly Breach Breakdown for Aug. 7, 2026. I'm Alex Achten, vice president of media relations for the ITRC. Thanks to Sentilink for supporting the ITRC and this podcast. Each week, we review the latest events and trends in data security and privacy. This week, we will discuss some major Microsoft updates. 

Spinach and your most recent workday might be out of sight and out of mind for you. For Microsoft, it’s SMS and voice authentication. That is why the title of this episode is “Out of Text, Out of Mind.” I am sure some of you are saying, “Alex, what the heck are you talking about?” Let me tell you! 

According to Microsoft’s 2025 Digital Defense Report, Microsoft Threat Intelligence has observed artificial intelligence-enabled phishing campaigns reaching click-through rates as high as 54%, compared with roughly 12% for more traditional campaigns, making stolen passwords and phishable second factors an urgent risk. 

Recently, Microsoft announced it is updating its authentication experience by making passkeys the default method, in hopes of protecting users from phishing, credential theft and social engineering as identity attacks grow more sophisticated in the era of AI. As passkeys become the default authentication option, SMS and voice authentication will be retired. 

Microsoft reports that it will begin rolling out passkeys in Microsoft Entra ID on Sept. 1, 2026. As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys. The next time they perform multifactor authentication, they’ll be prompted to register a Microsoft passkey.  

The next date to be marked on the calendar is Feb. 1, 2027. That is when Microsoft will retire its telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability.  

Some of you still might be asking…but why? How will passkeys help? 

Well, authentication methods that use SMS or voice rely on shared secrets or channels that criminals increasingly intercept, phish or manipulate. Passkeys use public-key cryptography, making them phishing-resistant by design. By making passkeys the default authentication experience, organizations reduce reliance on phishable authentication methods and strengthen protection against credential theft and phishing. 

To prepare for Microsoft passkeys in Entra ID: 

  1. Identify who still uses SMS or voice. 
  2. Move users to passkeys. 
  3. Notify users of what is changing, when and what actions they need to take. 

This change will not impact all of our listeners. However, at the ITRC, we encourage everyone, whether you are a business leader or a regular consumer, to switch to passkeys on all accounts when they are offered because they are easier and more secure. When fully implemented, passkey technology can eliminate an entire class of identity crime.  

Put the old SMS and voice authentication methods out of text and out of mind. It is a new day and age. It’s the Passkey Era.  

If you want to know more about how to protect your business or personal information or think you have been the victim of identity theft, fraud or a scam, you can speak with an expert ITRC advisor on the phone, via text message, chat live on the web, or exchange emails during our normal business hours Monday through Friday (6 a.m. to 5 p.m. Pacific time). Just visit IDTheftCenter.org to get started. 

Thanks again to Sentilink for their support of the ITRC and this podcast. Please hit the like button for this episode and subscribe wherever you listen to your podcasts. 

We will return next week with another episode of the “Weekly Breach Breakdown.” I’m Alex Achten. Until then, thanks for listening.  

Listen On