From SMS MFA to Passkeys: A Practical Microsoft Entra Migration Plan
Aug 10, 2026 · 53m
Summary
Meryl and guest Jay Maharaj discuss Microsoft’s deprecation of SMS MFA and the shift to phishing-resistant passkeys. They compare device-bound versus synced passkeys, highlighting improved user experience and security. The episode also covers using Entra Verified ID for secure onboarding, high-value resource access via FaceCheck, and self-service account recovery to reduce helpdesk reliance.
Topics discussed
Introduction and Microsoft's passkey rollout context
SMS deprecation timeline and legacy MFA risks
User familiarity with biometrics and passkeys
Device-bound vs. Synced passkeys explained
Significant improvements in user login experience
Phishing resistance and passwordless benefits
Passkey profiles and organizational flexibility
Security challenges in onboarding and bootstrapping
Verifiable credentials for identity verification
Self-service account recovery and cost analysis
Help desk security and social engineering risks
Roadmap for achieving a passwordless environment
Listen ad-free on Castria