Episode 433: Passkeys, Passwords, and the End of SMS MFA
Jul 30, 2026 · 45m
Summary
In this episode, the hosts discuss Microsoft’s shift from MFA to phishing-resistant authentication, highlighting the retirement of SMS and voice methods. They examine the challenges of deploying passkeys as the new default, including user experience friction, Bluetooth connectivity issues, and ecosystem limitations. The conversation also covers backup credential strategies for admins and the complexities of managing hardware tokens like YubiKeys in enterprise environments.
Topics discussed
Introduction: The shift from passwords to passwordless
Microsoft's timeline for retiring SMS and voice MFA
User experience challenges with passkeys and Authenticator
End-user adoption hurdles and device dependency
Navigating the transition to passwordless authentication
Technical nuances: Bluetooth, proximity, and connectivity issues
Managing YubiKeys, AA GUIDs, and firmware updates
Using Entra ID registration campaigns for passkey setup
Integration with third-party password managers like 1Password
The impact of AI on phishing and the need for passkeys
Backup strategies: 3-2-1 rule for admin accounts
Conclusion: Final thoughts and community resources
Listen ad-free on Castria