The rules of digital identity are changing fast. In fact, identity has become the primary attack surface for modern cybercriminals globally, with 86% of phishing attacks now being AI-driven. Faced with this new AI-powered threat landscape, Microsoft recently announced that passkeys will now be the default authentication experience in Microsoft Entra ID – transitioning from legacy, phishable authentication methods like SMS and voice authentication beginning September 1, 2026.
By elevating phishing-resistant passkeys to the default authentication method for Entra ID users, Microsoft and organizations globally are prioritizing security that can withstand modern phishing and social engineering attacks. Microsoft has long been a pioneer in advocating for stronger security measures through its Secure Future Initiative, and has integrated support for YubiKeys across the breadth of its ecosystem in recent years.
This latest move aligns with a larger trend among tech giants to mandate phishing-resistant authentication. Salesforce, for example, is enforcing MFA in production environments, with privileged users being required to use phishing-resistant MFA methods like YubiKeys and built-in authenticators that leverage FIDO2 and WebAuthn standards.
Whether you are securing enterprise operations or frontier AI workflows, the industry consensus is clear: trust starts at the point of login. We recommend starting to migrate your users now. Talk with our team if you want help with pre-registering YubiKeys for your users – or follow the self-service registration steps below before the September 2026 registration campaigns begin.
How to add YubiKeys to your Microsoft Entra ID account
Follow the step-by-step instructions below to get started today or visit here.
- Open a browser window and navigate to https://myprofile.microsoft.com
- Sign in to your account
- Select Security Info in the left navigation tile1.png
- Select Add Method
- Select Security Key (or Passkey), and then Add (Note: The user experience may vary if your users are allowed to register any type of passkey in the Entra tenant.)
- Click USB Device and then Next
- Insert your YubiKey and select External security key or built-in sensor, then click OK
- Create a PIN, then touch your YubiKey
- Touch your YubiKey again to confirm
- Label the YubiKey, then click Next
- Select Done – You have now successfully registered your YubiKey to your account!
True security requires a phishing-resistant, hardware-backed root of trust built on credentials that cannot be copied or synced. With hardware-backed passkeys, you achieve phishing resistance that binds identity to a physical device that requires a human touch. Together, Yubico and Microsoft are delivering a future where authentication is resilient, flexible, and securely anchored in the physical world.
For more information on Microsoft’s transition to passkeys for Entra ID, visit here. To learn more about how YubiKeys can secure your cross-platform enterprise environment, and how Microsoft and Yubico work together to raise the bar for identity assurance, visit here.
