Today marks the beginning of the end of an era for enterprise Microsoft authentication.As of Sept. 1, passkeys are now the default authentication method for Entra ID, Microsoft’s cloud-based identity and access management (IAM) service. By Feb. 1, 2027, Microsoft-provided SMS and voice authentication will be a thing of the past.The move is seen as one aimed at pushing enterprises toward passwordless authentication — something security leaders are broadly on board with but often struggle to fully deploy.Microsoft putting its weight behind passkeys in the enterprise may mark a watershed moment for the passwordless technology, but legacy applications and specialized use cases remain a sticking point.As a result, security practitioners and independent experts see the immediate corporate future as a hybrid authentication world with passwords (and their inherent risks) very much still alive.How passkeys resist phishingThe core benefit of passkeys over passwords is that they eliminate shared secrets entirely. Instead of typing a guessable string, users authenticate via cryptographic key pairs unlocked locally by their device’s biometrics or a PIN.Passkeys are resistant to classic phishing because a fake website cannot trick the browser or OS into using a passkey for the wrong domain due to built-in cryptographic checks.Many consumer and enterprise services now offer passkeys as a sign-in option and the technology is backed by government technical assurance agencies such as the UK’s National Cyber Security Centre (NCSC).The reality on the groundFrom an enterprise CISO’s perspective, passkeys offer improved security and a better user experience, but they introduce challenges in governance and device lifecycles, along with concerns about ecosystem lock-in.“The NCSC’s push reflects the reality that traditional passwords even with multi-factor authentication remain vulnerable to modern, AI-turbocharged phishing and credential stuffing,” says Jason Soroko, senior fellow at global certificate authority Sectigo.Alex Laurie, GTM CTO at enterprise identity and access management vendor Ping Identity, notes that passwords remain one of the weakest links in enterprise security, “largely because they can be stolen or reused.”“Passkeys dramatically reduce the effectiveness of phishing attacks by binding authentication to the legitimate application or website, and Microsoft’s decision to make passkeys the default reflects the growing maturity of passwordless authentication across the industry,” Laurie says.That said, whereas passkeys are ideal for consumer use cases where the relationship to the user is not known ahead of time, they are not ideal for employee authentication, Sectigo’s Soroko points out.“Widespread business-to-employee adoption of passkeys still faces severe blockers, primarily revolving around the operational complexities of account recovery, the compliance headaches of binding corporate credentials to personal consumer ecosystems (like a BYOD Apple ID or Google account), and the sheer incompatibility of legacy infrastructure,” he notes.“Any time there is a need for tightly controlled management of the relationship, there is going to be a better passwordless technology that exists,” Soroko says.Dray Agha, senior manager of security operations at managed detection and response vendor Huntress, describes Microsoft making passkeys the default in Entra ID as a “tipping point” for enterprise adoption while noting several potential drawbacks.“The catch for CISOs is a loss of control, relying on Apple, Google, or Microsoft to sync and recover these keys offloads the security burden, but binds enterprise security tightly to consumer ecosystems,” Agha says. “If an employee is locked out of their personal account, recovering their corporate identity becomes that bit more of a headache for IT.”Ecosystem fragmentationEcosystem fragmentation among platforms that support passkeys is another obstacle.“Generating a passkey on an iPhone and trying to use it on a shared corporate Windows machine isn’t seamless yet,” Agha explains. “Until passkeys flow effortlessly across competing platforms, user experience will feel fragmented.”One of the biggest challenges security teams face isn’t how users sign in when everything is working as expected, but how enterprise workers can regain access when they lose a device or change roles.“CISOs need to ensure recovery processes are phishing-resistant and don’t inadvertently introduce weaker security than the passkeys themselves,” says Ping Identity’s Laurie. “Secure recovery is essential to maintaining both security and business continuity.”Passkeys offer the promise of improved security but only if the technology is robustly and coherently applied.“The Black Hat USA 2026 Pass-the-Passkey Family of Attacks talk is a useful reminder that passkeys mitigate whole classes of attacks, but flawed implementations can still create relay, replay, spoofing, or impersonation paths,” says Michael Grafnetter, principal security analyst at SpecterOps.Hybrid model will give passwords a stay of executionDeploying passkeys to access cloud apps offers enterprises a straightforward security win, but full passkey migration is currently a “myth for legacy and smaller businesses,” Agha contends.“Passkeys rely on modern web standards,” he adds. “They won’t play nice with custom internal applications, older on-premise infrastructure, or niche industrial workflows.”For the foreseeable future, hybrid is the only realistic strategy, according to Agha.“CISOs should aggressively deploy passkeys for modern cloud apps to get an immediate security uplift but keep traditional phishing-resistant MFA or physical hardware tokens active as a bridge for legacy systems,” he advises.Other experts also back the hybrid model.“Legacy applications and specialized use cases mean some systems may not yet support passkeys,” Rich Greene, SANS Institute instructor, tells CSO. “For many organizations, a hybrid model is therefore the most practical approach, allowing them to introduce passkeys where they’re ready, while continuing to support passwords for applications and workflows that still rely on older authentication methods.”Even for mainstream application, a better rollout strategy is to plan to introduce passkeys gradually rather than at one fell swoop.“A phased rollout, starting with pilot groups or selected applications, allows organizations to identify and resolve issues on a smaller scale before expanding passkey adoption across the enterprise,” Greene advises. “As legacy systems are phased out, passkeys can be introduced more broadly across the environment.”Few organizations can transition every application to passkeys and eliminate password use overnight.“Legacy applications, specialist business systems, and third-party software may continue to rely on traditional authentication methods for some time,” notes Ping Identity’s Laurie. “Rather than aiming for an immediate and full migration, organizations should adopt a phased strategy that introduces passkeys where they deliver the greatest security benefit, while maintaining secure support for legacy environments.”