A Year of Workforce Passkeys in Entra ID: Lessons Learned and the Road Ahead

 

Passkeys are soon to be the default authentication method in Entra ID. At the start of 2027, SMS MFA is no longer included within Entra ID. The winds of change are moving through authentication in Entra, but what does this all really mean?

In this session, Semperis Chief Identity Architect Eric Woodruff dives into what passkeys have looked like across the enterprise, giving you a taste of what’s ahead.

Eric explores why enablement of passkeys is great, but without enforcement, attackers will shift, as we’ll explore downgrade attacks and how they can bypass passkeys. You’ll get a look at what the rollout experience was like from the admin and end-user perspective, the technical and business challenges faced, and how they were solved. Eric examines the debate of device-bound vs synced passkeys, covering the technical and operational pros and cons in a Microsoft ecosystem. And speaking of a Microsoft ecosystem…he discusses whether Active Directory is really a blocker to passkey enablement. The session wraps with an exploration of other adjacent technologies needed to bring an enterprise fully phishing-resistant, changing up your Conditional Access policies for Identity Protection, and the challenges and adoption of technology like Verified ID and self-service account recovery.