Security
Phishing-resistant authentication for Microsoft 365 tenants: why Authenticator push is no longer enough, how passkeys actually work, and how to migrate without locking people out.
- From Authenticator MFA to multi-device passkeys
Organizations that already require Microsoft Authenticator remain exposed to phishing that relays push approvals and one-time passwords. Multi-device passkeys are FIDO2 credentials held on the user's devices rather than as shared secrets. A sound Entra ID design assigns methods by role and migrates the tenant in sequence so that a lost or replaced phone does not interrupt access.
