Entra ID passkeys become default as SMS/voice MFA retires
Microsoft will make passkeys the default sign-in method in Entra ID from 1 September 2026 and retire Microsoft-provided SMS and voice delivery on 1 February 2027. The key…
17 articles
Security changes, vulnerabilities and practical resilience without turning every update into panic or theatre.
13 articles · authority 65/100
Microsoft will make passkeys the default sign-in method in Entra ID from 1 September 2026 and retire Microsoft-provided SMS and voice delivery on 1 February 2027. The key…
The enterprise rush to deploy AI agents is running into a familiar problem in a new form: identity. If an agent can act, call tools, move data or trigger workflows, it needs a proper identity model, not a vague service account and a hope that logs will be enough. That shifts the discussion from ‘what can the model do?’ to ‘what can this agent prove it is allowed to do, and how is that enforced?’
Critical unauthenticated code execution in specified Silicon One-based Cisco Nexus 9000 switches can give a reachable attacker root privileges and reload the device. Operators should urgently establish exposure, restrict access and upgrade using Cisco’s platform-specific guidance.
If you are tightening up Microsoft Entra ID security, the first wins are usually not exotic: they are the controls that reduce password abuse, shrink admin exposure, and stop legacy sign-in paths from becoming an easy route in. The trick is to turn on the right controls in the right order, without breaking sign-in for the people who keep the business running.
Microsoft is steering Entra ID away from SMS and voice MFA and towards passkeys. The shift is security-led, but it’s operationally risky: recovery, Conditional Access interactions, legacy apps, and helpdesk load can all change the outcome.
Ransomware exploitation of SharePoint flaws has sharpened the case for removing public access to on-premises farms. With SharePoint Server 2016 and 2019 unsupported, organisations must investigate historic compromise and choose migration, Subscription Edition or retirement.
Microsoft will make passkeys the default sign-in method in Entra ID from 1 September 2026 and retire Microsoft-provided SMS and voice delivery on 1 February 2027. The key risk is strand-through: recovery and helpdesk flows that still assume telecom MFA.
Jersey’s Cyber Security Law takes effect in two stages: the JCSC gains statutory functions on 1 September, while OES security duties and 24-hour incident reporting begin on 1 December. Potential operators should use the gap to establish scope and response readiness.
Time-based backup immutability is now available for Azure SQL Database LTR backups: once the policy is enabled and locked, protected backups can’t be deleted or modified until the retention window ends. But it only covers backups created after the lock.
Microsoft lists CVE-2026-58644 as exploited in the wild. SharePoint Server operators should verify every farm meets the June fixed-build threshold, install the latest August cumulative updates and assess any previously exposed unpatched host for compromise.
Microsoft has marked two SharePoint Server vulnerabilities as actively exploited. Organisations with internet-facing or previously exposed farms should patch to current builds, preserve evidence and assess whether attackers gained access before remediation.