
Microsoft Cloud IT Pro Podcast · 2026-07-30 · 46 min
Key moments - from our scoring
Substance score
68 / 100
Five dimensions, 20 points each
Microsoft 365 authentication is undergoing a fundamental transformation from making passwords safer with MFA to eliminating phishable authentication entirely. This shift culminates in September 2026 when passkeys become the default authentication method for Microsoft 365, alongside the retirement of SMS and voice MFA by February 2027. The hosts examine this transition through both an IT security lens and a practical operator's perspective, revealing significant complexity beneath the marketed simplicity of passwordless authentication. Passkeys aren't a single solution - they're stored in Microsoft Authenticator, password managers like 1Password, hardware tokens like YubiKeys, or Windows Hello for Business, each with different user experiences and failure modes. The conversation covers real deployment challenges: Bluetooth connectivity unpredictability between phones and computers, the cryptic AAGUID system that forces organizations to maintain approved firmware versions across FIDO2 devices, account recovery scenarios, support burden, and the wife-acceptance factor of authentication flows. The episode provides critical context for IT pros balancing security requirements against usability and organizational support capacity.
Microsoft will give organizations options to use third-party telecom providers by September 18, 2026, require voice users to move to third-party telecom by October 30, 2026, and fully block SMS and voice authentication on February 1, 2027, at which point passkeys will be the required passwordless method.
Passkeys require users to understand where they're stored (authenticator app, password manager, hardware key, or device), set up biometric authentication on their phone or computer, and deal with Bluetooth connectivity that can be unpredictable - sometimes connecting in seconds, sometimes timing out and invalidating the QR code.
AAGUID is an identifier that tracks the specific firmware version and manufacturer of FIDO2 devices; organizations can restrict which AAGUIDs are allowed in Entra ID, meaning firmware updates or new device versions may no longer be trusted, forcing users or organizations to acquire new hardware keys.
Organizations lose the ability to deploy passkeys to those users and may need to plan alternative authentication methods, though Microsoft's sunset of SMS and voice MFA by February 2027 eliminates that fallback option.
Passkeys use Bluetooth proximity detection to allow a phone to authenticate to a computer without explicit pairing; the user scans a QR code on their computer, authenticates on their phone with biometrics, and waits for the devices to connect via Bluetooth - but connectivity can be unpredictable, especially across VPNs or with certain device configurations.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid, practical insights about authentication transitions and passkey implementation challenges that operators actually face. However, much of the discussion circles around known pain points (Bluetooth connectivity issues, user friction, ecosystem lock-in) rather than revealing novel solutions or unexpected angles. The specifics about AA GUIDs, firmware updates, and registration campaigns add substance, but significant portions involve restating problems without breaking new ground.
there's this whole weird kinda matrix that you have to walk through, and it quickly turns into, I think, like, what I would just call a quagmire
SMS, voice, OTP, all of these are very phishing vulnerable
The hosts present a balanced, practitioner-grounded perspective that avoids pure cheerleading for passkeys, which is refreshing. However, the core framing - that passkeys are both necessary and problematic, that Microsoft's ecosystem creates friction, that user education is critical - is relatively well-trodden in IT security discourse. The insights about YubiKey firmware rotations and multi-tenant complications are specific enough to add some originality, but the overall argument lacks significant counterintuitive claims.
From a security perspective, I'm all for that. From an end user perspective, I've had some challenges with passkeys
I can't imagine trying to go through that with a 2,000
This is a co-hosted conversation between two experienced Microsoft 365 and Azure practitioners with genuine operational depth. Both speakers demonstrate real hands-on experience managing large-scale environments, multiple tenants, YubiKey deployments, and actual user rollout failures. They speak from deep practical knowledge, not theory. This is notably stronger than pure analyst or vendor commentary, though neither guest appears to be a marquee enterprise identity architect.
I've had clients already ask wanna get to passwordless. To your point, how do we do this? What does this look like in terms of an actual deployment?
I have four or five passkeys on my phone. I cannot use them. I have tried them with, like, three different computers
The episode grounds its discussion in concrete operational details: specific Microsoft timelines (September 18, October 30, February 1, 2027), AA GUIDs, firmware version examples (5.4 to 5.7), Bluetooth connectivity problems, actual user counts (10, 6-7 people, thousands-person orgs), and specific authentication methods (YubiKey, Authenticator, 1Password, Windows Hello). However, it lacks hard metrics on failure rates, cost data, time estimates for rollouts, or quantified support burden increases. Anecdotes dominate where data would strengthen claims.
by February 1 02/01/2027, SMS and voice is gonna be fully retired
I have four or five passkeys on my phone. I cannot use them. I have tried them with, like, three different computers. I've tried resetting the passkeys
The hosts engage in genuine back-and-forth with real follow-ups and practical pushback. Scott frequently challenges Ben's claims or asks clarifying questions (e.g., "Have you ever gone to set up a passkey and one password always wants to take over"), and they build on each other's frustrations productively. However, the conversation occasionally meanders without sharp closure, and there are fewer moments where one host pushes the other toward a surprising conclusion or resolves a tension decisively. The pacing is natural but sometimes loses momentum.
Is that causing an issue? Do I have like, there's so many nuances, I feel like, that can go a little bit south with passkeys
So maybe before we dive too deep into our rant about pass keys, we should talk about kinda, like, what's out there today
Computed from the transcript - who did the talking, and the words that came up most.
Welcome to Episode 433 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben and Scott discuss how Microsoft 365 authentication is moving from "make passwords safer with MFA" to "remove phishable authentication wherever possible." The practical conversation for IT pros is no longer just whether MFA is enabled. It is which methods are allowed, which users are still on SMS or voice, how passkeys change the user experience, and how to balance security, accessibility, recovery, and support load. Your support makes this show possible! Please consider becoming a premium member for access to live shows and more.
Transcribed and scored by The B2B Podcast Index.
- Welcome to episode 433 - of the Microsoft Cloud IT Pro podcast recorded - live on 07/27/2026. - This is a show about Microsoft three sixty - five in Azure from the perspective of IT - pros and end users, where we discuss a - topic or recent news and how it relates - to you. Today, we discuss how Microsoft three - sixty five authentication - is moving from make passwords safer with MFA - to remove phishable authentication wherever possible. - The practical conversation for IT pros is no - longer just whether MFA is enabled, it is - which methods are allowed, which users are still - on SMS or voice, - how passkeys change the user experience, - and how to balance security, accessibility, - recovery, and the support load.
- Blast off to our topic of the day. - To - authentication. - That's quite a topic. Authentication.
- Yeah. So you you and I have been - maybe ranting a little bit in the background - to each other and figured this would make - for a a good conversation. - So there's this whole world in, - I I think, Microsoft land, and we'll probably - focus on the m three sixty five, but - largely applies to the same things of logging - into Azure or really any property that's bound - to Entra ID Yep. As an identity provider.
- So there there's been this march from Microsoft - over the years to - move away from - making passwords safer with things like multifactor authentication - to just getting to a general stance of - phishable authentication - is not possible where wherever - it was possible - in the past. So that that's been a - a weird one. Right? Like, we're in this - world of transitioning - from - MFA and MFA enablement and all the things - we've done over the years to get there - to - a new set of methods, - which are allowed.
And even out of that - set of methods, sometimes things are changing between, - like, SMS, - OTP. - You've got the whole world of, like, passkeys - are supposed to be better, but I think - you and I might rant a little bit - like, are they really? - And see where we come out. So I - think it'll be a fun conversation because we - get to kinda talk about the changes in - the authentication landscape, - what's - happened along the way, what's changed, what's in, - what's out, - and how - folks can think about maybe not baselining, but - maybe rebaselining, - how you think about security, - accessibility in a world of we're trying to - eliminate phishable authentication wherever possible.
- What does things like account recovery look like? - What's your support burden with your end users, - and where does that fall out? So there's - a whole bunch to kinda peel apart - as we go through this one. So - you wanna start with maybe, like, passkeys and - m three sixty five because that's kinda becoming - the - default - authentication experience here - pretty soon.
Yeah. September this year. Right. And - I was gonna say even some history - on that before we start talking about pass - keys, they are gonna be the default is - some of this came out too is that - Microsoft's been talking about this, but for a - little bit, but the road map came out - about this and there may be some new - dates is that - as a part of pass keys becoming the - new default, - Microsoft also announced that - SMS - and voice - for MFA - are going to be fully retired.
So if - you are using - Intra for this stuff and - you're still relying on SMS invoice, - there is now an official timeline - from Microsoft on this that as of as - early as September - of this year, 2026, - September 18, Microsoft is going to give you - options for telecom providers - if you want to keep using SMS and - voice. They're no longer gonna offer it, but - they will give you the option to go - sign up with a third party telecom and - use it by October 2026, - October 30.
Organizations still using voice have to - go to third party telecom. And then by - February 1 - 02/01/2027, - SMS and voice is gonna be fully retired. - They're gonna be blocked from signing in, and - this is interesting. I think you'll still be - able to use third parties after 2027, - but the Microsoft one is gonna be just - gone.
If you were using Microsoft at all - by February, you're gonna have to go to - passkeys, - which is why - in preparation for this, September 1 passkeys are - gonna become that default. Which I think is - gonna lead to a little bit of, like, - passkey fatigue for folks. - It's gonna be - gonna be a an interesting place, I think, - for customers to land. This is one of - these.
Like, I have two very different perspectives - on passkeys. - I have my IT pro - security - passkeys are - awesome standpoint - because - SMS, voice, phishing I mean, the more we - can get to passkeys and no passwords. - From a security perspective, I'm all for that. - From an end user perspective, - I've had some challenges with passkeys, and I'm - like, this is we're in this IT landscape.
- We're used to dealing with technology - and passkeys I can get around. I think - to some users and some people I deal - with, and I'm like, this could be interesting - to say the least. I think it is - a little bit of - a a hurdle. - Everything out there is - ever so slightly different.
And I think in - the world of m three sixty five and - passkeys, it's kinda muddied even further because you're - locked into - the Microsoft ecosystem - for better or worse. Like, we were talking - about this maybe last week or the week - before. - I would really like to be able to, - like, manage my passkey - for something like my Entra ID - in one password where every other passkey that - I have is. Guess what I can't manage - in one password?
I have to use the - Microsoft Authenticator app, which has been losing features - over the years. You would think it's getting - more streamlined and better. Like, it's not better. - It's - it kinda sits out there and continues to - persist.
But things like doing, like, a passkey - through the authenticator app are infuriating - versus just doing them in your browser - or through a password manager, be it one - password or bitwarden - or anything - like that. So I I think that's part - of it is, like, Microsoft - locks you into an ecosystem - that maybe isn't as friendly or isn't doing - the things that you're doing in other parts - of it, which makes it a little harder - to kinda onboard to and smooth - out. And, you know, it also has its - own fits and bumps along the way.
So, - like, if I go and authenticate - to - m three sixty five and my organization requires - me to use - use a a pass key, well, that's great. - So I've got that pass key on my - phone. I've got the authenticator app installed. So - let's go ahead and pull that up.
Alright. - Let me scan the QR code. Yep. I - scanned the QR code, - authenticated with my face or touch ID or - fingerprint, whatever it happened to be.
- And then you kinda gotta wait for the - magic to happen. So I find this part - to be kind of infuriating across every operating - system, be it, like, - a a Mac or Windows device is I - sit here and I I I authenticate on - my phone, and then I gotta wait for - it to connect over Bluetooth - and find my device. - And, hopefully, it connects. - Sometimes, it connects in, like, two seconds, and - it's like, oh, wow.
That that went through - and it was magical. Sometimes it just sits - and spins forever, and it's the most infuriating - thing because you don't know what happened. And - it'll do these crazy things, like, it'll time - out. And then that QR code is now - invalid.
You gotta go back, generate another one, - start your authentication flow. Like, it's very, like, - black box in the implementation - and the way Microsoft did it, I think, - versus the way you can hit it in - other parts of the ecosystem. - Say if you were to just be able - to, like, store your passkey in a password - manager or your local browser or things like - that. My my Microsoft has made some deliberate - choices there, and - some of them have, I think, just - additional friction that that make them just ever - so slightly harder to use an onboard with - and then to train your users on.
Like - you said, like, I think you and I - are pretty I think it's fair to say, - like, we're savvy when it comes to this - stuff, and - it infuriates me at times. - Like, that doesn't make - it very high on things like the WAF, - the with the wife acceptance factor for something - like this would be pretty low. Right? If - I told my wife, like, hey.
Every time - you need to log in to your email - account, you have to jump through this hoop, - she would, I think, just stop using email. - It is. And there was an interesting article - that came out too from on How to - Geek that we'll link to in the show - notes where it talks about some of this - too where - passkeys are supposed to replace passwords. - Microsoft is obviously trying to move in this - direction with passkeys.
- They did it, I mean, what, three or - four or five years ago already with personal - Microsoft accounts so you could delete your password, - but they're still confusing. And you were mentioning - your wife, I know my wife would fall - in this boat as well, is and this - article - kinda hints at us as that passkeys are - just kind of happening, - but there's not a lot of I think - it's confusing. - It's hard for users to understand and, like, - what is a passkey? - You mentioned this earlier.
It's like, I can - do passkeys on authenticator. I can do passkeys - in one password. I can do passkeys on - USB keys, on FIDO two keys. - Technically, - pass keys can be stored on Windows using - Windows Hello for Business.
- Like, in the past, the password is a - password. Everybody kind of understood usernames and passwords, - And passkeys are like, well, where are they - stored? - Different websites - can store them different places. - Different things are supported.
- And trying to get from a user perspective, - how do you get users to understand this? - How do you get users to adopt this? - And what does that user experience look like - is - I feel like it's a challenge, especially, like - you said, for those non IT users that - aren't really used to it. They don't really - know what it is, and some of them - are like, well, where do I store this?
- And, I mean, to my perspective, one password's - great because if I switch devices, - my passkey goes with me. But what if - when I replace my phone and all my - passkeys are there, my passkeys are on my - computer, and I go to a new computer, - but I all my passkeys were locked up - in Windows Hello for Business on my old - computer. - There's a lot more - complexity - to passkeys and I think a lot more - user education that has to happen when you - start looking at how do you push these - out and deploy these to end users.
For - sure. I think just even, like, like like, - the onboarding flow alone - is enough to kinda think about and get - through. And then how do you wanna configure - your environment, I think, is another part of - it. Like, I think some organizations would say, - hey.
Like, hey. Pass keys are, like, the - end all be all. Let's go do them. - And sometimes that's at the expense of making - other forms of authentication, maybe even, like, a - little bit more friction or harder to use.
- So you might say, like, hey. I'm gonna - keep a token for a pass key alive - for twenty four hours, but sorry if you - authenticate - by hardware key, by, like, a YubiKey or - something like that. I'm gonna make you reauthenticate - every two hours because you have the little - key in there. Right?
It should be easy. - It won't interrupt your flow at all, except - it really does interrupt your - interrupt your flow. So so maybe before we - dive too deep into our rant about pass - keys, we should talk about kinda, like, what's - out there today and what's going away and - what folks should maybe think about as you've - got this general march towards - passkeys for everybody. Yeah.
It's coming. Right? Whether - you want it or not, it's coming. So - you do have to kinda prepare for it - and get ready.
I've had clients already ask - wanna get to passwordless. - To your point, how do we do this? - What does this look like in terms of - an actual deployment? Even passwordless - is, I I think, a hard one for - folks to - understand - and get behind.
So, like, I have parts - of the organization that I'm in. Like, sometimes, - like, we do have environments with passwords. Sometimes - we have ones without. I've seen folks, like, - get very confused - about which ones do and which ones don't - and how you can log in and what - you can log into with what.
So, like, - I I have some environments which are driven - by pass keys, like hardware tokens, like YubiKeys, - things like that, and I can only log - in with a YubiKey. I have other places - where I can only log in with a - passkey via the authenticator app, and then I - have some places where I can still log - in with a password. So that's hard to - balance too. It's just, like, the context switch - and knowing - where you are at any given time and - kinda what's allowed in there.
So - maybe most folks don't have, like, multiple environments - like that or things to think about along - those lines. But if you do, it's just - another component of end user - enablement that you need - to think about - along the way. Right. Microsoft does offer some - guidance here, right, to think about like like, - they have an article out there and learn.
- Plan a phishing resistant passwordless authentication deployment in - Microsoft entry ID. And it kinda walks you - through, like, high level what to do, but - it very much focuses on - device readiness. - So, like, what is Windows 10 with Windows - Hello for Business enabled, Windows 11? - What do you get across, like, mobile platforms, - macOS, - things like that?
It doesn't spend a bunch - of time on, like, end user personas, which - I think is an important part is, like, - understanding your audience and what you need to - dig into. - Like, they kind of wishy washy it and - they just say, oh, there's admins and there's - nonadmins. - Well, that's probably - not - the right way to think about it. Like, - arguably, there's gonna be folks in, like, I - don't know, like, let's say, like, finance or - HR, and somebody in finance might have a - different authentication method to - system x y x versus - system y or system z or things like - that depending on what that thing is and - how important the data is in it and - everything else.
So I think you gotta spend - a little bit more time on kinda planning - and personas, understand your organization, and then be - able to map those things back into - those various authentication methods - and what you want to enable where or - how you want to enable where, I guess. - You mentioned going back and talking through those. - Did you wanna kinda work through - what are those different ones? I guess, kinda - thinking at it from a more of an - intra perspective - in terms of - what do we have today - and what are some of those options you - have.
What do we have today? Like, there's - where we came from. So you've got the - worlds of passwords. All the things you use, - so you have to deal with passwords.
So - Yep. Yep. Password spray attacks, all all that - kind of stuff. SMS, - MSA - or OTP codes, - things like that.
You've had authenticator - with push notifications, - and then those push notifications can be as - simple, like, hey. I wanna come in and - just face ID, touch ID, whatever apps we - have on your platform of choice, - or they can also - be, like, number entry kind kinds of things. - And then on top of all of those, - you always had things like conditional access layered - in as as well. So that's kind of - the world we're coming from.
And then where - we're going to is a lot of that - stuff is going away. So passwords are going - away. SMS - is SMS MFA or OTP is going away. - So that's that that voice retirement component that - you talked about there and everything that comes - with it.
So you gotta think across this - lens of passwords, - SMS and voice, - OTP, - authenticator, - Windows Hello. - You've got FIDO two keys, and you've got - synced pass keys. - You've got your - authenticator - pass keys, which are different than just regular - authenticator and getting, like, an OTP code, - out of it, things like that. And then - you've got your conditional - conditional access stuff layered in there along the - way.
So there's a whole bunch of, like, - moving parts and pieces and things to think - about depending on where your organization is at - today, how your tenant's configured, all all those - kinds of things. Yeah. When you're going in - and configuring it, like, I've had to do - this for my own tenant. I've had to - do it for others, and - it is really thinking through - what do passkeys mean for your organization.
- And I think that's where - some of what we've been talking about already - starts coming into play as before it was - just, okay, SMS and voice. Everybody has a - phone. Well, I would hope most people have - a phone. You can do SMS.
You can - do voice. That's pretty easy straightforward. - But then when you get into the area - of passkeys, it's to your point. - Now maybe I have to do authenticator app, - and I've had clients where I've talked to - where they start getting pushback of, no.
This - is my personal device, - and it is 100% - my personal device. I am not going to - put authenticator - on it so that - you could do passkeys. In the past, - those types of users - in some of these companies I've worked with, - they're okay with a voice caller and SMS - text because it's not an application. It's not - a business application going on to their personal - device.
- So it's, okay, what do we need to - do if we're gonna go the - the mobile app route for authenticator - and doing synced pass keys or - even push notifications and number matching there? And - to the point of, is it going to - work? I've actually had it Is it going - to work? Is it's an important question to - ask Yeah.
And something to definitely validate out - there. Right. Because you said your experience with - Bluetooth is, does it connect, which the whole - Bluetooth with passkeys is still - a little bizarre because it's not like you - have to necessarily pair the devices together. It - still reaches out over Bluetooth to make sure - you're in proximity without really doing a - what most people think of when they're pairing - a keyboard or pairing - AirPods or pairing a Bluetooth device.
You're not - doing that, but it is still communicating over - Bluetooth, - which can be unpredictable. And lately, I still - don't know what it is. I have four - or five passkeys on my phone. I cannot - use them.
I have tried them with, like, - three different computers. I've tried resetting the passkeys. - I get, like, the QR code, scan this - to use your passkey. I scan it, and - it just doesn't - recognize it.
It never connects. And I've started - digging into, like, do I have something on - my phone that's blocking that underlying Bluetooth connection? - I have also seen things you can run - into issues with - VPNs. I have global secure access on some - of my devices.
So they technically egress through - Microsoft's data center in Virginia, I think, when - I'm going over global secure access. Now my - phone and my computer are on two different - networks that look like they're in geographically - different locations. - Is that causing an issue? Do I have - like, there's so many - nuances, I feel like, that can go a - little bit south with passkeys - on mobile devices.
- That has become a challenge for me, and - then it's, like, well, what are my other - options? Then you start thinking down - the YubiKey route. - I have different clients that have different requirements - for YubiKeys. - When you're going and setting up any of - these passcodes, whether it's a YubiKey or something - else, they all have I don't even know - how to pronounce it.
It's the AA - GUID that every - it's not even every manufacturer. It's like every - different version - or firmware number - of these different things have this GUID. 1Password - has one, but then YubiKey has one for - biometric devices, for proximity devices, - for just plug in devices, - and - Authenticator - has its own. You can go in and - start limiting in this in my Entra environment, - Entra.
- People have me saying Entra. In my Entra - environment, - it is Entra. Let's I don't different people. - I talk to too many people.
It is - Entra. Let's confirm that a minute. It is - Entra, not intra. In your intra environment, you - can go configure what are these AA - grids that I'm going to approve.
- I'm starting to gather a collection of YubiKeys - because it's like, this client - only has these three in there. This client - has this one. This client has these. - And now I have to start keeping track - from my perspective, - this maybe isn't your everyday user, which passkeys - are on which - YubiKeys - that I'm having to swap out as I'm - authenticating into different tenants.
- It it very quickly becomes complicated - for me because of multiple tenants, but even - you've mentioned it with one tenant as firmware - updates, - your - your organization that you're working for - may update - which ones are allowed. And all of a - sudden, one day, just one passkey stops working - because they decided we're no longer gonna trust - that firmware. I don't know how many folks - leverage the a a goo with thing, but - if you work in an organization that does - I've encountered more than I thought.
I wouldn't - think most folks would dig in that far - because it is kinda buried, like, down in - in the depths of FIDO key configuration - inside of, - Entre there, but it's a rotating game. So - I know for me, I have a stack - of YubiKeys at home right now. Like, I - just keep them all on my desk on - the side, like, because I can keep using - them for other things if I wipe them. - So I can use them for my Gmail - and my regular, like, Microsoft account, my MSA, - my consumer account, things like that.
But for - my organizational account, I'm on this constant train - of, like, bumping YubiKeys because I have to - go to new versions of new YubiKeys because - they have updated firmware, - which probably prevent - security concerns - and have patches and blah blah. Bunch of - stuff that I've never seen published anywhere. I - don't know if, like, YubiKey or Yubico or - or folks publish those kinds of things. But - I'm on this constant march of - always having to figure out, like, is this - the right YubiKey?
Because they all look the - same, but they all have different capabilities. - And then does it have, like, the right - set of identities on it, which you can't - really tell on a YubiKey. Right? You kinda - have to put it in and try it.
- There's no, like, YubiKey app that you just - load up, and it says, oh, here's all - the here's all the identities that are bound - to this thing. So they don't make it, - like, very easy. - And organizationally, - if, like, you're on like, everybody's on the - same version of a YubiKey and then you - have to plan for this. Right?
So let's - say you're a thousand person organization and all - of a sudden, everybody's on YubiKeys. Great. So - you go buy a thousand YubiKeys, you bulk - price whatever. What happens when - those were on firmware - five dot four, and now you've gotta get - everybody to a new AA GUID and up - to firmware - five dot seven or whatever it happens to - be.
Well, guess what? You need to go - buy a thousand new YubiKeys. You need to - send out those YubiKeys to your users, and - then you have to have your users - bind a new - YubiKey to their account and then stop using - their old YubiKey. And, like, what do you - do with that?
Well, it's just e waste - and and other things that are out there. - And so so, yeah, it's this whole weird - kinda kinda matrix that you have to walk - through, and it quickly turns into, I think, - like, what I would just call a quagmire. - Like, - it's it's hard to navigate, and it's hard - to - it's hard to think through. Like, I I - really struggle thinking back to, like, some of - the several thousand person, like, m three sixty - five environments that I've managed in the past - about transitioning those organizations - over to something like authenticator - bound pass keys.
- Like, oh my gosh. Like, what a - what a nightmare scenario that is. I'd rather - do, like, - a a a 5,000 seat, like, office upgrade - or an exchange upgrade or something like that - or a a SharePoint farm upgrade than than - go through and push that one. Yeah.
Because - it is. It's hard. Right? You're going away - from maybe, like, something like YubiKey - or a CAC card or something else that - you had out there, and then you're binding - it to a a mobile device.
Like and - like you said, like, I I think some - people do have a big hesitation around my - personal device coming in, and they're like, does - my personal device now need to be MDM'd? - Well, how hard? You know? Does it need - to be MDM, and what does that follow - along with?
So there there's a whole bunch - of considerations out there on, like, the hardware - side and the procurement side and the life - cycle side that add to the cost - of something like passwordless - authentication - with - with passkeys like this. - If you're managing file storage today, you've probably - felt the pressure. Refresh cycles are harder to - plan, costs and complexity are increasing, especially as - file workloads scale across regions. - That's why Microsoft customers trust Nasuni.
As an - Azure certified software, - Nasuni provides a global file system designed for - enterprise scale environments, - keeping file data secure, governed, and accessible across - Azure environments without added infrastructure complexity. - It's the foundation - to keep your unstructured data stable even as - your infrastructure evolves. To see how much you - could save while keeping your initiatives on track, - visit nasuni.com/tco.
- That's nasuni.com/tco. - Microsoft is trying to help with this. I - would say it's better than it was three - months ago.
I had one company that switched - to passkeys three months ago, and it was - three ish months ago. We sent out instructions. - Right? Like, go install your authenticator app.
Go - in here. Click on passkeys. Add a passkey. - Walk them through everything.
This was only, like, - six or seven people. And we were like, - on this date, you're gonna have to use - your passkey. We're flipping over conditional access. - Passkeys are gonna be required.
We flipped it - over and, like, 50% of the 10 people, - I can't get into my account. It's telling - me I don't have a passkey. - Get on the phone with them. Well, did - you go do this?
No. I just had - authenticator on there, and I was getting push - notifications and number matching, and I thought that - was good enough. - No. You actually have to go register a - passkey.
So and that was only 10 people - to your point. I can't imagine trying to - go through that with a 2,000. - As of July 1, - I believe this came out or June, - Microsoft - at least rolled out a way now to - do a registration - campaign in Entra Yep. To set up a - passkey.
- So this - does support - passkeys - FIDO two to register a passkey, - whether it be synced, which is going to - be your authenticator one. I'm still waiting for - synced in one password. Probably, I'm not gonna - hold my breath for that one. Or the - device bound If it comes, please tell me.
- Like Yeah. I will keep you updated. Or, - like, the device bound, your Ubiquys - Authenticator - also - has an option of device bound, I think. - But it at least has that campaign there - now, so you can go turn these on - and actually walk people through setting up pass - keys versus just it's on or off.
Which - is helpful for existing accounts. I think you - still need to think about, like, the new - user flow and things like that. So, like, - how do you onboard your users in a - world where there are no passwords and you - need to get them a passkey and things - like that? - That's an interesting one - too.
I I haven't seen a bunch out - there about the way organizations - are handling that kind of thing, but it's - not, like, well covered in, like, Microsoft land - either. No. I'm working on this for another - client. - It is possible because I've had customers - onboard me through it.
Granted, it was like - a 20 page Word document - step by step with screenshots because it's not - straightforward because it involves a temporary access pass - and the registration, all that. I would love - this to see this get better both from - what you said. How do you onboard users - initially? - But even these registration campaigns, it's pretty much - like go turn it on and force people - to do a passkey.
- It doesn't give you a lot of control. - Like, do I want to walk people through - a registration - campaign to use a - USB device, or do I want them to - go to authenticator? - I'm hoping we see more come with these - registration - campaigns - to set up pass keys to be able - to better control it and guide people - through the right path or set which path - you want people to take. This is also - hard.
I don't know if you've had this. - Have you ever gone to set up a - passkey and one password always wants to take - over even if you collect that it's a - USB passkey, and then you have to go - in and say use a different USB device, - and instead of one password, select your FIDO - key. It's things like that I feel like - from an end user perspective - need to get a lot smoother or I - want to see get a lot smoother for - this whole registration - process. I think it's a loaded thing right - now.
So, - like I said, I would like to see - Microsoft be more open. So don't bind me - to Authenticator. - And when I say don't bind me to - Authenticator, I mean, not Authenticator Authenticator, but I - mean Authenticator with a passkey, which is a - a different mode that's in there. Like, it - makes it super confusing to talk about.
So - some of this other stuff, like like, one - password maybe, like, conflicting with, like, a browser - versus something else. Like, I think that just - speaks to, like, the ecosystems - all over the place. Like, does Microsoft really - have to care about one password? I don't - I don't know if they should, - but I think they should care about being, - like, open in the ecosystem - and kinda - meeting customers in the middle where they want - to be because there are customers out there - that and I've seen, like, enterprises that use - one password - for management of these kinds of things.
And - they make it out there, and they license - it for their users. So think Microsoft should - be maybe, like, a little bit more open - in open in that space. - I would love to see updates to - the registration campaign stuff. So to your point, - like, I think one of the biggest things - with passkeys is training and user enablement.
Like, - you do have to spend time there and - train your users. I don't think you can - just expect that everybody's gonna grok it and - pick it up. But, like, those registration campaigns - don't give you a lot of flexibility. Like, - sure, I can go out and create this - thing, but all it's gonna do is hound - my user to go ahead and create MFA - and get a passkey or the authenticator enablement - if you're doing that.
And that's kinda it. - Like, you'd really want the ability to, like, - add a help link here. Like, just, like, - click this link to learn more and maybe - go over to, like, your custom learning system - or your documentation, - things like that. Because - to your point, it could be a 20 - page PDF or a 20 page Word doc - for onboarding.
But I guarantee it's usually a - couple pages at least, like, four or five - men by the time you put some screenshots - and stuff in there to get folks to - to where they need to be. So I - think, like, having that, - Microsoft should probably go and provide some additional, - like I don't actually know what they do. - I didn't see this. Like, you know how - they provide, like, the onboarding campaigns for SharePoint - and Outlook and Exchange Online, all those kinds - of things?
I've never seen one for - MFA, like, like, an enablement campaign thing. Like, - like, the word templates - and everything that's out there. So, yeah, you're - largely left to your own in this space, - which is it's just a a weird one - for the way it sits out there. And - I think the lift for customers - and the folks who are admins and operators - of these environments - and what they need to do there.
I - think, hope, this is going to be coming - faster and faster. - Where it's gonna be pass keys It's gonna - keep barreling down. Yeah. There's there's I'm actually - surprised this is the one area I'm surprised - still uses SMS for everything - is, - by and large, all of my banks - still use SMS - for - authentication.
- And the reason I say this is coming - faster and faster, I have - seen with AI. AI is really good at - writing by and large. The phishing - emails - and the phishing - attacks - that I have started seeing, certain - things you used to look for in emails - to know that it was phishing - in, again, SMS, voice, - OTP, all of these are very phishing vulnerable. - And even voice calling with what AI can - do with voice mail and replicating someone else's - voice.
Only takes about ten seconds, fifteen seconds - from a clip. It's kinda wild. You're gonna - have to move someone can replicate both of - us, Scott, from our podcast. Take all of - our podcast episodes and create the virtual Ben - and Scott.
Pass keys are going to have - to be there to prevent some of these - phishing because phishing things like OTP and SMS - and voice is going to get easier and - easier, I think, at an exponential pace with - the way technology and AI and all of - that are going. This brings up an interesting - question. So - in the world of these things are changing - rapidly, - and there's kind of a clear road map - at least from the m three sixty five - entry ID side to say, hey. Let's get - from kinda - x to y or a to b as - a destination - kind of thing is - when you're going down and you're enabling all - these things, - is - how do you think about backup credentials?
- And because you can have multiple modes of - authentication - today. Like, the goal is passwordless, - but you have all these other click stops - and maybe these things that you're using out - there today, and they become legitimate backups. Right? - If I'm really struggling - with my passwordless authentication - and passkey, like, do you give me a - fallback and let me go to OTP or - voice - or something else for a little bit little - while?
So how many backup credentials do you - think, like, folks - should have - in an organization - generally? And then how many backup credentials do - you think admins or, like, privileged operators should - have? And - at some point, you're gonna have to think - about disabling those. Right?
So how many backup - credentials should - admins, privileged operators have versus regular users - before you're comfortable going ahead and, like, disabling - some of those weaker methods, - things that are out there? I'm trying to - think over the last several months - when I've had to go in and get - into different environments. - I think - based on the last several months or even - years, - I think you could do two. One backup - method and a primary.
I think you could - get away with - and this - you could define the nuances here of backups. - I would go - with one passkey, - and this is where it's a nuance is. - Do you count one method as having, like, - two different UB keys and a passkey and - authenticator? - Does that count as just passkey, or is - that technically three different ways?
And then I - still have fallen back to - something in authenticator, - whether it's a push number matching. - There have been a couple times where I've - had to fall back to an OTP - where I go to try to log in - to Entra, and it says, we couldn't send - you a push notification right now. And I've - had to go back to that OTP route - using a code and authenticator, - or I will do some OTP codes in - one password. - So I think that's where I would fall - out as maybe something in authenticator, - whether a push or an OTP, - and - I would probably say multiple passkeys.
- One of them not being an authenticator, having - a physical - hardware - passkey, partly - challenges I have had with some of the - passkeys in Authenticator. I think you have to - do it. Like, it's kinda like the three - two one backup method thing. - And putting all your eggs in the Authenticator - basket is kinda hard, whether it's passkey - or it's OTP - through authenticator - or, like, push notification - with a number, things like that.
Because, like, - one, what if the authenticator app is broken - today, which could happen along the way. Like, - who knows? Like you said, you can't get - push notifications - or and that could be a failure on - Microsoft side, - could be a failure on the app side, - could be a connectivity thing, all all that. - So I think you have to have something - else to assess out of this.
So whether - that's, like, - device bound, like a FIDO two key - sitting, - like, there at your desk, which, yeah, maybe - that's got, like, a different, - like, token time out, and you have to - reauthenticate more. But at least you can get - into the environment, and you can do things - that's that that's an important one. I do - think there's less value in the world of - things like voice, - SMS, all that. Like, if you're gonna go - and say, like, hey.
321 - is - password - passkey on authenticator plus OTP on authenticator plus - a FIDO key, I think that kinda gets - you there. - SMS, - you're probably - for what? Like, 99 - plus percent of the time, SMSing the same - phone that authenticator - is already on. So or same thing with - voice.
You're calling at usually the same number, - things like that. So I don't think you - have to go down that path, and maybe - that helps you. Like, if you do go - start transitioning users - and getting them over, you can at least - get them used to the authenticator app for - all the foibles that it has. But at - least get them used to it and then - give them some kind of backup method outside - of that.
Ideally, in, like, a FIDO two - key, but then I think you do have - to weigh, like, one, do we wanna get - FIDO two keys for everybody? - Two, - which ones do we get? Because there is - the whole, like, support risk trade off thing - there that we were talking about with, like, - firmware and things like that. So maybe if - you got a bunch of YubiKeys years ago, - maybe you really don't wanna do those and - just wanna push customer or push your users - over to, - another kind of - authentication - method that's out there.
And I think admins, - because you also mentioned admins. I think this - is where the admin versus non admin one - becomes an interesting thing. Right? Like, my admins, - super privileged, - I I don't know.
I might actually wanna - make them, like, UB he only and authenticate - a whole bunch. Right? Like so I'm not - dependent on a device. I'm not dependent on - someone taking a device from them.
It's just - YubiKey. They've got like, we you can do - you can make things like pinbound requirements and - all that. So, like, I have some environments - that I authenticate to that has, like, a - 10 character password, others with an eight, some - with a six. Like, it's all over the - place, but you can do those kinds of - things.
And I think admins are a little - more willing to take on some of that - friction and burden even though we all hate - it. I think we're, like, positioned to do - it versus just a a regular user who - I would wanna have more, like, softer fallback - methods for, like, oh, hey. Passwordless, like like, - that whole, like, Bluetooth negotiation thing didn't work, - but you've got the option of doing a - push notification or, OTP - option - of doing a push notification - or, OTP through authenticator or something like that.
- So at least they're still in the same - app, same place kinda thing, and you can - move them towards the next. Yeah. And I - think as an admin too, I would also - say at least two YubiKeys or two FIDO - two keys. Like, don't just have one because - the last thing you want is - your global admin accounts or I mean, even - if you have multiple global admin accounts is - in an emergency, nobody can find their one - YubiKey.
They left it in the backpack. It's - at their desk and they're on the road. - Like, I have a YubiKey that pretty much - sits in my general desk - vicinity, but then I have another one that's - 99.9% - of the time - with me as I travel around, whether it's - a backpack or you have it on your - keys, whatever that is.
And then I also - I actually oftentimes have three where I have - another one that's just stuck away somewhere - if I need to get to it. But - I think you do have to be careful - when you start getting into some of the - admin and especially global admin. If you're gonna - rely on YubiKey only, don't rely on just - one YubiKey for that global admin. Have two - or three.
Even if one of them's in - a safe, like, stick it in the safe, - stick it away as a backup. You do - have to have some break glass someplace - to be able to get in and do - those things. But I think passwords, I would - say, are less and less. I honestly cannot - remember the last time I've needed my password - for Microsoft 365.
- Everything I've been able to do lately with - a either FIDO two or - a number matching - push notification - password list through - authenticator? I've only had to do passwords - on Windows devices - where, - for whatever reason, like Windows Hello for business - doesn't work or isn't available for so for - example, maybe like a virtual machine. So you - go, you spin up a virtual machine, you're - testing something out, you bind it to your - environment. - It might not have, like, a full TPM - or, like, a proper TPM to do, like, - Windows Hello for business.
- Especially, like, for you and I, we're typically - on Macs. Like, if you spin up a - VM in VMware Fusion or over in parallel - or something like that, like, you can do - Windows Hello on a TPM - via - a PIN, but your password's also sitting there, - like, ready to go and and enabled and - spun up. So I I think that's really - the only time that I use a password. - But you've had to use one?
I don't - use a FIDO key with macOS because they're - so janky there, but you do have, like, - touch ID on Macs, certain keyboards, and things - like that. So I think that's okay. But - on, like, the Windows side of things, like, - I'm probably - 90 plus percent - passkey, just authenticator - and, hey. Hope hope it binds to my - device the right way.
And then, really, I'm - only on FIDO keys for the devices that - require FIDO keys or for the environments that - I log into that require FIDO, but I - haven't changed my password - in years, I think. I think I still - have the same password that I started with - when I joined - Microsoft six years ago, which is kinda wild. - Right? I've worked for those organizations where you - change your password every ninety days.
I'm like, - I either Microsoft's wrong or they were wrong, - but I think Microsoft's right in in how - they're doing this thing and pushing it through. - So I think less and less. Like, there - there is, like, less of that reliance. - I think if you can get over the - technical hurdles and the technological hurdles, which no - matter what you say, like, I would die - on this hill, like, they are there, and - they do exist.
Yes. You're gonna have to - constantly kinda go with users and work with - them to get them through that. But - if you're willing to go down that path - and do it, I think it is an - interesting place - to land. So like I said, I would - love for Microsoft to provide more guidance, more - flexibility, and, like, things like those registration campaigns - and flows.
And I would actually love - to see, like, solid guidance or, like, even, - like, a canned implementation of, like, here's, like, - a sidecar website or something like that allows - you to stand this up in your environment - or in the cloud someplace - that allows for that new user onboarding. Like, - how do I onboard a new user in - the passwordless world, and I need to get - them, like, set up with a passkey on - authenticator? Like, that is still a very weird - flow and weird problem to go and solve.
- I've seen orgs solve that in different ways - with, like, custom websites - and different things that are out there. But - I think Microsoft could do a little bit - better kinda, like, shoring up the guidance there - and providing, like, here's the hero experience for - how those things go. So that way you're - not locked into the, well, here's the new - customer, client, or organization I'm joining, and every - single one has its own bespoke implementation of - a 20 page PDF that you've got to - go out and read and figure out.
100%. - So as always, thanks to folks for listening. - Questions, - comments, - hit us up on the website. We have - a contact form there.
If you'd be so - kind, give us a review - in your podcast or or place of choice. - Listen to us through Google Play, Spotify, - Apple Podcasts, things like that. We'd really appreciate - it. I would also call out Ben.
We - have a subreddit, and we publish all the - episodes over to a subreddit. We were hoping - to drive maybe some discussions there. - So, you know, if folks wanna - kinda go over to - Reddit what is our subreddit, Ben? Remind me.
- It's just m s cloud. - I have tried to unify everything around m - s cloud IT pro, and I believe Reddit - is - in the same boat. So if you go - to reddit.com/rmsclouditpro, - you'll see all of the podcast episodes out - there as well.
So if you wanna have - a discussion with us there, maybe the contact - form's a little hard to use, things like - that, Come and hit us up and leave - us a question or a suggestion, - anything like that. We always love the feedback - and the comments and new ideas that folks - bring. Absolutely. Well, thanks, Scott.
Go enjoy the - rest of your week, and we'll talk to - you soon. Thanks, Ben. Have a good one. - You - too.
If you enjoyed the podcast, go leave - us a five star rating in iTunes. It - helps to get the word out so more - IT pros can learn about Office three sixty - five and Azure. - If you have any questions you want us - to address on the show or feedback about - the show, feel free to reach out via - our website, Twitter, or Facebook. - Thanks again for listening, and have a great - day.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.