If you use Microsoft 365, Outlook, Teams, or any other Microsoft service, you need to be aware of a significant change that Microsoft is rolling out. From 1st May 2025, Microsoft is making passwordless sign-in the default for all new personal accounts — and business accounts are firmly in the crosshairs for the months that follow. Here’s everything you need to know.
What Is Microsoft’s Passwordless Push?
Microsoft has been building towards eliminating passwords for years, and 2025 is when it gets serious. The company is replacing traditional passwords with passkeys — a modern, phishing-resistant authentication method built on FIDO2 industry standards.
Instead of typing a password, users verify their identity using a biometric (like a fingerprint or Face ID), a PIN, or a trusted device. The passkey itself is stored securely on your device, and a cryptographic key pair does the heavy lifting — meaning there’s no password to steal, guess, or leak in a data breach.
What’s Happening on 1st May 2025?
From 1st May 2025, all new Microsoft personal accounts (Outlook, Hotmail, Xbox, etc.) will be created as passwordless by default. Existing personal account holders are being strongly prompted to switch, and Microsoft’s sign-in pages are being redesigned to favour passkeys and passwordless methods over traditional password entry.
In practice, this means that when you sign in, Microsoft will first try to authenticate you without a password — using the Microsoft Authenticator app, a passkey, Windows Hello, or a one-time code — before falling back to a password prompt.
When Does This Affect Business Accounts?
For organisations using Microsoft Entra ID (formerly Azure Active Directory) — which underpins Microsoft 365, Teams, SharePoint, and most business Microsoft services — the passwordless rollout is already underway and accelerating throughout 2025.
Microsoft has been enabling system-preferred MFA across Entra ID tenants, which automatically pushes users towards the most secure available authentication method. For many business users, this means the Authenticator app’s number-matching push notifications rather than SMS codes — and increasingly, passkeys.
Here’s what the business timeline broadly looks like:
- Now (Q2 2025): Passkeys are fully supported in Microsoft Entra ID. Admins can enable them today. System-preferred MFA is active, pushing users to stronger methods automatically.
- Mid-2025 onwards: Microsoft is expected to make passkeys the recommended default for new Entra ID users and increase pressure on tenants to migrate away from weaker methods like SMS-based codes.
- Late 2025 – 2026: Legacy authentication methods (basic auth, SMS MFA, phone call MFA) are being progressively retired across Microsoft 365 services. Businesses still relying on these will start hitting access issues.
Why Is Microsoft Doing This?
The numbers are stark. Microsoft reports that password-based attacks account for the vast majority of identity breaches, with billions of phishing attempts targeting Microsoft accounts every year. Passkeys are inherently phishing-resistant — even if a user is tricked into visiting a fake login page, the passkey simply won’t work on an illegitimate site because it’s cryptographically bound to the real domain.
Beyond security, passkeys are faster. Microsoft’s own data shows passkey sign-in takes around 3 seconds compared to 69 seconds for a typical password plus MFA combination — a huge productivity win across an organisation.
What Does Your Business Need to Do?
This isn’t something to leave to the last minute. Here’s a practical checklist for IT administrators and business owners:
1. Audit Your Current Authentication Setup
Log into the Microsoft Entra admin centre and review your current Authentication Methods Policy. Identify how many users are still relying on SMS codes, phone calls, or — worst of all — passwords alone with no MFA.
2. Enable Passkeys in Your Entra ID Tenant
Passkeys (FIDO2) can be enabled now in the Entra admin centre under Authentication Methods > Passkeys (FIDO2). You can roll this out to a pilot group first before going organisation-wide.
3. Deploy and Enforce the Microsoft Authenticator App
If your users aren’t already on the Authenticator app, now is the time to run a registration campaign. The app supports both push notifications with number matching (a strong MFA method) and passkeys stored directly on users’ phones.
4. Phase Out SMS and Phone Call MFA
Once the Authenticator app is in place, begin disabling SMS and voice call MFA options. These legacy methods are increasingly viewed as insufficient and are being retired by Microsoft. Moving users off them reduces risk and future-proofs your setup.
5. Update Conditional Access Policies
Review your Conditional Access policies to require phishing-resistant authentication strengths for high-value applications and admin accounts. Microsoft provides built-in policy templates for this in the Entra admin centre.
6. Communicate with Your Users
Change management matters. Users who suddenly find their login experience has changed — or who are prompted to set up a new sign-in method — need clear, simple guidance. Prepare a brief communication explaining what’s changing and why, with step-by-step setup instructions.
7. Review Legacy Applications
Some older applications may still use basic authentication (username and password via legacy protocols). These will stop working as Microsoft retires basic auth across its services. Identify and update or replace these apps before they cause disruption.
What If You Do Nothing?
Ignoring this transition isn’t a viable option. Businesses that don’t act will face a combination of increasing security risk (as password-based accounts become more targeted), degraded user experience (as Microsoft’s sign-in flows are redesigned away from passwords), and eventual access issues as legacy authentication methods are formally retired.
How ML Services Can Help
Navigating Microsoft’s identity and authentication landscape can be complex, especially for organisations with legacy systems or limited IT resource. At ML Services, we help businesses assess their current setup, plan and execute the transition to passwordless authentication, and train users so the change feels seamless rather than disruptive.
If you’d like to understand where your business stands and what steps you need to take, get in touch with our team today. The sooner you start, the smoother the transition will be.
