惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
腾讯CDC
爱范儿
爱范儿
Google DeepMind News
Google DeepMind News
V
V2EX
Blog — PlanetScale
Blog — PlanetScale
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
量子位
F
Fortinet All Blogs
G
Google Developers Blog
T
The Blog of Author Tim Ferriss
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
T
Tailwind CSS Blog
J
Java Code Geeks
S
SegmentFault 最新的问题
D
Docker
博客园 - 司徒正美
The GitHub Blog
The GitHub Blog
Jina AI
Jina AI
M
MIT News - Artificial intelligence
博客园 - 【当耐特】

Latest news

I tested Surfshark's new Dausos VPN protocol - here's how it compares to WireGuard How to easily encrypt your files on an Android phone - for free I'm not giving up on DJI cameras yet - not when they can upset my GoPro like this The best website builders for small businesses in 2026: Expert tested and reviewed Why I'm recommending last year's phones over 2026 models - with one exception This powerful Gemini setting made my AI results way more personal and accurate After testing this HP laptop, I get why its 'boring' design is adored by business users The best TV antenna of 2026: Expert tested Your old iPad or Android tablet can be your new smart home panel - here's how Apple's original AirTag still tracks effectively, and you can get a 4-pack for its best price ever T-Mobile will give you an iPad for $99 when you sign up for a new line - here's how How to qualify for Apple's education discount - and get a $499 MacBook Neo for school T-Mobile will give you a Samsung Galaxy Watch 8 for free - how to get yours Prolonged AI use can be hazardous to your health and work: 4 ways to stay safe Verizon will give you a free iPad or Apple Watch with your next iPhone - how the deal works The best laptops of 2026: Expert tested and reviewed I hid 4 Bluetooth trackers (including AirTags) to test their reliability - here's how Android rivals compared I stopped using my iPhone's hotspot after testing this 5G router - and that won't change The best Kindles in 2026: Expert recommended Does Best Buy price match? Everything to know about matching prices online and in-store The best WordPress hosting services of 2026: Expert tested and reviewed The best Apple Watch of 2026: Expert tested and reviewed The best TV screen cleaners of 2026: Expert recommended The best 50-inch TVs of 2026: Expert tested I traded my Sonos Era 300 for Denon's new home speaker - and see no reason to go back AI-powered website builders have come a long way - here's your best option in 2026 Amazon just slashed $250 off the Google Pixel 10 - and a Prime subscription isn't required I found the apps slowing down my PC - how to kill the biggest memory hogs These companies are actually upskilling their workers for AI - here's how they do it Verizon will give you Meta Ray-Bans for free with this Fios Internet deal - how to get yours
Microsoft won't send you SMS texts for login anymore - wh...
Written by Lance Whitney, ContributorContributor May 21, 2026 at · 2026-05-21 · via Latest news
Authenticate a Microsoft account with a passkey
Screenshot by Lance Whitney/ZDNET

Follow ZDNET: Add us as a preferred source on Google.


ZDNET's key takeaways

  • Microsoft is phasing out SMS as an authentication method.
  • SMS messages are unencrypted and vulnerable to hackers.
  • Microsoft account owners will be prompted to set up a passkey instead.

When trying to sign-in to or recover one of your online accounts, you'll often receive a text message that prompts you to verify that you're the account owner. But that SMS-based message is not a secure authentication method. Now, Microsoft is putting the brakes on it for anyone who uses a Microsoft account.

Also: Mobile phishing is a bigger threat than email now - how to stay protected

On a new support page, Microsoft announced that it will start phasing out SMS as an authentication and account recovery method for personal Microsoft accounts. Instead, the company is pushing passkeys, which offer much stronger security.

What makes SMS authentication so insecure?

Why is SMS such a poor form of authentication? No matter which messaging app you use, SMS lacks end-to-end encryption to protect the text during its journey. As such, the message can be intercepted by hackers who then gain access to the included security code.

One common tactic is SIM swapping. Here, a hacker who snags your text can use the security code to sign in to your mobile account, thereby convincing your carrier to transfer your number to a different SIM. From there, they can receive SMS authentication texts sent to your number, allowing them to take over your personal accounts one by one.

"SMS-based authentication is now a leading source of fraud, and by moving to passwordless accounts, passkeys, and verified email, we're helping you stay ahead of evolving threats while making account access simpler and more seamless," Microsoft said on its support page. "SMS authentication is vulnerable to phishing and SIM-swap attacks. We're replacing it with passkeys and verified email for better protection and convenience."

Also: Should you stop logging in through Google and Facebook? Consider these SSO risks vs. benefits

Mobile carriers are certainly aware of the risks of SIM swapping, and many now offer SIM protection  that locks your phone line to guard against unauthorized changes. However, SMS is still an inherently weak and vulnerable authentication method.

With SMS on its way out, how would you verify a login or recovery for your Microsoft account? For that, Microsoft said it will guide you through the process of adding a verified email and passkey. If you'd rather not wait and want to set up a passkey right away, another Microsoft support page explains how to do that.

Yet another reason to use a password manager

One hiccup with passkeys is that they're device-specific. What happens if you create a passkey on your computer but then need to use it on your mobile phone, or vice versa? To get past that barrier, Microsoft suggests using a password manager to store the passkey and use it on any device where the program is installed.

Most major password managers now support passkeys, including the Microsoft Password Manager in Edge, Google Password Manager, Apple Passwords, 1Password, NordPass, Bitwarden, and Dashlane.

Also: The best password managers: Expert tested

Another method is to save a passkey to a physical security key, which you can then plug into your PC or mobile device to authenticate your account. Alternatively, you can save the passkey on your mobile phone and scan it when you need to sign in on your computer. On Windows PCs, Windows Hello also supports passkeys. Whichever method you choose, you would typically use your face, fingerprint, security key, or PIN to sign in with the passkey.

Though the transition to passkeys does require several steps, the short-term pain is worth the long-term gain, as they say. I applaud Microsoft for making this change. I wish more companies would follow suit.

Security