Security

Phishing-resistant authentication for Microsoft 365 tenants: why Authenticator push is no longer enough, how passkeys actually work, and how to migrate without locking people out.

  • From Authenticator MFA to multi-device passkeys
    August 31, 2026 · 14 min read

    Authenticator push and TOTP (Time-based One-Time Password, a 6-digit temporary code) are still phishable. Synced passkeys, how the sign-in actually works, and a sequenced Entra rollout that does not strand people on a new phone.



© 2026 - EAC Partners
Privacy
An unhandled error has occurred. Reload 🗙