Microsoft has told IT administrators to move Entra ID users off SMS and voice-based first-factor sign-in before it shuts the option down in February 2027. Alternatives include passkeys, QR code authentication, and FIDO2 security keys, and the change applies even to organizations using their own telephony providers for multifactor authentication. The retirement covers only workforce tenant scenarios, not customer identity products like Entra External ID.
bleepingcomputer.com
· 2026-09-21
Security researchers, including work from SpecterOps, have documented at least 39 distinct methods that can undermine passkey authentication despite the underlying FIDO2 cryptography remaining secure. These techniques target the surrounding infrastructure rather than the cryptographic keys themselves, including browsers, operating systems, password managers, sync services, Bluetooth transport, and account recovery workflows. Many have working proof-of-concept tools, and some techniques are already surfacing in real-world attack activity.
bleepingcomputer.com
· 2026-09-04
AC2 is a new open protocol designed to let AI agents request verifiable human sign-off before taking consequential actions, such as merging code, sending client messages, calling APIs, or executing payments. It installs into existing frameworks via a plugin and single command, using DIDComm v2.0 messaging and passkey authentication through Liquid Auth (FIDO2/WebAuthn), without needing a central relay server or blockchain.
ac2protocol.org
· 2026-08-27