Microsoft is implementing significant changes to its authentication systems, continuing its years-long push toward passwordless security. The latest changes include the removal of password management features from Microsoft Authenticator and the introduction of mandatory multi-factor authentication (MFA) requirements across Azure services, marking a decisive shift in the company’s comprehensive transition away from traditional passwords.
The company has eliminated the password management functionality from the Microsoft Authenticator app while maintaining support for passkeys and other passwordless authentication methods. The modification follows Microsoft’s earlier announcement of phasing out password support entirely from the Authenticator app by August 1, 2025, representing a significant milestone in the company’s authentication strategy.
Starting September 1, 2025, Microsoft will enforce mandatory MFA for all Azure sign-in attempts across multiple services, including the Azure Portal, Entra admin center, Intune admin center, Azure CLI, PowerShell, mobile app, Infrastructure as Code tools, REST API operations, and Azure SDK. The requirement will be waived only when users employ stronger authentication methods such as passwordless or passkey (FIDO2) solutions. The change builds upon Microsoft’s recent success with passwordless authentication through Entra ID, which has demonstrated login speeds three times faster than traditional methods.
The company’s research indicates that MFA blocks more than 99.2 percent of account compromise attacks. As part of this security enhancement initiative, Microsoft is encouraging users to transition from password-based authentication to passwordless methods like passkeys or FIDO2. The requirement extends to emergency and break-glass accounts, with recommendations to use passkeys or certificate-based authentication to meet MFA requirements.
Administrative changes include the retirement of legacy MFA and Self-Service Password Reset (SSPR) policies, scheduled for September 30, 2025. System administrators will need to update their authentication policies to meet the new requirements. The changes match broader industry trends, as demonstrated by similar moves by other tech giants like Google Cloud to enhance workspace security with advanced authentication methods.
Microsoft is also implementing additional security features, including Certificate Revocation List (CRL) Fail Safe and Certificate Authority (CA) Scoping, though these are separate from the Authenticator password management removal initiative. The company has also expanded its authentication options in Microsoft Entra ID with new methods including SMS and QR code authentication, providing users with more secure alternatives during the transition period.
Sources: Microsoft Announces Changes to MFA and Authentication Management
Sources: Microsoft has removed the password management feature from Authenticator
Sources: Planning for mandatory multifactor authentication for Azure and other admin portals