Passkeys Hit Critical Mass: Microsoft Auto-Enables for Millions, 87% of Companies Deploy as Passwords Near End-of-Life
Microsoft begins auto-enabling passkey profiles across all Entra ID tenants, triggering the largest enterprise migration to passwordless authentication in history — as new data shows 87% of companies are deploying passkeys and 69% of consumers already have at least one.

A digital illustration representing passwordless authentication with passkey icons replacing traditional password fields
Microsoft has begun automatically enabling passkey profiles across all Microsoft Entra ID tenants, triggering what analysts are calling the largest enterprise migration to passwordless authentication in history. Organizations that have not configured custom settings by early April will have passkey defaults applied automatically, affecting millions of enterprise users globally.
The move comes as new research from the FIDO Alliance and HID Global shows 87% of U.S. and UK companies have deployed or are actively deploying passkeys, while consumer adoption has risen to 69% — up from just 39% two years ago.
March 2026: The Tipping Point
Security experts have long predicted a moment when passwordless authentication would shift from emerging technology to mainstream standard. That moment has arrived.
Microsoft's automatic passkey enablement, disclosed in Message Center notification MC1221452 in January 2026, represents the company's most aggressive push toward passwordless authentication to date. The rollout follows this timeline:
- Early March 2026: General Availability rollout beginsThe move comes as new research from the FIDO Alliance and HID Global shows 87% of U.S. and UK companies have deployed or are actively deploying passkeys, while consumer adoption has risen to 69% — up from just 39% two years ago.
March 2026: The Tipping Point
Security experts have long predicted a moment when passwordless authentication would shift from emerging technology to mainstream standard. That moment has arrived.
Microsoft's automatic passkey enablement, disclosed in Message Center notification MC1221452 in January 2026, represents the company's most aggressive push toward passwordless authentication to date. The rollout follows this timeline:
- Early March 2026: General Availability rollout begins
- Early April – Late May 2026: Automatic migration for tenants that have not opted in
- June 2026: Government cloud environments (GCC, GCC High, DoD) follow
The update introduces a new passkeyType property, enabling administrators to configure device-bound passkeys, synced passkeys, or both — replacing the previous single tenant-wide FIDO2 policy with granular, group-based profiles.
What Is Changing in Microsoft Entra ID
The new Passkey Profiles system introduces several key capabilities. Administrators can now create up to three group-based configuration profiles, with more planned. The update draws a clear distinction between device-bound passkeys — backed by hardware such as Windows Hello or FIDO2 security keys — and synced passkeys, which operate across devices via iCloud Keychain, Google Password Manager, or third-party managers like 1Password and Bitwarden.
Attestation enforcement is also now available, providing cryptographic proof of a passkey's make and model during registration. Registration campaigns can be configured to automatically target passkey enrollment rather than defaulting to Microsoft Authenticator.
Synced passkeys address the primary adoption barrier enterprises have faced: cross-device usability. Previously, device-bound passkeys required re-registration on every machine. Synced passkeys maintain phishing resistance while allowing seamless authentication across a user's devices. The trade-off is that synced passkeys do not support attestation in Entra ID — organizations requiring cryptographic hardware verification must continue using device-bound passkeys only.
Reddit Uses Passkeys to Verify Human Presence
In a development announced March 24, 2026, Reddit revealed plans to deploy passkeys as a primary defense against its bot problem — introducing a novel use case that goes beyond traditional authentication.
Reddit CEO Steve Huffman described the approach as "ass in seat" verification: confirming that a real human is physically present and interacting with the platform, regardless of the tools they are using. Face ID, Touch ID, and biometric passkeys require physical human presence, making them an effective and lightweight proof-of-humanness mechanism.
Critically, Reddit's implementation is designed to preserve anonymity. The platform wants to know whether a user is a real person, not who that person is. Enforcement will be targeted — only accounts displaying suspicious or unusual activity will be prompted to verify. Automated accounts must be disclosed as bots by users.
The move comes as Reddit faces mounting regulatory pressure on age assurance. The UK Information Commissioner's Office fined the platform £14.47 million in February 2026 for failures in age assurance under UK data protection law. Passkeys offer a path to verify humanness without collecting personally identifiable information — a critical capability for platforms navigating global privacy regulations.
Reddit's approach aligns with a broader industry movement around proof of personhood, which is gaining momentum as AI-generated content and sophisticated bots proliferate across major platforms.
Security Research: Vulnerabilities in Google Authenticator's Synced Passkeys
As adoption accelerates, security researchers are uncovering new attack surfaces in cloud-synced passkey implementations. Research published by Palo Alto Networks on March 25, 2026 identified hidden mechanisms in Google Authenticator's synced passkey architecture that introduce cybersecurity risks organizations must now account for.
Google's passkey ecosystem relies on a cloud component that handles sensitive cryptographic operations, passkey synchronization across macOS, Windows, Linux, and ChromeOS, and management of the Security Domain Secret — a master key that encrypts all synced passkeys.
The synchronization process works as follows: Chrome establishes a secure peer-to-peer connection with Google's cloud authenticator using WebSockets and the Noise Protocol. The cloud authenticator decrypts the master Security Domain Secret, generates a new passkey, encrypts it, and sends it to the device before uploading it to Chrome Sync for distribution across all enrolled devices.
Palo Alto Networks identified several risk areas in this architecture. If an attacker compromises the communication channels, they could potentially impersonate a trusted synced device. Cloud-based weaknesses may be exploitable for unauthorized passkey authentication. Anomalous authentication patterns across distributed devices are also difficult to detect without purpose-built monitoring.
The research does not invalidate synced passkeys as a technology, but it does underscore a trade-off that organizations must actively manage: synced passkeys sacrifice some of the guarantees provided by hardware-bound keys in exchange for cross-device convenience. Security teams are advised to treat cloud identity infrastructure as an evolving attack surface, monitor for anomalous authentication patterns, and audit for misconfigured access permissions.
Adoption by the Numbers
Multiple data sources confirm that passkey adoption has reached critical mass heading into 2026.
On the consumer side, FIDO Alliance research from November 2025 found that 69% of consumers now have at least one passkey, up from 39% two years prior. More than half consider passkeys more convenient than passwords, and 53% believe they offer greater security. Dashlane's Passkey Power 20 report from October 2025 reported that passkey authentications doubled year-over-year to 1.3 million per month, with login times up to 17 times faster than traditional passwords on platforms like TikTok.
Enterprise adoption mirrors this trajectory. A survey of 400 executives conducted by HID and the FIDO Alliance found that 87% of companies have deployed or are deploying passkeys, with two-thirds rating deployment as a high or critical priority. Password usage dropped 26% following passkey implementation, and organizations reported an 85% reduction in password reset support costs.
Platform-level deployments have driven significant volume. Google reports over 800 million accounts now use passkeys. Amazon saw 175 million users create passkeys in the first year following rollout — roughly 25% of its customer base — with login speeds six times faster than traditional passwords. Microsoft reported a 120% increase in authentications after making passkeys the default for new accounts in May 2025, with a 95% success rate compared to 30% for legacy methods.
Regulatory Pressure Is Forcing the Timeline
Government mandates are accelerating enterprise migration, particularly in financial services. The UAE Central Bank set a March 31, 2026 deadline requiring all licensed financial institutions to eliminate SMS and email one-time passwords. India's deadline for phishing-resistant MFA in financial services falls on April 1, 2026. The Philippines has set a June 2026 deadline for SMS OTP elimination across regulated financial institutions, and the EU Digital Identity Wallet is scheduled to roll out by the end of 2026.
In the United States, NIST SP 800-63-4, published in July 2025, requires that AAL2 multi-factor authentication offer a phishing-resistant option. AAL3 requires phishing-resistant authenticators with non-exportable private keys. The USPTO discontinued SMS authentication in May 2025, FINRA followed in July 2025, and both the FBI and CISA have issued warnings against SMS-based authentication.
SMS one-time passwords are being phased out across regulated industries for compounding reasons: they are vulnerable to SIM swapping and SS7 attacks, they add friction that drives abandonment, and OTP delivery infrastructure carries ongoing cost. Passkeys address all three failure modes simultaneously.
The Business Case Is Proven
Real-world deployments have consistently produced strong business outcomes alongside security improvements.
HubSpot, which launched passkeys in December 2024, reported a 25% improvement in login success rates over passwords and login times four times faster than passwords combined with two-factor authentication. Air New Zealand saw a 50% reduction in login abandonment and a 30% increase in conversions. Sony PlayStation reported 88% faster enrollment globally and 24% faster login times. Microsoft's own deployment resulted in authentication that is 14 times faster than legacy methods.
Why 2026 Is the Inflection Point
Several converging factors explain why passkey adoption accelerated sharply in 2025 and 2026. Universal browser support has been in place since 2022 across Chrome, Safari, and Edge. Operating system readiness spans iOS 16, Android 9 and above, macOS Ventura, and Windows 10 and 11. Production-ready identity provider integrations are now available from Okta, Azure AD, Auth0, and Ping Identity. Cross-platform credential portability, once a significant barrier, has been resolved through Apple's import and export capabilities, Google Password Manager's end-to-end encrypted sync, and full passkey support from 1Password, Bitwarden, and Dashlane.
The result is that what once required a six-month migration project can now be completed in two to three development sprints, with IAM platforms providing drop-in WebAuthn widgets, automated fallback strategies, and admin-level attestation support.
What Organizations Should Do Now
For enterprises navigating Microsoft's automatic passkey enablement, the immediate priority is to review current FIDO2 settings in Microsoft Entra ID under Security → Authentication Methods → Policies. Organizations should decide whether to opt in during the March General Availability rollout — retaining control over configuration — or accept Microsoft's defaults when automatic migration begins in April.
Beyond the immediate Microsoft deadline, a phased rollout approach is recommended. Most organizations begin by enabling passkeys for security-conscious early adopters and IT teams, collect feedback, measure login success rates and support impact, then expand gradually. Only 21% of organizations deploying passkeys target all users immediately, according to HID and FIDO Alliance research. Most prioritize high-value accounts, users with access to sensitive data, and technically proficient early adopters before broadening rollout.
Account recovery planning is essential and frequently overlooked. Organizations should establish backup passkeys on secondary devices, one-time recovery codes, admin reset workflows with verified identity, and where appropriate, biometric identity verification against government-issued ID documents.
Most enterprises will ultimately deploy both device-bound and synced passkeys, matching the passkey type to the risk profile of the application or user group rather than applying a single approach across the board.
Looking Ahead
Industry analysts project that passkeys will become the default authentication method for consumer applications between 2026 and 2027, with enterprise deployments reaching mainstream scale between 2028 and 2030. Passwords are expected to persist as a legacy fallback during this transition period before becoming effectively obsolete for new accounts beyond 2030.
Gartner has predicted passkeys will become the primary authentication method by 2027, with 2026 marking the decisive inflection point. The data from this month — Microsoft's forced migration, Reddit's proof-of-humanness deployment, and security research exposing the next generation of identity threats — suggests that prediction is on track.
The question for organizations is no longer whether to adopt passkeys, but how quickly the transition can be completed before regulatory deadlines, security incidents, and competitive pressure remove the choice entirely.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.