Microsoft's September Deadline: The End of SMS Verification for Enterprise Logins
Published on 08/02/2026 at 00:32 | Redaktion boerse-global.de
Corporate IT departments running Microsoft's ecosystem face a hard cutoff this autumn as the tech giant accelerates its passwordless transition. The company's August 1 release of Edge 151.0.4129.59 didn't just patch vulnerabilities — it set the stage for a mandatory migration that will retire one of the most familiar security rituals in the enterprise world: the SMS code.
Come September 1, 2026, organizations using Microsoft Entra ID will see their multi-factor authentication (MFA) flows automatically shift from text-message and voice-based verification to passkeys. The old methods won't simply fade away quietly, though. Microsoft has pinned February 1, 2027 as the date when SMS and voice MFA are switched off for good.
The browser update itself brings a few housekeeping changes that IT teams should note. Apple users will need macOS 13 as the minimum operating system to run Edge going forward. Microsoft has also pulled the plug on the browser's built-in Drop feature, while support for Microsoft Translator in older versions ended on July 30, 2026. These moves reflect a broader effort to slim down legacy functionality and steer users toward more modern, secure infrastructure.
The Phishing Wave Behind the Policy Shift
The urgency isn't theoretical. Security researchers tracking threat actor Storm-2945 — operating under the Midnight Blizzard umbrella — have flagged an aggressive campaign dubbed CaptiveCrunch. The attack chain starts with compromised hotel Wi-Fi networks, where attackers tamper with DNS and HTTP traffic to reroute guests toward fake update pages or malicious device-code phishing portals.
Since July 16, 2026, there's been a noticeable uptick in attackers steering victims toward Microsoft's device-code authentication flow. The numbers paint a stark picture: roughly 99 percent of device-code phishing attacks target Microsoft infrastructure, and between 10 and 15 new campaigns emerge every 24 hours. Two malware strains are doing heavy lifting in these operations — CornFlake, a Go-based remote-access trojan, and ChocoShell, a PowerShell credential stealer. Both have been in active circulation since early May 2026.
As you tighten authentication and close down phishing vectors, don't overlook the gaps in your workplace safety documentation that could leave your business exposed to enforcement action. A free Health & Safety Toolkit gives you ready-to-use risk assessments and checklists that help you meet UK compliance duties without hours of paperwork. Download the free Health & Safety Toolkit
Cloud Hardening and AI Defenses
On the infrastructure side, Microsoft quietly closed out July with some notable security milestones. Native CIS benchmark assessments for Linux virtual machines on Azure became generally available on July 31, covering RHEL, AlmaLinux, Rocky, and Ubuntu distributions. The company also confirmed that CosmosEscape — a critical vulnerability in its Cosmos DB service — was fully remediated during July.
Artificial intelligence is increasingly part of the defensive playbook. Microsoft's MAI-Cyber-1-Flash model, built on 137 billion parameters, posted a 95.95 percent success rate in the CyberGym benchmark, suggesting AI-assisted threat detection is maturing into a practical tool rather than a research curiosity.
While AI-driven defenses handle cyber threats, protecting your people from physical hazards requires a different kind of diligence — one that's documented and audit-ready. Over 37,000 UK businesses rely on a free toolkit that covers essential compliance areas from fire safety to manual handling. Get the free Risk Assessment Toolkit
For security teams navigating this transition, the guidance from experts is straightforward: keep VPN usage consistent, disable the device-code flow where feasible, and move to phishing-resistant MFA without delay. The September switchover may feel abrupt, but the threat landscape driving it shows no signs of letting up.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
