Microsoft is steering Entra ID tenants away from text-message sign-in and toward passkeys, turning an old convenience feature into a migration deadline.
A stage-by-stage look at identity shows why the real security question is not which SSO logo you buy, but how far the platform can stretch as the company and its app estate grow.
A 2026 MFA roundup puts the spotlight on a bigger truth: the safest login control is the one that matches the environment, especially when phishing-resistant methods and legacy app coverage diverge.
A new wave of passwordless tools is less about replacing passwords and more about deciding whether trust lives on the device, in the identity provider, or inside a verified onboarding flow.
A 2026 roundup of eight customer identity platforms is really a map of modern login risk - who owns the identity boundary, how users recover access, and how much password debt an organization is still carrying.
A branded payment reminder can look routine, but in the wrong hands it becomes a fast path from inbox to credential-harvesting page.
A familiar security term can now be used to lower suspicion, while the real target remains Microsoft 365 access, sessions, and tenant persistence.
GOV.UK One Login is shifting millions of users toward passkeys, a change that reduces dependence on passwords but also makes device security and recovery flows far more important.
GOV.UK One Login is moving toward passkeys for more than 23 million users, a shift that weakens password and SMS-based attacks while leaving recovery and fallback design as the pressure points.
A pair of Microsoft-linked campaigns shows how modern fraud now targets email infrastructure and the recovery steps around cloud identity, not just passwords.
Google has introduced a direct transfer path for passwords and passkeys between managers on Android, shifting a long-sensitive workflow away from export files and toward on-device, user-approved exchange.
The dangerous part is not the passkey itself, but the human workflow around identity recovery, where urgency and trust can be turned into account takeover.
A portable rogue base station can push nearby phones onto weaker mobile conditions and deliver phishing texts that look like trusted carrier notices.
A compromised Windows PC can turn Google’s passkey workflow into a post-compromise target, showing that strong cryptography does not remove the need to trust the browser, sync layer, and recovery path.
A set of 39 documented techniques shows how attackers can target prompts, enrollment, recovery, and synced credentials without defeating FIDO2 cryptography itself.
A password manager is never just a vault anymore: Proton Pass is bundling encrypted credentials, aliases, built-in 2FA, dark web monitoring, and passkeys into one identity-defense stack.
A partnership expansion into Australia and nine other countries lands alongside a stronger sign-in rule for OpenAI's Trusted Access for Cyber program, putting phishing-resistant authentication at the center of access control.
A discounted bundle for encrypted passwords, passkeys, aliases, and leak alerts shows how consumer security is moving from isolated tools to layered identity control.
A new security update adds multiple passkeys, longer alphanumeric passwords, and caller context - a small set of changes that could matter a lot in a platform where trust is often tested before a message is even opened.
New security features point to a broader shift away from one-time codes and toward phishing-resistant authentication, with extra friction added before users trust an unknown caller.