Manufacturer reviewing Microsoft passkeys, cyber insurance requirements and CMMC compliance with an IT advisor.

Microsoft's 2027 Authentication Deadline: What Manufacturers, Defense Contractors, and Business Owners Need to Do Now

By Peter Noble, Founder & CEO, Noble Technology Group

Most business leaders I talk with are not losing sleep over passwords. They are focused on customer deadlines, production schedules, staffing challenges, quality, cash flow, compliance requirements, and keeping operations moving.

Unfortunately, cybercriminals know that. They understand that a manufacturer cannot simply pause production for several days without consequences. They know that an engineering firm needs access to drawings, email, cloud applications, and project records. They also know that a defense subcontractor may be under pressure to protect sensitive information while meeting demanding customer and compliance obligations.

That is why identity-based attacks deserve executive attention. In many incidents, an attacker does not need to break through a sophisticated firewall. The attacker only needs to obtain a valid username, password, or phishable verification code and sign in as though they belong there.

Microsoft's changing authentication roadmap should therefore be viewed as more than a technical update. Beginning September 1, 2026, Microsoft says passkeys will become the default authentication experience in Microsoft Entra ID for users enabled for SMS or voice. Those users will be enabled and prompted to register a passkey when they perform multifactor authentication. On February 1, 2027, Microsoft-provided telecom delivery for SMS and voice authentication will be retired. Microsoft recommends moving users to passkeys or another phishing-resistant authentication method before that date. Review Microsoft's Entra retirement timeline.

I see this as a clear signal of where cybersecurity, cyber insurance requirements, and compliance expectations are heading. Organizations that prepare now can reduce risk, improve the sign-in experience, strengthen audit readiness, and avoid turning a predictable change into an emergency project.

This is not really a passkey project. It is a business-risk and operational-resilience project.

This Is Not Really About Passkeys

The technology matters, but the business issue is identity security. For years, organizations have tried to manage password risk with longer passwords, complexity rules, password-expiration policies, security awareness training, and multi-factor authentication. Those controls can help, but passwords remain attractive to attackers because people can be persuaded to reveal them.

The expansion of artificial intelligence makes this problem more urgent. Microsoft Threat Intelligence has observed AI-enabled phishing campaigns reaching click-through rates as high as 54%, compared with roughly 12% for more traditional campaigns. That does not mean every AI-assisted message will succeed, but it does illustrate why familiar-looking email, polished writing, and personalized social engineering can no longer be treated as obvious warning signs. Read Microsoft's passkey security announcement.

Once an attacker gains access to a valid business account, the effects can spread quickly. Depending on the account and the environment, the attacker may attempt to:

  • Read email and impersonate an employee.
  • Change payment instructions or create fraudulent requests.
  • Access cloud files, customer records, or intellectual property.
  • Use the compromised account to target coworkers, vendors, and customers.
  • Establish persistence and wait for a more damaging opportunity.
  • Support a larger ransomware or data-extortion attack.

That is why I do not recommend treating authentication as an isolated IT setting. Identity controls should be connected to business continuity, incident response, cyber insurance, compliance, employee onboarding and offboarding, and the protection of critical operations.

Why Manufacturers and Defense Contractors Should Pay Attention

At Noble Technology Group, we focus on organizations where uptime, documentation, and customer trust have direct business value. That includes machine shops, precision manufacturers, aerospace suppliers, engineering firms, defense subcontractors, and other growing businesses that cannot afford unreliable systems or vague security practices.

For these organizations, cybersecurity has moved beyond the server room. Operations leaders are being asked questions by customers, prime contractors, insurers, auditors, and ownership teams. They need to know whether access is controlled, whether systems can be recovered, whether security practices are documented, and whether the company can provide evidence rather than verbal assurances.

If your company handles Controlled Unclassified Information, supports Department of Defense programs, or is preparing for CMMC, authentication is only one piece of the program, but it is an important piece. A secure sign-in process helps protect the boundary between an authorized user and the systems, applications, and information that user can reach.

Through Noble Technology Group's managed IT services, IT consulting, and compliance services, we help companies connect technology decisions to business requirements. The goal is not to install a new tool simply because it is available. The goal is to implement controls that are supportable, documented, appropriate for the environment, and aligned with the organization's actual risk.

Why Manufacturing Remains a Ransomware Target

Manufacturing is especially attractive to ransomware operators because downtime creates immediate pressure. When email is unavailable, office work slows down. When production scheduling, ERP, file access, shipping, labels, quality systems, or connected operational processes are unavailable, the business can quickly feel the impact in missed output and delayed commitments.

Black Kite's 2025 manufacturing report said manufacturing remained the number-one ransomware target for the fourth consecutive year and that attacks on manufacturers increased 9% compared with the prior year. The report connected the risk to expanding digital supply chains, complex technology footprints, and security vulnerabilities. It also reported that manufacturing represented 38.9% of ransomware victims among companies earning more than $1 billion, 30% among companies earning between $100 million and $300 million, and 17% among companies with less than $20 million, where manufacturing was the second-most-targeted industry. View Black Kite's manufacturing ransomware findings.

Separate reporting on 2025 ransomware activity stated that manufacturers experienced 1,466 attacks, up from 937 in 2024, a 56% increase. The same reporting said the average ransom demand for manufacturers rose from $523,000 in 2024 to nearly $1.2 million in 2025. Publicly reported figures do not describe every private incident, but the direction is clear enough for business leaders: attackers recognize the urgency created when production and supply chains stop. Review the reported 2025 ransomware data.

Manufacturing environments also present practical security challenges:

  • Legacy systems may be difficult to replace or patch without disrupting production.
  • Specialized equipment may depend on older software or vendor-controlled configurations.
  • Third parties may require remote access for support and maintenance.
  • Office IT and operational technology may have developed at different times under different owners.
  • Production demands can make maintenance windows difficult to schedule.
  • Smaller suppliers may have limited internal security resources despite meaningful contractual obligations.

Passkeys do not solve all of those issues. No single product does. But phishing-resistant authentication can remove or weaken one of the most common entry paths: stolen credentials. When combined with endpoint protection, secure configuration, segmentation, monitoring, tested backups, and employee training, stronger authentication becomes part of a layered risk-reduction strategy.

In manufacturing, cybersecurity is not only about protecting data. It is about protecting the ability to produce, ship, invoice, and keep promises.

The Growing Impact of Cyber Insurance Requirements

One of the biggest drivers of cybersecurity improvement today is cyber insurance. Applications and renewal questionnaires increasingly ask detailed questions about controls, not just whether a company owns antivirus software.

Depending on the carrier, policy, organization, and risk profile, the questions may address:

  • Multi-factor authentication for email, remote access, privileged accounts, and critical systems.
  • Endpoint detection and response.
  • Backup frequency, separation, immutability, and recovery testing.
  • Security awareness and phishing training.
  • Incident response planning.
  • Administrative access and account lifecycle management.
  • Vulnerability and patch management.
  • Protection of cloud and Microsoft 365 environments.

The exact requirements are determined by the insurer and the policy. Passkeys should not be presented as a guarantee of coverage, approval, or lower premiums. They are one control within a larger risk-management program. Still, a move toward phishing-resistant authentication can demonstrate that the organization is addressing credential theft with a control designed specifically to resist phishing.

I recommend reviewing insurance questions well before renewal. If a control is missing, the organization needs enough time to evaluate licensing, devices, user impact, configuration, deployment, documentation, and testing. Waiting until a renewal application is due often creates a rushed project, and rushed security projects are rarely the best security projects.

A qualified insurance professional should interpret policy language and coverage. Noble Technology Group's role is to help clients understand and improve the technology controls they can truthfully document. Our IT support and compliance services are built around practical implementation, clear documentation, and alignment between the written answer and the environment behind it.

What Is a Passkey?

A passkey is a passwordless credential based on public-key cryptography. When a passkey is created, the service retains a public key and the user's device protects the corresponding private key. The private key is not handed to the website during sign-in. The user approves authentication locally, commonly with a fingerprint, facial recognition, device PIN, or security key.

For a business leader, four points matter:

  • There is no reusable password to type into a fraudulent page.
  • The credential is associated with the legitimate service.
  • The user's device protects the private key.
  • The sign-in experience can be faster and simpler than a password plus a texted code.

This design is why passkeys are described as phishing-resistant. A fake website cannot simply collect a password and replay it against the real service. That is a meaningful security improvement over passwords and phishable one-time codes.

Passkeys are not the only phishing-resistant option. Windows Hello for Business and FIDO2 security keys may also fit an organization's needs. The right design depends on the devices people use, the applications they access, licensing, administrative capabilities, recovery needs, workforce locations, and compliance obligations.

Why SMS and Voice Authentication Are Being Retired

SMS and voice verification improved security compared with password-only authentication, but they rely on channels that can be intercepted, manipulated, socially engineered, or redirected. Microsoft states that SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID after the announced retirement.

Microsoft's timeline contains two milestones business leaders should put on their planning calendar:

  • September 1, 2026: Passkeys begin becoming the default authentication experience for Entra ID users enabled for SMS or voice. Microsoft says those users will be automatically enabled and prompted to register a passkey when they complete MFA.
  • February 1, 2027: Microsoft-provided telecom delivery for SMS and voice authentication is retired. Microsoft says users whose only available MFA method is SMS or voice will be required to register a passkey during sign-in to continue accessing their account.

Organizations that still require SMS or voice will need to evaluate customer-managed providers through Microsoft's identified path and any associated costs. For many businesses, the more strategic answer will be to move users to phishing-resistant methods instead of preserving a weaker process.

What Passkeys Mean for CMMC, NIST SP 800-171, and DFARS

Passkeys can support a compliance program, but they do not make a company compliant by themselves. CMMC and NIST SP 800-171 address a broad set of practices involving access control, identification and authentication, audit and accountability, incident response, configuration management, risk assessment, system integrity, media protection, personnel security, and other areas.

For a defense contractor, the useful question is not, "Do passkeys equal CMMC?" The useful questions are:

  • Which systems and users are in scope?
  • What information is being protected?
  • What authentication methods are currently used?
  • Which methods are phishing-resistant?
  • How are privileged and non-privileged accounts managed?
  • How will registration, recovery, revocation, and termination be documented?
  • What evidence will demonstrate that the control is operating?

That last question matters. Compliance requires more than an intended setting. Organizations need repeatable procedures, assigned responsibilities, supporting records, and evidence. A technically sound deployment can still create audit pain if nobody documents who owns it, how exceptions are handled, or how the company verifies continued operation.

Our approach to IT consulting and compliance services is to connect the technical control to the operational process. Policies become procedures. Procedures become checklists. Checklists create evidence. That is how a technology change becomes a defensible business practice.

A Real NTG Business-Continuity Story

One of the clearest reminders of why preparation matters came from Westflex. In Noble Technology Group's client materials, Elliot LeGros summarized the outcome after a catastrophic physical event in a few direct words:

"Headquarters burned down... back up the next day."
Elliot LeGros, Westflex

That statement is powerful because it is not really about a server, a cloud platform, or a backup product. It is about resilience. A headquarters fire is the type of event that can overwhelm an unprepared organization. The business outcome that mattered was the ability to recover and continue.

Another client, Joshua Carr of California Marine Cleaning, described Noble Technology Group as a:

"Trusted IT partner across three time zones... real-time problem solving."
Joshua Carr, California Marine Cleaning

Those experiences capture what clients are really buying when they invest in managed IT services. They are buying preparation, accountability, documentation, response, and the confidence that someone understands how technology supports the business.

Passkeys fit that same philosophy. They are not exciting because they use cryptography. They are valuable because they can reduce a common attack path, simplify sign-in, and support a more resilient identity strategy. The proper objective is not to chase technology. It is to reduce foreseeable risk before that risk becomes a disruptive event.

The Real Business Cost of Weak Authentication

Authentication can sound like a narrow technical topic, but a compromised identity can create consequences across the organization.

Operational impact

  • Production downtime and interrupted workflows.
  • Delayed shipments and missed customer commitments.
  • Employees unable to access email, files, or business applications.
  • Management pulled away from normal responsibilities.

Financial impact

  • Incident response, investigation, and recovery costs.
  • Lost productivity and revenue.
  • Legal, insurance, and notification expenses where applicable.
  • Emergency purchasing and rushed remediation.

Compliance and contractual impact

  • Customer questions and vendor-security reviews.
  • Corrective-action work and additional evidence requests.
  • Potential delays in compliance initiatives.
  • Concerns about the protection of sensitive information.

Reputational impact

  • Loss of customer confidence.
  • Strained supplier and partner relationships.
  • Leadership credibility placed under pressure.

Not every compromised account produces every outcome. The point is that identity security has business consequences. Strong authentication deserves the same disciplined planning as backups, disaster recovery, physical security, quality controls, and production maintenance.

Seven Steps to Prepare Before the 2027 Deadline

1. Identify users still enabled for SMS or voice

Start with facts. Determine which users are enabled for SMS or voice authentication and which users rely on those methods in practice. Microsoft specifically recommends identifying active SMS or voice users before planning the migration.

2. Map users, devices, and workflows

Document how employees sign in, what devices they use, whether devices are managed, which applications are critical, and where exceptions may exist. Include office staff, production users, remote employees, executives, service accounts, administrators, and third-party access.

3. Review cyber insurance requirements

Read the current application, renewal questionnaire, endorsements, and control representations. Have your insurance professional clarify policy questions. Then compare the stated controls with the actual environment and document gaps that require technology work.

4. Assess compliance and contractual obligations

Identify requirements arising from CMMC, NIST SP 800-171, DFARS, customer contracts, supplier agreements, or internal policies. Authentication decisions should support the larger compliance boundary rather than create an isolated solution.

5. Select the right phishing-resistant methods

Evaluate passkeys, Windows Hello for Business, and FIDO2 security keys. Consider user roles, device compatibility, recovery, administrative overhead, shared-workstation scenarios, privileged access, mobility, and supportability.

6. Pilot before broad deployment

Begin with a controlled group representing real-world use cases. Validate registration, normal sign-in, lost-device recovery, replacement devices, offboarding, help-desk procedures, and emergency access. Record what works and correct what does not.

7. Train users and preserve evidence

Tell employees what is changing, why it matters, and what they should expect. Update policies and procedures. Preserve deployment records, approvals, training documentation, configuration evidence, and exception decisions where those records support your compliance program.

The best migration is the one users understand, the help desk can support, and leadership can defend during an audit or insurance review.

Frequently Asked Questions About Passkeys and Compliance

Are Microsoft passkeys required for every business?

No. Microsoft has not said that every business must use passkeys in every scenario. Microsoft has announced that passkeys will become the default Entra ID authentication experience beginning September 1, 2026 for users enabled for SMS or voice, and that Microsoft-provided SMS and voice authentication will be retired February 1, 2027. Organizations should evaluate their user population and choose appropriate phishing-resistant methods.

Can passkeys help satisfy CMMC requirements?

Passkeys can support stronger identity and authentication controls, but they do not satisfy CMMC by themselves. A CMMC program includes many practices and requires documented, operational controls across the defined environment. Passkeys should be evaluated as one component of that broader program.

Do passkeys satisfy cyber insurance requirements?

That depends on the insurer, policy, application wording, and organization. Passkeys can support phishing-resistant authentication, but cyber insurance reviews commonly address many controls. Confirm insurance expectations with a qualified insurance professional and ensure technology answers accurately reflect the deployed environment.

Are passkeys better than SMS-based MFA?

Passkeys are designed to resist phishing because they use public-key cryptography and bind authentication to the legitimate service. SMS codes can be phished, intercepted, socially engineered, or redirected. Microsoft is moving users away from its native SMS and voice delivery toward passkeys and other phishing-resistant methods.

Will passkeys replace Microsoft Authenticator?

Not necessarily in every organization. Authentication strategies can include passkeys, Windows Hello for Business, FIDO2 security keys, and other methods based on the environment. The goal should be a supportable, phishing-resistant design rather than forcing every user into one method without analysis.

What happens if an employee loses a device?

The organization needs a documented recovery process. That process should address identity verification, revocation where appropriate, replacement-device registration, temporary access, and evidence of the action. Recovery should be tested during the pilot rather than designed during an emergency.

Do employees need new hardware?

Some existing devices may support passkeys or Windows Hello for Business, while other scenarios may call for FIDO2 security keys or device upgrades. A readiness assessment should confirm compatibility rather than assume it.

Are passkeys practical for shared manufacturing workstations?

They may be, but shared-workstation workflows require careful design. The organization should evaluate individual accountability, device ownership, shift changes, application support, recovery, and production impact. A pilot using actual shop-floor workflows is essential.

Will passkeys stop ransomware?

No single control stops all ransomware. Passkeys can reduce the risk of credential phishing, but organizations still need layered controls such as endpoint protection, secure configuration, patching, backups, monitoring, user training, incident response, and network protections.

Will prime contractors require passkeys?

Prime contractors often focus on required security outcomes and contractual obligations rather than one product. A specific customer may impose additional requirements. Review the applicable contract and security questionnaire instead of assuming passkeys alone will satisfy it.

How can Noble Technology Group help?

Noble Technology Group helps manufacturers, engineering firms, aerospace suppliers, defense subcontractors, and other growing organizations assess identity risk, review Microsoft 365 security, modernize authentication, document procedures, and align technology controls with business, insurance, and compliance goals.

Move From Reactive IT Support to Business Risk Management

Traditional IT support waits for something to break. Modern managed IT services should help the organization identify foreseeable risks, develop priorities, implement controls, document decisions, and verify that recovery processes work.

That does not mean every company needs every tool. It means every company needs a reasoned plan. A 30-person machine shop, a 150-person aerospace supplier, and a distributed professional-services firm may choose different authentication methods, but each should know:

  • Who can access critical systems.
  • How identity is verified.
  • How privileged access is protected.
  • How lost devices and terminations are handled.
  • How controls are monitored and documented.
  • How the business will continue after an incident.

That is the difference between buying technology and managing risk.

Is Your Business Ready for Microsoft's Authentication Changes?

If your organization still relies on SMS or voice authentication, now is the time to begin planning. Do not wait for registration prompts, an insurance renewal, a customer audit, or a compliance deadline to expose gaps that could have been addressed methodically.

Noble Technology Group can help you evaluate:

  • Current Microsoft Entra ID authentication methods.
  • Passkey, Windows Hello for Business, and FIDO2 readiness.
  • Identity risks affecting Microsoft 365 and critical applications.
  • Cyber insurance control questions.
  • CMMC, NIST SP 800-171, and contractual considerations.
  • Device compatibility, user workflows, and recovery procedures.
  • Policy, procedure, training, and evidence requirements.

Our goal is to make security practical. We want the control to work for the employee, the help desk, the operations team, the executive team, and the auditor.

Schedule an initial consultation with Noble Technology Group and let's build a clear plan for stronger authentication, better resilience, and fewer surprises.


About Peter Noble

Peter Noble is the Founder and CEO of Noble Technology Group, a La Mesa-based managed IT services, IT support, IT consulting, cybersecurity, and compliance services provider. Noble Technology Group helps manufacturers, engineering firms, aerospace suppliers, defense subcontractors, and growing organizations connect technology decisions to uptime, security, documentation, and business goals.

{
"@context": "https://schema.org",
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Are Microsoft passkeys required for every business?",
"acceptedAnswer": {
"@type": "Answer",
"text": "No. Microsoft has announced that passkeys will become the default Entra ID authentication experience beginning September 1, 2026 for users enabled for SMS or voice, and that Microsoft-provided SMS and voice authentication will be retired February 1, 2027. Organizations should evaluate their user population and choose appropriate phishing-resistant methods."
}
},
{
"@type": "Question",
"name": "Can passkeys help satisfy CMMC requirements?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Passkeys can support stronger identity and authentication controls, but they do not satisfy CMMC by themselves. A CMMC program includes many practices and requires documented, operational controls across the defined environment."
}
},
{
"@type": "Question",
"name": "Do passkeys satisfy cyber insurance requirements?",
"acceptedAnswer": {
"@type": "Answer",
"text": "That depends on the insurer, policy, application wording, and organization. Passkeys can support phishing-resistant authentication, but cyber insurance reviews commonly address many controls."
}
},
{
"@type": "Question",
"name": "Are passkeys better than SMS-based MFA?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Passkeys are designed to resist phishing because they use public-key cryptography and bind authentication to the legitimate service. SMS codes can be phished, intercepted, socially engineered, or redirected."
}
},
{
"@type": "Question",
"name": "Will passkeys replace Microsoft Authenticator?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Not necessarily in every organization. Authentication strategies can include passkeys, Windows Hello for Business, FIDO2 security keys, and other methods based on the environment."
}
},
{
"@type": "Question",
"name": "What happens if an employee loses a device?",
"acceptedAnswer": {
"@type": "Answer",
"text": "The organization needs a documented recovery process addressing identity verification, revocation where appropriate, replacement-device registration, temporary access, and evidence of the action."
}
},
{
"@type": "Question",
"name": "Do employees need new hardware?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Some existing devices may support passkeys or Windows Hello for Business, while other scenarios may call for FIDO2 security keys or device upgrades. A readiness assessment should confirm compatibility."
}
},
{
"@type": "Question",
"name": "Are passkeys practical for shared manufacturing workstations?",
"acceptedAnswer": {
"@type": "Answer",
"text": "They may be, but shared-workstation workflows require careful design around individual accountability, device ownership, shift changes, application support, recovery, and production impact."
}
},
{
"@type": "Question",
"name": "Will passkeys stop ransomware?",
"acceptedAnswer": {
"@type": "Answer",
"text": "No single control stops all ransomware. Passkeys can reduce credential-phishing risk, but organizations still need layered controls such as endpoint protection, secure configuration, patching, backups, monitoring, training, and incident response."
}
},
{
"@type": "Question",
"name": "Will prime contractors require passkeys?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Prime contractors often focus on required security outcomes and contractual obligations rather than one product. Review the applicable contract and security questionnaire instead of assuming passkeys alone will satisfy it."
}
},
{
"@type": "Question",
"name": "How can Noble Technology Group help?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Noble Technology Group helps organizations assess identity risk, review Microsoft 365 security, modernize authentication, document procedures, and align technology controls with business, insurance, and compliance goals."
}
}
]
}

{
"@context": "https://schema.org",
"@type": "Service",
"name": "Managed IT, Cybersecurity and Compliance Services",
"serviceType": [
"Managed IT Services",
"IT Support",
"IT Consulting",
"Cybersecurity Services",
"Compliance Services",
"CMMC Readiness Support",
"Microsoft 365 Security"
],
"provider": {
"@type": "LocalBusiness",
"name": "Noble Technology Group",
"url": "https://nobletechgroup.com",
"telephone": "+1-619-752-1620",
"address": {
"@type": "PostalAddress",
"streetAddress": "7777 Alvarado Rd. Suite 705",
"addressLocality": "La Mesa",
"addressRegion": "CA",
"postalCode": "91942",
"addressCountry": "US"
}
},
"areaServed": [
{
"@type": "AdministrativeArea",
"name": "San Diego County, California"
},
{
"@type": "Country",
"name": "United States"
}
],
"audience": {
"@type": "BusinessAudience",
"audienceType": "Manufacturers, engineering firms, aerospace suppliers, defense subcontractors, and growing businesses"
},
"url": "https://nobletechgroup.com",
"offers": {
"@type": "Offer",
"url": "https://nobletechgroup.com/initial-consultation/",
"description": "Initial consultation for managed IT, cybersecurity, Microsoft 365 security, and compliance planning."
}
}