Microsoft is transforming its identity strategy, declaring passwords an ‘attack surface.’ On World Passkey Day 2026, it detailed a comprehensive plan to make passkeys the default for Entra ID, Windows, and consumer accounts by late May 2026. Enhanced account recovery and the removal of security questions by January 2027 underscore a future where passwords are obsolete.