started · updated
Microsoft and Google announce new security updates for authentication and mobile privacy
Microsoft has announced a roadmap to phase out SMS-based multi-factor authentication due to rising security risks from AI-driven attacks, such as SIM swapping and sophisticated phishing. Starting February 1, 2027, IT administrators will no longer be able to use SMS for Microsoft Entra ID logins. The company is shifting focus toward more secure methods, including PINs, biometrics, and passkeys, which store authentication data directly on devices rather than on servers.
In a separate development, Google is introducing a native ‘App Lock’ feature in the Android 17 QPR2 Beta. This system-level security tool allows users to lock specific applications using fingerprints or PINs by long-pressing an app icon. When an app is locked, the system also hides notification previews, widgets, and home screen shortcuts associated with that application to enhance privacy. Android 17 is expected to be officially released in December.