Entra ID & IdentityPlatform ChangesRetrospectives

Microsoft Ignite 2018: Passwordless Sign-In and Microsoft Threat Protection Arrive

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.

At Microsoft Ignite in September 2018, Microsoft made identity and threat protection central themes. Two announcements stood out: passwordless sign-in for Azure AD accounts using the Microsoft Authenticator app, and Microsoft Threat Protection, an integrated view across email, endpoints and identity.

Passwordless arrives for work accounts

Microsoft had offered phone sign-in for personal Microsoft accounts. At Ignite 2018, it announced passwordless phone sign-in for Azure AD work accounts in preview, alongside FIDO2 security key support in the roadmap. Microsoft argued that passwords were the root of most identity attacks and that the long-term goal was to remove them.

Integrated threat protection

Microsoft Threat Protection brought together Office 365 ATP, Windows Defender ATP and Azure ATP, with the promise of correlated investigation and automated response. It was the beginning of what would later become Microsoft 365 Defender and then Microsoft Defender XDR.

Why it mattered

These announcements set the direction for the next eight years:

  • Identity first: Azure AD (now Entra ID) at the center of security, not just sign-in.
  • Passwordless: a multi-year journey through Windows Hello, FIDO2 keys and eventually passkeys.
  • XDR: correlating signals across products rather than investigating each one in isolation.

In hindsight

Passwordless took longer than Microsoft hoped. Adoption accelerated only with passkeys and phishing-resistant MFA requirements years later. The XDR vision arrived faster. For customers, the practical lesson from Ignite 2018 is that roadmaps are long — and the organizations that started early on passwordless pilots were best prepared when phishing kits made traditional MFA unreliable.

microsoft passwordlessIgnite 2018 passwordless2018

More on this story