Microsoft Passkeys Replacing SMS & Voice Sign-in Methods

Microsoft is retiring SMS authentication for Microsoft 365 and Azure sign-ins, and passkeys will become the default authentication method in Microsoft Entra ID starting September 1, 2026. If anyone on your team still signs in with a text message or voice code, this change impacts your business directly. Here is what is changing, when it happens, and what your leadership team needs to decide before the switch becomes permanent.

Key Takeaways

  • Passkeys replace SMS and voice codes as the default Microsoft Entra ID sign-in method starting September 1, 2026. 
  • Microsoft-provided SMS and voice authentication stops working entirely on February 1, 2027. 
  • AI-enabled phishing campaigns now succeed at click-through rates as high as 54%, compared to roughly 12% for older campaigns, making SMS-based sign-in a growing liability. 
  • Businesses that build a passkey rollout plan before September 2026 will avoid help desk overload and login lockouts in 2027. 

Table of Contents

What is Changing with Microsoft Entra ID Authentication?

Three dates matter for every organization using Microsoft Entra ID, the identity system behind Microsoft 365 and Azure sign-ins:

  • September 1, 2026 – Passkeys will become the default, phishing-resistant sign-in method.
  • October 30, 2026 – Businesses with a regulated, technical, or operational need may select and configure a supported telecom provider through the Microsoft Security Store. 
  • February 1, 2027 – Microsoft SMS and voice authentication will no longer work.

What most organizations will experience in September:

This rollout will be gradual – so not every single organization will see the change on the first day. However, once it reaches your tenant, Microsoft’s official retirement documentation states that employees who currently receive a text or phone call code during sign-in will start seeing a prompt to register a passkey instead.

What most organizations will experience in February:

After February 1, anyone who has not switched will be blocked from signing in until they complete passkey registration. That is, unless your organization opts to continue using the sign-in methods, but you will be responsible for paying for the related telecom costs.

“Organizations that still require SMS or voice authentication methods will have the option to choose one of our telecom partners through the Microsoft Security Store. Customers will be responsible for any associated telecom-related costs charged by the telecom partners.”

What is a Passkey, in Plain Terms?

A passkey replaces a password and a text code with something the person already has:  

  • A fingerprint 
  • A face scan 
  • A device PIN 
  • A physical security key 

 

A passkey uses a cryptographic key along with biometrics or a device PIN, to verify a user’s identity – instead of a shared secret sent over a text message.  

So, there’s no code for an attacker to intercept, and no six-digit number for someone to trick an employee into typing into a fake login page.  

That is the entire reason Microsoft is making this the default instead of an option. It’s a much more effective approach to identity and access management.  

Watch Microsoft’s 4-minute video for more information on passkeys. 

Why Is Microsoft Retiring SMS and Voice Authentication?

Microsoft is retiring SMS and voice authentication because they are now the weakest widely used form of multi-factor authentication, and attackers have automated ways around both.

Text messages can be intercepted, and SIM swapping (where an attacker convinces a carrier to move a phone number to a new SIM card) is a well-documented way they have gotten past SMS-based sign-ins.

The threat has also become harder to detect. Microsoft Threat Intelligence has observed AI-enabled phishing campaigns reaching click-through rates as high as 54%, compared with roughly 12% for more traditional campaigns. Because of this, it’s important that Microsoft helps customers reduce their reliance on phishable authentication methods, such as SMS and voice.

What Impact Will This Have on Your Staff?

For most of your tech-savvy staff, this transition will be a minor adjustment.

However, employees who are less comfortable with technology – or who are more driven by habits – will find this a significant change to something they do every day, often multiple times a day.

Confusion at that scale tends to turn into help desk tickets, delayed sign-ins, and frustration during the rollout window.

What Should Business Leaders Do Before September 2026?

Don’t wait until January 2027 to build a plan. That leaves you with very little time before the legacy authentication methods stop working. 

Four actions, starting this quarter, keep this from becoming a scramble: 

  • Explain to staff why Microsoft is doing this (e.g., SMS and voice codes are increasingly phished, passkeys can’t be stolen by cybercriminals). Organizations that explain what is coming will get through this transition with far fewer support tickets. 
  • Explore whether your organization needs to pay for the telecom option through the Microsoft Security Store after February 1, 2027. Identify anyone with a genuine reason to keep SMS or voice – such as older devices, regulatory requirements, or remote workers without a smartphone. 
  • Find out how many employees currently sign in with SMS or voice authentication. Your managed IT provider or internal IT team can pull this directly from Entra ID admin settings. 
  • Build a passkey rollout plan before September 2026. Decide which devices support passkeys, what training your team needs, and who owns help desk volume during the switch. 
  • Have leadership make the switch first, publicly, if possible. By “leading from the front,” it signals to staff that this isn’t optional and it isn’t a scary process. 

Is There Still an Option to Keep SMS Authentication?

A small number of organizations have a genuine business, regulatory, or technical reason to keep phone-based authentication, such as CMMC-scoped environments or field workers without company smartphones.  

For those cases, Microsoft is not eliminating the option outright. Starting October 30, 2026, admins can select and configure a supported telecom provider through the Microsoft Security Store to keep SMS or voice authentication running for specific user segments. For everyone else, the recommended and no-additional-cost path is a passkey.

Getting Ahead of the Microsoft Passkeys Default Deadline

Passkey

Organizations that treat this as a September planning item, not a January scramble, are the ones whose employees stay signed in without a help desk pile-up.

If you want a straight answer on what the Microsoft Entra ID MFA changes mean for your specific environment, and how a managed IT provider can build and communicate the passkey rollout for you, that is a conversation worth having with your IT provider now, while there is still runway to plan it properly.

Latest Teal News
Recent Articles

Join Leading Execs to See What's Next in IT

Thousands of executives already get invited to live virtual events for straight talk on AI, M365, cybersecurity, compliance, and automation. Sign up today. 

Categories
Our Most-read Articles This Month

KEEP EXPLORING