Passkeys become the default in Entra ID as SMS MFA ends

Microsoft is making passkeys the default sign-in experience in Microsoft Entra ID and ending its own delivery of one-time codes by SMS and voice call. From 1 September 2026, users currently enabled for SMS or voice will be automatically enabled for passkeys and prompted to register one at their next sign-in with MFA. From 1 February 2027, Microsoft retires SMS and voice for good – with no option to opt out.

What changes on 1 September 2026

On that date, Microsoft additionally enables every user who is allowed to use SMS or voice in the authentication methods policy or in the legacy MFA settings for passkeys. At the same time, the tenant registration campaign is set to the “Microsoft Managed” state and targeted at those users. The next time they complete an MFA sign-in, they are nudged to set up a passkey.

  • The prompt can be snoozed an unlimited number of times at first – in September it does not yet block sign-in.
  • Anyone already using a passkey, Windows Hello for Business or another phishing-resistant method can carry on unchanged.
  • A temporary opt-out is available through Microsoft Graph: set the passkeyDynamicMigration property in the authentication methods policy to true. It only works until 1 February 2027.

From 1 February 2027, SMS and voice are gone

On that date, Microsoft retires its own delivery of SMS and voice calls in Entra ID. Users whose only available MFA method is SMS or voice are asked to register a passkey during sign-in – and that prompt is then blocking. Without a registered passkey they can no longer get into their account. Microsoft states explicitly that there is no opt-out from this behaviour and that it applies to every tenant.

For companies without a dedicated identity team, that is the real sticking point: starting in January 2027 risks a rush on the help desk – from exactly those users who cannot sign in and therefore cannot help themselves either.

Why Microsoft is retiring SMS and voice

SMS and voice call are no longer considered secure second factors. Both rely on a shared secret travelling across third-party networks and are vulnerable to phishing, SIM swapping and replay. Passkeys instead use cryptographic key pairs tied to a device or a synced credential store, and they cannot be phished. Microsoft distinguishes between synced passkeys held in the platform credential manager and device-bound passkeys such as the passkey in Microsoft Authenticator, Entra Passkey on Windows or FIDO2 hardware security keys.

If SMS really has to stay: your own telecom provider

Where a telephony channel is indispensable for regulatory or operational reasons, SMS remains possible – but only through a telecom provider you contract yourself via the Microsoft Security Store. From 18 September 2026, Microsoft publishes information about the available providers; from 30 October 2026, a provider can be selected and configured. That means a separate contract and additional cost, so it should be deliberately limited to the few user groups that genuinely need the channel.

What companies should do now

  • Find out which users in Microsoft Entra ID are still enabled for SMS or voice – Microsoft provides a PowerShell script for this. What counts is being enabled in the policy, not actual usage.
  • Enable passkey (FIDO2) as a method and start the registration campaign deliberately before 1 September, rather than letting it happen to you automatically.
  • Review service, break-glass and shift accounts as well as users without a company device – this is where passkey registration most often fails.
  • Announce the change early and hand out short instructions per device type; Microsoft provides ready-made communication templates.
  • Establish whether a regulatory reason for SMS exists and document it – only then is the route via your own telecom provider worthwhile.

Official Microsoft sources

How many of your users still depend on SMS, and how to move them to passkeys without sign-in outages, is something we assess as part of a Microsoft Security Assessmentget in touch.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment