Microsoft Entra ID Passkeys: What Organizations Need to Know Before SMS and Voice MFA Change

Microsoft is changing how organizations use authentication in Microsoft Entra ID.

Starting September 1, 2026, Microsoft will begin making passkeys the default authentication method for users who are enabled for SMS or voice authentication. On February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice MFA. Organizations that still need SMS or voice authentication will need to select a supported telecom provider through the Microsoft Security Store and manage the associated costs themselves. (Microsoft)

That is the headline. But the bigger issue is this:

Organizations that still rely on SMS or voice MFA need to prepare now.

This update is not just a Microsoft setting change. It affects user sign-in, help desk support, MFA policies, security posture, Conditional Access, user communications, and account recovery planning.

SMS and Voice MFA Are No Longer Strong Enough

SMS and voice MFA were once common ways to add a second layer of protection to user accounts. But they are no longer considered strong enough for today’s identity threats.

Text messages and phone calls can be phished, intercepted, socially engineered, or abused through SIM swapping. Attackers have also become more effective at tricking users into approving sign-ins or giving away codes. Microsoft is pushing organizations toward passkeys because passkeys use public-key cryptography and are designed to resist phishing, replay attacks, and credential theft. (Microsoft Learn)

In simple terms, passkeys are a safer authentication method because the user is not typing or sharing a password or one-time code. Instead, the sign-in is tied to a cryptographic key pair and a trusted device, app, or security key.

This is part of a broader move toward phishing-resistant MFA.

Who Will Be Affected?

Organizations using Microsoft Entra ID should review this update, but the highest priority group is clear:

Users who still rely on SMS or voice authentication for MFA or self-service password reset are the most affected.

Microsoft says users enabled for SMS or voice will be automatically enabled for passkeys and prompted to register a passkey during MFA sign-in beginning September 1, 2026. After February 1, 2027, users who still rely on Microsoft-provided SMS or voice will need to register a passkey or use a customer-managed telecom provider if the organization configures one. (Microsoft Learn)

This matters for:

  • CIOs and IT leaders managing Microsoft Entra ID

  • Security teams responsible for MFA and identity protection

  • Help desk teams supporting sign-in issues

  • Employees who use SMS or phone calls to verify identity

  • Organizations with legacy MFA configurations

  • Organizations using SMS or voice for self-service password reset

  • Public cloud Microsoft Entra ID tenants

Microsoft’s current timeline applies to the public cloud. Other cloud environments will follow a separate timeline. Azure AD B2C is out of scope for this change, and Microsoft says External ID will have a separate announcement. Microsoft also notes that B2B and internal guest support for passkeys is planned by the end of calendar year 2026. (Microsoft Learn)

What Organizations Need to Do Now

Organizations should not wait until February 2027.

The best first step is to identify who is still using SMS or voice authentication. Microsoft recommends finding users who are enabled for SMS or voice in the Authentication Methods Policy or legacy MFA policy, then planning a passkey rollout. Microsoft also provides guidance for using scripts and reports to identify affected users. (Microsoft Learn)

From there, organizations should:

1. Review Current MFA Methods

Find out which users are using SMS, voice, Microsoft Authenticator, Windows Hello for Business, FIDO2 security keys, or other authentication methods.

This review should include employees, administrators, contractors, service desk accounts, shared-use scenarios, and any users with special access requirements.

2. Decide Which Passkey Types to Allow

Microsoft supports both synced passkeys and device-bound passkeys.

A device-bound passkey is tied to a specific device or security key. A synced passkey can be available across multiple devices through a supported passkey provider. Microsoft notes that device-bound passkeys may be preferred for highly regulated users or elevated-access roles, while synced passkeys may be easier to deploy broadly. (Microsoft Learn)

3. Plan User Communications

This change will affect how people sign in. That means communication matters.

Users need to know:

What is changing

Why passkeys are more secure

When they will be prompted

What device or method they should use

What to do if they lose a phone or security key

Who to contact for help

Do not let the first communication be a surprise prompt during sign-in.

4. Prepare Help Desk and Recovery Processes

If an employee loses a phone, security key, or passkey-enabled device, IT needs a clean recovery path.

Microsoft’s account recovery guidance explains that recovery can help users regain access when they lose access to all authentication methods, and that users may be issued a Temporary Access Pass so they can register new authentication methods. (Microsoft Learn)

5. Review Whether SMS or Voice Still Has a Business Need

Some organizations may still need SMS or voice authentication for regulatory, operational, or user-access reasons. If that is the case, Microsoft says those organizations will need to select and configure a supported telecom provider through the Microsoft Security Store. Microsoft plans to publish pricing and provider details on September 18, 2026, with provider configuration available beginning October 30, 2026. (Microsoft)

For most organizations, this should be treated as an opportunity to reduce reliance on SMS and voice.

Not sure how many users still rely on SMS or voice authentication?

Moser can help assess your current authentication methods, identify areas of dependency, and build a practical passkey transition plan.

What Deployment and Administration Teams Need to Do

Deployment and administration teams should treat this as an identity modernization project, not a last-minute settings update.

Administrators should prepare in four areas: policy, rollout, enforcement, and support.

1. Enable Passkeys in Microsoft Entra ID

Microsoft’s passkey deployment guidance says administrators can enable passkeys through the Microsoft Entra admin center by going to Protection > Authentication methods > Policies, then selecting Passkey (FIDO2). Admins can enable self-service setup, create passkey profiles, apply those profiles to groups, decide whether synced passkeys are allowed, and optionally enforce passkeys through Conditional Access authentication strength. (Microsoft Learn)

2. Use a Registration Campaign

A registration campaign can nudge users to set up passkeys during sign-in. Microsoft’s registration campaign feature lets administrators target users or groups, select the authentication method to promote, and control the campaign state. (Microsoft Learn)

This is important because users are more likely to adopt passkeys successfully when the rollout is phased and communicated clearly.

3. Create Different Policies for Different User Groups

Not every user has the same risk level.

Organizations may want different policies for:

  • Standard employees

  • Administrators

  • Executives

  • Developers

  • Service desk teams

  • Frontline workers

  • Contractors or guest users

  • Regulated users

  • Shared-device environments

High-risk or privileged users may need device-bound passkeys or FIDO2 security keys. Lower-risk users may be good candidates for synced passkeys, depending on the organization’s policy and risk tolerance.

4. Monitor Adoption and Reduce SMS/Voice Dependency

Administrators should track who has registered passkeys, who still uses SMS or voice, and which users are likely to need extra support.

The goal is not just to enable passkeys. The goal is to reduce dependency on weaker authentication methods before Microsoft-provided SMS and voice MFA delivery is retired.

Moser helps organizations plan, modernize, secure, and support complex technology environments. Through Moser’s Core Technology services, our teams help organizations manage infrastructure, cloud, modernization, automation, and operational support needs.

FAQ: Common Microsoft Entra ID Passkey Questions

When people say passkeys are the default authentication method in Microsoft Entra ID, what does that mean?

It means Microsoft will begin prompting users who are enabled for SMS or voice authentication to register a passkey as the default authentication method during MFA sign-in. This starts September 1, 2026.

Is Microsoft eliminating passwords in Microsoft Entra ID?

No. This update does not mean Microsoft is eliminating passwords entirely from Entra ID. The change is focused on making passkeys the default authentication method and retiring Microsoft-provided SMS and voice MFA telecom delivery.

Are passkeys replacing Microsoft Authenticator?

No. Passkeys are not replacing Microsoft Authenticator. Microsoft Authenticator can be used as a passkey provider, and Authenticator remains part of Microsoft’s broader authentication ecosystem.

Are passkeys replacing SMS and voice authentication?

Yes, for Microsoft-provided SMS and voice MFA delivery. Microsoft will retire its native SMS and voice telecom delivery on February 1, 2027. Organizations that still need SMS or voice must configure a supported telecom provider through Microsoft Security Store.

When does the Microsoft Entra ID passkey change take effect?

The rollout starts September 1, 2026. Microsoft-provided SMS and voice MFA delivery ends February 1, 2027. (Microsoft)

Why is Microsoft moving Entra ID users to passkeys?

Passkeys are more resistant to phishing than SMS, voice calls, and passwords. Passkeys use public-key cryptography and reduce reliance on codes that can be stolen, intercepted, or socially engineered.

How do I know whether my organization is affected?

Your organization is affected if users are enabled for SMS or voice authentication in Microsoft Entra ID, especially for MFA or self-service password reset.

What happens if you do not have that done by then, and SMS or voice is the only way you know how to sign in?

Users will not simply be silently locked out. After February 1, 2027, users who still rely on SMS or voice and do not have another valid method will receive a blocking passkey registration prompt. They will need to complete passkey registration before continuing sign-in.

Which Entra ID users will be prompted to register a passkey?

Users who are enabled for SMS or voice authentication are the primary group Microsoft will prompt to register passkeys. After February 1, 2027, passkey registration prompts will be enforced for users who still rely on Microsoft-provided SMS or voice MFA. (Microsoft Learn)

Are users who already use Microsoft Authenticator affected?

Users who already use stronger authentication methods may experience less disruption. However, if they are still enabled for SMS or voice, they may still be included in Microsoft’s passkey registration experience. Administrators should review policies rather than assuming Authenticator users are fully excluded.

Are Windows Hello for Business users affected?

Users already signing in with Windows Hello for Business can continue using it. Microsoft says users already using passkeys, Windows Hello for Business, or another phishing-resistant method can continue using those methods. (Microsoft Learn)

Does the change affect guest or B2B users?

Microsoft says B2B and internal guest users are included in scope, and passkey support for those users is planned by the end of calendar year 2026. Organizations with guest access should monitor Microsoft’s timeline closely. (Microsoft Learn)

Does it affect Azure AD B2C or Microsoft Entra External ID?

Azure AD B2C is out of scope for this change. Microsoft says External ID will have a separate announcement next year. (Microsoft Learn)

Does the passkey requirement apply to government cloud tenants?

The current Microsoft timeline applies to public cloud tenants.

Can organizations permanently opt out of passkeys?

No. Microsoft provides a temporary opt-out option for the September 1, 2026 to February 1, 2027 period, but there is no opt-out from the February 1, 2027 enforcement. (Microsoft Learn)

What happens if an organization does nothing before February 1, 2027?

Organizations that do nothing risk user disruption. Users who rely on Microsoft-provided SMS or voice MFA will need to register passkeys, or the organization must configure a supported telecom provider if SMS or voice authentication is still required.

How do we find users who still rely on SMS or voice?

Microsoft recommends identifying users enabled for SMS or voice through authentication method reporting and a PowerShell script. Administrators should review both modern Authentication Methods Policy settings and legacy MFA policy settings. (Microsoft Learn)

What is the difference between a synced and device-bound passkey?

A device-bound passkey is tied to one device, app, or hardware security key. A synced passkey can be available across multiple devices through a supported passkey provider.

Do passkeys work?

Yes. Passkeys are built on FIDO standards and use public-key cryptography. They are designed to make sign-in easier for users and harder for attackers to phish. (Microsoft Learn)

Will passkeys work on a shared computer or unmanaged device?

It depends on the device, browser, passkey provider, and your organization’s policies. Shared-device and unmanaged-device environments should be tested carefully. Administrators should decide which passkey types are allowed and use Conditional Access where appropriate.

What happens if an employee loses their phone or security key?

The organization should have an account recovery process. Microsoft supports recovery workflows such as Temporary Access Pass so users can regain access and register a new authentication method.

Can an employee create more than one backup passkey?

Yes, if organizational policy allows it. In many environments, allowing users to register more than one strong authentication method can reduce help desk burden and prevent lockout scenarios.

Can an attacker steal or copy a passkey?

Passkeys are much harder to steal or replay than passwords, SMS codes, or voice-based MFA. The private key is designed to stay protected by the device, app, security key, or passkey provider. That said, passkeys still need good governance. Organizations should protect devices, recovery processes, privileged accounts, and passkey provider policies.

Final Takeaway

Microsoft’s Entra ID passkey update is a strong move toward phishing-resistant authentication. But organizations should not treat it as a passive Microsoft rollout.

The practical work starts now:

  • Find SMS and voice users.

  • Plan the passkey rollout.

  • Communicate with employees.

  • Prepare help desk workflows.

  • Configure policies carefully.

  • Build a recovery process.

  • Decide whether SMS or voice still has a valid business need.

The organizations that prepare early will have a smoother transition, stronger identity security, and fewer user disruptions.

Ready to Prepare for the Microsoft Entra ID Passkey Update?

Talk with Moser about planning your Microsoft Entra ID passkey transition. We can help your team assess current authentication methods, identify SMS and voice MFA dependency, plan passkey deployment, prepare user communications, and reduce risk before the February 2027 deadline.Not sure how many users still rely on SMS or voice authentication?

Moser can help assess your current authentication methods, identify areas of dependency, and build a practical passkey transition plan.

Plan Your Entra ID Passkey Transition


Is Your Organization Ready for the Entra ID Passkey Transition?

Microsoft’s authentication changes are coming fast. Use our Entra ID Passkey Readiness Checklist to identify what your team needs to review, plan, and prepare before SMS and voice MFA changes take effect.

Next
Next

SQL Server 2016 is no longer supported. Is your business ready for what comes next?