Microsoft just changed how millions of organizations sign into their accounts. The company is retiring SMS and voice authentication in Microsoft Entra ID, and passkeys by default will become the standard sign-in method for every tenant. This shift affects any business running Microsoft 365 or Entra ID, and the clock is already running.
Security teams need to understand this change now, not in six months. Passkeys by default will start rolling out automatically, and businesses that wait too long risk login disruptions for employees. This article breaks down the timeline, the reasoning behind the move, and the steps your business should take before enforcement begins.
What Microsoft’s Passkeys by Default Announcement Actually Changes
Microsoft Entra ID is shifting away from SMS and voice as native authentication methods. Passkeys by default will become the automatic sign-in experience for any user currently enrolled in SMS or voice multi-factor authentication. Instead of typing a code sent to a phone, users will confirm sign-in with a device credential, a security key, or a biometric prompt.
This is not a minor feature update. Microsoft describes it as part of a broader industry push toward phishing-resistant authentication. Because SMS and voice codes can be intercepted or socially engineered, Microsoft is removing them as a first-line defense for most tenants.
The Retirement Timeline for SMS and Voice
Three dates matter most for planning purposes.
On September 1, 2026, passkeys by default become active for any user currently enabled for SMS or voice. Those users get automatically enrolled in passkey registration and nudged during sign-in. On February 1, 2027, Microsoft-provided SMS and voice delivery is fully retired. After that date, users whose only MFA method is SMS or voice face a blocking prompt requiring passkey registration before they can sign in.
There is no opt-out for the February enforcement. Every tenant is affected, regardless of size or industry.
Why Microsoft Is Moving to Passkeys by Default
Security drives this decision more than convenience. SMS and voice codes were never designed to withstand modern phishing techniques, and attackers have adapted quickly. Passkeys use cryptographic key pairs instead of shared secrets, so there is no code to steal, forward, or replay.
The Security Problem with SMS and Voice Codes
SIM-swap attacks let criminals hijack a phone number and intercept authentication codes directly. Voice calls face similar risks through call forwarding and social engineering against carriers. Meanwhile, phishing kits built specifically to capture one-time codes have become common and cheap to deploy.
The Cybersecurity and Infrastructure Security Agency has called phishing-resistant multi-factor authentication the strongest available defense against account takeover. Passkeys meet that bar because the sign-in ceremony binds cryptographically to the legitimate website. A fake login page simply cannot complete the handshake, so credential theft through phishing becomes far harder.
Adoption data backs up the shift. The FIDO Alliance reports that over half of surveyed users have already enabled a passkey on at least one account. Businesses that delay adoption are now behind, not ahead, of where the market already sits.
What Passkeys by Default Means for Your Business Right Now
Every organization using Microsoft Entra ID needs a plan before September 1, 2026. Waiting until the deadline arrives creates unnecessary risk and rushed decisions. Instead, treat this as a structured rollout with clear ownership.
Step 1: Find Out Who Still Uses SMS or Voice
Start by identifying every user enrolled in SMS or voice authentication today. Microsoft provides a PowerShell script through its passkey deployment guide to generate this list quickly. Once you know who is affected, you can prioritize outreach and registration support.
Step 2: Build a Passkey Rollout Plan
Passkeys by default work differently depending on the device and platform involved. Some employees will use synced passkeys stored in a password manager, while others will use device-bound passkeys tied to a laptop or security key. Decide which model fits your workforce, then configure a registration campaign inside Entra ID to prompt users during their next sign-in.
Give IT staff and help desk teams the training they need before rollout begins. Employees will have questions, and a prepared support team keeps friction low.
Step 3: Decide If You Need a Telecom Provider
Some businesses have a genuine regulatory or operational reason to keep SMS or voice active. If that applies to your organization, plan to configure a customer-managed telecom provider through the Microsoft Security Store starting in late 2026. For everyone else, passkeys by default should be the target end state for all users.
Risks of Waiting to Adopt Passkeys by Default
Delaying your passkey rollout creates two separate problems. First, users who remain on SMS or voice past February 2027 will hit a blocking registration prompt with no warning if IT has not prepared them. This can halt productivity across an entire department during a busy workday.
Second, businesses that skip planning often rush the rollout later, which increases help desk tickets and user frustration. A phased approach, starting with awareness and ending with reminders, keeps the transition smooth. Coretelligent has seen this pattern play out across managed cybersecurity services engagements, where early communication consistently reduces support volume during authentication changes.
How to Prepare Your Team for the Passkey Transition
Clear communication matters as much as technical configuration. Tell employees why the change is happening, what they need to do, and when the deadline falls. Use short, direct messages rather than lengthy policy documents that go unread.
Pair this communication with hands-on registration support. Set up short walkthroughs for Windows Hello, Microsoft Authenticator, and hardware security keys so employees are not left guessing. Phishing-resistant methods only work if people actually register and use them correctly, so training deserves real investment. Coretelligent’s guidance on defending against modern email attacks outlines similar principles for rolling out stronger authentication without overwhelming end users.
Track registration progress weekly. If adoption stalls in a specific department, address it directly instead of waiting for the deadline to force compliance.
Passkeys by Default and the Bigger Picture for Business Security
This retirement is part of a larger trend across the technology industry. Google, Apple, and most major identity providers are pushing passkeys as the new standard, so Microsoft’s move is not happening in isolation. Businesses that build strong passkey adoption now will be better positioned for future authentication requirements from regulators and cyber insurers alike.
Passkeys by default also reduce the operational burden on IT teams over time. Fewer help desk tickets related to lost codes or undelivered texts translate into real savings. Additionally, phishing-resistant authentication lowers the odds of a costly account takeover, which protects both revenue and reputation.
Getting Your Business Ready Before the Deadline
The passkey transition is not optional, and the timeline is fixed. Businesses that start now will avoid the blocking prompts, help desk surges, and compliance gaps that come with waiting. Passkeys by default represents a meaningful security upgrade, but only for organizations that plan the rollout carefully.
Coretelligent helps businesses navigate authentication changes like this one without disrupting daily operations. Our outsourced CISO services can help your leadership team build a passkey rollout plan, identify at-risk users, and communicate the change clearly across your organization. If your business needs support preparing for Microsoft’s authentication changes, reach out to discuss a plan tailored to your environment.