Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice multifactor authentication (MFA) delivery services on February 1, 2027.
According to Microsoft, the transition is part of Microsoft’s broader effort to eliminate phishable credentials as enterprises expand cloud usage, remote access, and AI-enabled workflows.
Passwords, one-time SMS codes, and voice-based verification remain frequent targets of credential phishing, adversary-in-the-middle attacks, SIM swapping, social engineering, and replay attacks.
Microsoft Entra ID Makes Passkeys Default
Under the new policy, Entra ID tenants with users currently enabled for SMS or voice authentication will have those users automatically enabled for passkeys through the Authentication Methods Policy. When an affected user subsequently signs in and is prompted for MFA, Entra ID will prompt them to register a passkey.
Microsoft will configure the Registration Campaign in a Microsoft Managed state and automatically target eligible users. This approach is intended to reduce administrative effort while accelerating adoption of phishing-resistant authentication across enterprise tenants.
Passkeys use public-key cryptography rather than shared secrets. A private key remains protected on the user’s device or authenticator, while the service retains the corresponding public key.
Because no reusable password or one-time code is transmitted during authentication, passkeys are designed to resist credential theft and phishing-based account takeover. Entra ID supports both synced and device-bound passkeys.
Synced passkeys can be stored in credential managers, including iCloud Keychain and Google Password Manager, allowing users to access credentials across supported devices. Device-bound passkeys remain associated with a particular platform or authenticator.
Examples of device-bound authentication options include Windows Hello for Business, Microsoft Authenticator, Entra Passkey on Windows, and FIDO2 hardware security keys.
Organizations with higher assurance requirements may prefer device-bound credentials or hardware-backed keys, particularly for privileged accounts, administrators, and sensitive business systems.
Microsoft-provided SMS and voice MFA services will be retired on February 1, 2027. Organizations that still require telecom-based MFA after that date must use a customer-managed provider available through the Microsoft Security Store. Microsoft plans to publish information on supported providers beginning September 18, 2026.
Customer selection and configuration capabilities are expected to become available on October 30, 2026, leaving enterprises with only a limited period to evaluate, procure, test, and deploy an alternative telecom provider before the native service’s retirement.
The retirement creates a significant operational risk for organizations that defer migration. After February 1, 2027, users relying solely on SMS or voice authentication will receive a blocking passkey-registration prompt.
They must register a passkey to maintain access to Entra-protected applications and resources. Microsoft has stated that this enforcement will apply to all tenants and that no opt-out option will be available after the retirement date.
Administrators should therefore identify affected users in the Entra Authentication Methods Policy and legacy MFA settings as early as possible.
Microsoft has published a PowerShell-based usage analyzer to help organizations assess their dependence on SMS and voice MFA. Running the assessment requires Global Reader, Authentication Policy Administrator, or Security Reader permissions.
A staged migration should include enabling FIDO2 passkeys, creating security groups for affected users, launching a registration campaign, and issuing targeted end-user communications.
Although users can initially snooze enrollment prompts indefinitely, organizations should establish internal deadlines and provide clear instructions for passkey registration and recovery.
Administrators can temporarily postpone automatic passkey enablement and registration campaigns between September 1, 2026, and February 1, 2027.
Using Microsoft Graph beta, administrators with the Policy.ReadWrite.AuthenticationMethod permission can set the passkeyDynamicMigration opt-out property to true. However, that setting does not delay the SMS and voice retirement deadline.
Enterprises needing out-of-band telecom authentication must deploy a customer-managed provider before February 2027, while most organizations should prioritize passkeys, Windows Hello, or other phishing-resistant methods to avoid user disruption.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

