Microsoft is set to make passkeys the default authentication method in Microsoft Entra ID, marking a significant shift away from traditional, phishing-prone sign-in methods. This move also includes the retirement of Microsoft-provided SMS and voice authentication for multifactor authentication (MFA), encouraging organizations to adopt more secure, phishing-resistant credentials.
Starting September 1, 2026, users currently utilizing SMS or voice authentication will be automatically enabled for passkeys. During subsequent MFA sign-ins, these users will receive prompts to register a passkey. While Microsoft will manage the passkey registration campaign by default, users can defer the registration prompt during the transition period. This initiative aims to mitigate risks associated with SMS and voice-based authentication, which are susceptible to attacks such as phishing, SIM swapping, social engineering, number porting, and interception.
Passkeys employ cryptographic credentials tied to a device or credential manager, eliminating the need for reusable shared secrets that could be exploited on fraudulent websites. This design inherently resists phishing and replay attacks. Microsoft Entra ID supports both synced and device-bound passkeys. Synced passkeys can be stored in credential managers like iCloud Keychain or Google Password Manager, allowing usage across multiple devices. Device-bound passkeys remain on a specific device and include options such as Windows Hello for Business, Microsoft Authenticator passkeys, Entra Passkey on Windows, and FIDO2 hardware security keys.
The next critical milestone is February 1, 2027, when Microsoft will fully retire its native telecom delivery for SMS and voice in Entra ID. Organizations that continue to rely on these channels must transition to a customer-managed telecom provider available through the Microsoft Security Store. Microsoft plans to publish provider information starting September 18, 2026, with customer selection and configuration expected to be available from October 30, 2026.
Post-retirement, users whose sole MFA option is SMS or voice will encounter a blocking passkey registration prompt during sign-in, necessitating passkey registration before account access is granted. Microsoft has indicated that there will be no opt-out from this enforcement, making early migration essential to prevent account access disruptions.
Administrators are advised to identify users still enabled for SMS or voice authentication within the Entra Authentication Methods Policy or legacy MFA configurations. Microsoft provides a PowerShell-based analyzer to assist organizations in locating affected users. Security teams should enable Passkey (FIDO2), create targeted user groups, and initiate a staged registration campaign ahead of the automatic migration.
For enterprises, this announcement signifies that SMS and voice MFA should now be considered legacy fallback options rather than primary authentication controls. Organizations are encouraged to prioritize passkeys, Windows Hello for Business, and FIDO2 security keys, reserving customer-managed telecom services for specific regulatory or operational requirements.
Microsoft is offering a temporary opt-out for the automatic passkey enablement phase between September 1, 2026, and February 1, 2027. Administrators can use Microsoft Graph to set the passkeyDynamicMigration property in the authentication methods policy. However, this setting only delays the transition and does not prevent the February 2027 retirement and mandatory passkey registration requirement.
This strategic shift underscores Microsoft’s commitment to enhancing security by adopting more robust, phishing-resistant authentication methods. Organizations should proactively plan and implement these changes to ensure a seamless transition and bolster their overall security posture.