
A major change is coming to the way people access Microsoft services
Microsoft is changing the default authentication experience in Microsoft Entra ID. From 1 September 2026, users who are enabled for SMS or voice multi-factor authentication may be automatically enabled for passkeys and prompted to register one after completing MFA during sign-in.
This is an important step towards stronger, phishing-resistant sign-in methods. It may also require careful preparation across your people, devices, policies and support processes.
The impact will be different for every organisation. Even if your employees usually approve sign-ins through Microsoft Authenticator, SMS or voice may still be enabled for some users or used as part of account recovery. This means your exposure may not be immediately obvious.
Understanding that exposure now can help you avoid confusing prompts, additional support demand and sign-in disruption later.
What is changing?
Microsoft Entra ID is making passkeys the default authentication experience for users who are currently enabled for SMS or voice authentication.
Passkeys use cryptographic credentials stored on a device or in a secure credential store. Unlike a code delivered by text message or phone call, the credential is not a shared secret that can be intercepted, stolen or reused. Microsoft describes passkeys as a phishing-resistant authentication method.
There are two key dates organisations need to understand:
1 September 2026
Users enabled for SMS or voice authentication will be automatically enabled for passkeys. When they next sign in and complete MFA, they may be prompted to register a passkey. Microsoft also advises organisations to notify users and prepare their environments for passkey use.
1 February 2027
Microsoft-provided delivery of SMS and voice authentication will be retired in Microsoft Entra ID.
After this date, users whose only available MFA method is SMS or voice will receive a blocking prompt and will need to register a passkey before they can continue signing in. There is no opt-out from this final retirement.
Microsoft Authenticator, Windows Hello for Business, passkeys and FIDO2 security keys remain available. The retirement specifically concerns Microsoft-provided SMS and voice authentication.
Why preparation matters
This is not simply a technical setting change.
If users begin receiving unfamiliar registration prompts without clear communication or guidance, they may not understand whether the prompt is legitimate or what they are expected to do. Organisations may then experience increased support enquiries, incomplete registrations or difficulty signing in.
There are also broader questions to consider:
- Which users are currently enabled for SMS or voice authentication?
- Are SMS or voice methods still supporting self-service password reset?
- Do affected users have another suitable authentication method available?
- Are their devices ready for passkey registration?
- How should privileged, frontline or shared-device users be supported?
- Are there business, regulatory or technical requirements that still rely on telephone-based authentication?
- What communication and support will employees need during the transition?
Microsoft recommends identifying users enabled for SMS or voice before planning the migration. It also advises moving users to phishing-resistant methods or choosing a customer-managed telecommunications provider if SMS or voice must continue.
A passkey rollout should be planned around your people
Stronger authentication is valuable, but the way it is introduced matters.
A successful transition should give employees clear, practical guidance about what is changing, why it matters and what they need to do. It should also recognise that different roles, devices and working environments may require different levels of support.
A planned approach may include:
- assessing users and authentication methods
- reviewing device and passkey readiness
- identifying account recovery dependencies
- agreeing on the right authentication approach for different user groups
- preparing clear employee communications
- providing practical registration guidance
- supporting exceptions and users with additional requirements
- validating registrations before removing existing methods
This creates a more controlled experience and helps ensure that stronger security does not come at the expense of accessibility, productivity or user confidence.
Can SMS or voice authentication continue?
Organisations with a documented business, regulatory or technical requirement may be able to continue using SMS or voice through a supported customer-managed telecommunications provider selected through the Microsoft Security Store. Microsoft recommends using this option only where a phishing-resistant method does not meet the organisation’s requirements.
This approach introduces additional considerations. The organisation is responsible for selecting and managing the provider relationship, including reviewing coverage, pricing, terms, security and compliance requirements.
For many organisations, this change represents an opportunity to reduce reliance on telephone-based authentication and adopt a more secure, sustainable approach.
How Entag can help
The first step is understanding where your organisation stands today.
Entag can work with you to understand your exposure to Microsoft’s SMS and voice MFA changes and establish a practical path forward. Depending on your environment and requirements, this may include:
- identifying users who are still enabled for or reliant on SMS and voice
- reviewing authentication and account recovery readiness
- assessing user and device requirements
- identifying potential exceptions
- planning a staged transition
- developing clear communications for your employees
- supporting users through registration and adoption
- helping your organisation move towards stronger, phishing-resistant authentication
Our focus is to make the change clear, manageable and aligned with the way your organisation operates. Technology is only part of the transition. The right guidance and support for your people are just as important.
Understand your exposure before the deadlines
The move away from Microsoft-provided SMS and voice MFA is approaching. Organisations that assess their environment early will have more opportunity to communicate clearly, support their users and choose the right authentication approach.
Contact Entag to understand your exposure and see how we can help you prepare for the change.