Threat Intelligence • Identity Security

Microsoft Entra Passkeys: Prepare Before the Default Changes

From 1 September 2026, Microsoft Entra ID will automatically enable the passkey experience for users currently enabled for SMS or voice authentication. Organisations should prepare users now and complete their migration before Microsoft-provided SMS and voice delivery retires.

Trends4You Editorial

Executive summary

What is changing—and when

Microsoft is moving Entra ID users away from phishable SMS and voice authentication towards passkeys and other phishing-resistant methods. The change begins in September, but it is a staged transition rather than an immediate shutdown of SMS and voice.

Do not confuse the two dates

1 September 2026 changes the default experience for users enabled for SMS or voice. 1 February 2027 is when Microsoft-provided SMS and voice delivery is fully retired.

1 September 2026Users enabled for SMS or voice are automatically enabled for passkeys and may be prompted to register after completing MFA. Microsoft places the registration campaign into a Microsoft-managed state for those users.
18 September 2026Microsoft plans to publish more information about customer-managed telecommunications providers.
30 October 2026Customers with a genuine need to retain SMS or voice can begin selecting and configuring a provider through the Microsoft Security Store.
1 February 2027Microsoft-provided SMS and voice delivery retires. Users relying only on those methods may face a blocking passkey-registration prompt unless an alternative has been arranged.

Why it matters

Better security still needs careful adoption

Passkeys use cryptographic credentials rather than shared secrets and are resistant to phishing, SIM-swapping and replay attacks. That is a meaningful improvement, especially for organisations handling sensitive care, donor and workforce information.

However, an unmanaged rollout can create accessibility problems, support demand and account-recovery risks. Shared devices, volunteers, frontline workers, personal-device policies and users without compatible devices all need to be considered before enforcement.

Preparation plan

Six actions to take now

1

Find affected users

Use Entra authentication reporting and Microsoft's published discovery guidance to identify accounts enabled for or actively using SMS and voice. Include administrators, service owners, trustees, volunteers and external workers.

2

Choose supported methods

Decide which groups should use synced passkeys, Microsoft Authenticator passkeys, Entra Passkey on Windows, Windows Hello for Business or FIDO2 security keys. Avoid a single method for every user without testing their working context.

3

Design recovery before rollout

Document what happens when a phone is lost, a device is replaced or a user cannot complete registration. Require strong identity verification and maintain emergency administrative access.

4

Pilot with representative users

Test with a small group that reflects office, remote, frontline, volunteer and accessibility needs. Record registration failures and support questions before expanding.

5

Communicate in phases

Explain why the change is happening, what users will see and where they can obtain help. Follow with clear device-specific instructions and targeted reminders.

6

Measure completion and exceptions

Track registration, remaining SMS/voice dependency, failed sign-ins and approved exceptions. Review any operational need for a customer-managed telecom provider rather than treating it as the default migration route.

RACF-CC context

A practical identity improvement

This transition primarily supports RACF-CC Domain 1: Identity and Access Management. It also depends on Domain 2 for trusted devices, Domain 6 for sign-in monitoring, Domain 7 for account recovery and Domain 8 for documented ownership, exceptions and user communications.

Minimum viable outcome

Before February 2027, every user should have a tested phishing-resistant sign-in method, a workable recovery route and clear support instructions. SMS or voice exceptions should have a documented operational reason and owner.

Primary source

Follow Microsoft's live guidance

Microsoft may refine the rollout details. Recheck the live guidance before changing production authentication policies.

Voluntary support

Found this useful? Support Trends4You

Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.

Support is optional, handled securely by Stripe and does not provide additional access.