Executive summary
What is changing—and when
Microsoft is moving Entra ID users away from phishable SMS and voice authentication towards passkeys and other phishing-resistant methods. The change begins in September, but it is a staged transition rather than an immediate shutdown of SMS and voice.
Do not confuse the two dates
1 September 2026 changes the default experience for users enabled for SMS or voice. 1 February 2027 is when Microsoft-provided SMS and voice delivery is fully retired.
| 1 September 2026 | Users enabled for SMS or voice are automatically enabled for passkeys and may be prompted to register after completing MFA. Microsoft places the registration campaign into a Microsoft-managed state for those users. |
|---|---|
| 18 September 2026 | Microsoft plans to publish more information about customer-managed telecommunications providers. |
| 30 October 2026 | Customers with a genuine need to retain SMS or voice can begin selecting and configuring a provider through the Microsoft Security Store. |
| 1 February 2027 | Microsoft-provided SMS and voice delivery retires. Users relying only on those methods may face a blocking passkey-registration prompt unless an alternative has been arranged. |
Why it matters
Better security still needs careful adoption
Passkeys use cryptographic credentials rather than shared secrets and are resistant to phishing, SIM-swapping and replay attacks. That is a meaningful improvement, especially for organisations handling sensitive care, donor and workforce information.
However, an unmanaged rollout can create accessibility problems, support demand and account-recovery risks. Shared devices, volunteers, frontline workers, personal-device policies and users without compatible devices all need to be considered before enforcement.
Preparation plan
Six actions to take now
Find affected users
Use Entra authentication reporting and Microsoft's published discovery guidance to identify accounts enabled for or actively using SMS and voice. Include administrators, service owners, trustees, volunteers and external workers.
Choose supported methods
Decide which groups should use synced passkeys, Microsoft Authenticator passkeys, Entra Passkey on Windows, Windows Hello for Business or FIDO2 security keys. Avoid a single method for every user without testing their working context.
Design recovery before rollout
Document what happens when a phone is lost, a device is replaced or a user cannot complete registration. Require strong identity verification and maintain emergency administrative access.
Pilot with representative users
Test with a small group that reflects office, remote, frontline, volunteer and accessibility needs. Record registration failures and support questions before expanding.
Communicate in phases
Explain why the change is happening, what users will see and where they can obtain help. Follow with clear device-specific instructions and targeted reminders.
Measure completion and exceptions
Track registration, remaining SMS/voice dependency, failed sign-ins and approved exceptions. Review any operational need for a customer-managed telecom provider rather than treating it as the default migration route.
RACF-CC context
A practical identity improvement
This transition primarily supports RACF-CC Domain 1: Identity and Access Management. It also depends on Domain 2 for trusted devices, Domain 6 for sign-in monitoring, Domain 7 for account recovery and Domain 8 for documented ownership, exceptions and user communications.
Minimum viable outcome
Before February 2027, every user should have a tested phishing-resistant sign-in method, a workable recovery route and clear support instructions. SMS or voice exceptions should have a documented operational reason and owner.
Primary source
Follow Microsoft's live guidance
Microsoft may refine the rollout details. Recheck the live guidance before changing production authentication policies.
Voluntary support
Found this useful? Support Trends4You
Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.
Support is optional, handled securely by Stripe and does not provide additional access.
