Microsoft is set to revolutionize its authentication protocols by making passkeys the standard for Microsoft Entra ID by September 1, 2026. This strategic move signifies a shift from traditional SMS and voice multifactor authentication (MFA) methods, which are more susceptible to phishing attacks.
Transition to Passkeys
From September 2026, users currently relying on SMS or voice authentication will transition to passkeys. Microsoft will initiate an automatic enablement process for these users, who will encounter prompts to register a passkey during their future MFA sign-ins. This transition aims to enhance security by minimizing the vulnerabilities associated with SMS and voice authentication.
Passkeys offer a more secure alternative by utilizing cryptographic credentials linked to a user’s device or credential manager. Unlike traditional methods, they do not involve shared secrets, thus mitigating risks of phishing and replay attacks. Supported by Microsoft Entra ID, these passkeys can be synced across devices using credential managers like iCloud Keychain or remain device-bound with options such as Windows Hello for Business.
Key Dates and Deadlines
Microsoft has outlined significant dates in this transition. By February 1, 2027, the company will discontinue its native telecom support for SMS and voice in Entra ID. Organizations planning to continue using these methods must switch to a customer-managed telecom service through the Microsoft Security Store, with provider details available from September 18, 2026.
Post-February 2027, users without passkeys will encounter a mandatory registration prompt to access their accounts. Organizations are encouraged to migrate early to avoid disruptions, as there will be no opting out of this enforcement.
Implementation and Preparation
Administrators are advised to identify users utilizing SMS or voice methods through the Entra Authentication Methods Policy or legacy MFA settings. Microsoft offers a PowerShell-based tool to assist in locating these users. Security teams should enable Passkey (FIDO2), form targeted user groups, and execute a phased registration campaign before automatic migration begins.
Despite a temporary opt-out available between September 1, 2026, and February 1, 2027, through Microsoft Graph settings, this does not circumvent the eventual requirement. Enterprises must treat SMS and voice MFA as backup options and prioritize the adoption of passkeys and FIDO2 security keys.
This transition underscores the importance of proactive security measures and the adoption of robust authentication mechanisms to safeguard against evolving cyber threats.
