Microsoft just made a call that will land in every Microsoft 365 tenant sooner rather than later: passkeys are becoming the default authentication method in Microsoft Entra ID, and SMS and voice codes are being retired as native Entra capabilities in early 2027. If your business uses Microsoft 365 — and most do — this affects you.
Here’s the short version of the timeline Microsoft published:
- September 1, 2026 — Microsoft begins rolling passkeys out as the default MFA experience in Entra ID. Users currently on SMS or voice will automatically be enabled for passkeys and prompted to register one the next time they sign in.
- February 1, 2027 — Microsoft-provided SMS and voice authentication is retired. Organizations that still need text-message or phone-call codes will have to contract with a third-party telecom provider through the Microsoft Security Store, and pay separately for it.
“Passwords with a text-message code stopped being ‘good enough’ the moment AI-driven phishing kits started harvesting one-time codes in real time. Passkeys are the first MFA method built for the threat landscape we’re actually in.”
— Glenn Kupsch, President, Adaptive IT
Why Microsoft is doing this
SMS and voice codes were a huge step up from passwords alone, but they were never truly phishing-resistant. Attackers intercept text messages, socially engineer help desks into SIM-swapping numbers, and increasingly use AI-driven phishing kits that harvest one-time codes in real time. Microsoft Threat Intelligence says AI-assisted phishing campaigns are now hitting click-through rates as high as 54%, compared to about 12% for traditional phishing.
Passkeys sidestep the whole problem. They use public-key cryptography tied to a specific device, so there’s no shared secret to steal, no code to intercept, and no phone number for an attacker to hijack. They’re also faster for users — a face scan or fingerprint instead of waiting for a text and typing six digits.
What this means for your business
If your team signs in to Microsoft 365 with a text-message code today, that experience is going to change — and if you do nothing, it’ll change for you starting in September. A few things worth thinking about now:
- Inventory who’s still on SMS or voice. Anyone still using text-message MFA is on borrowed time and, more importantly, sitting on the weakest link in your security posture.
- Decide which passkey type fits your users. Entra supports synced passkeys (iCloud Keychain, Google Password Manager, etc.) that follow a user across their devices, as well as device-bound options like Microsoft Authenticator passkeys, Windows Hello, and FIDO2 security keys. Different roles may warrant different choices.
- Plan the rollout before Microsoft plans it for you. Automatic enrollment is convenient, but “surprise, you have a new sign-in method” is a support-ticket generator. A short user communication and a scheduled registration window prevents most of that noise.
- Update recovery paths. If SMS was your fallback for account recovery, that fallback is going away. Every user needs at least two working phishing-resistant methods.
- Budget for the exception cases. Shared mailboxes, service accounts, kiosk logins, and users without smartphones all need a plan. If you truly need SMS/voice after February 2027, you’ll be paying a third-party telecom for it.
The bigger picture
This is the direction the entire industry is moving. Google, Apple, and the FIDO Alliance have been pushing passkeys for years, and Microsoft flipping the default in Entra ID is the loudest signal yet that the password-plus-text-code era is ending. For most small and mid-sized businesses, the right move is to get ahead of the September rollout, not react to it after the first help-desk call.
Need help planning your passkey rollout?
If your business runs on Microsoft 365 and you’d rather not figure this out during the first Monday-morning support wave, Adaptive IT can plan and execute the passkey transition for you: audit your current MFA methods, pick the right passkey types for each group of users, set up a registration campaign, write the user comms, and clean up the edge cases (shared accounts, kiosks, users without smartphones). We do this every day so you don’t have to.
Contact us and we’ll walk through your tenant, flag the risky spots, and get a rollout on the calendar well before Microsoft’s September deadline.
Source: Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID (Microsoft Security Blog, July 13, 2026).
— Adaptive IT