
Executive Summary
Microsoft is changing how businesses protect Microsoft 365 and other services that use Microsoft Entra ID.
From 1 September 2026, Microsoft will begin making passkeys the default authentication experience in Entra ID. Employees who are currently enabled for text message or voice call authentication may be prompted to register a passkey when they next complete a multi-factor authentication check.
Microsoft will then retire its own SMS and voice authentication delivery on 1 February 2027. Businesses that still need these methods will have to use a supported third-party telecom provider and may face additional costs.
For most businesses, the sensible approach will be to move employees to phishing-resistant authentication before the deadline. This could include passkeys stored on approved devices, passkeys in Microsoft Authenticator, Windows-based options or physical security keys.
The change should improve security and may make signing in easier, but it needs to be planned properly. Businesses should identify affected users, select the right authentication methods, test the process and provide clear instructions to employees.
Introduction
Does your business still send employees a text message when they sign in to Microsoft 365?
For many organisations, SMS authentication was an important step forward. It meant that stealing an employee’s password was not always enough to access their account.
The problem is that criminals have become much better at stealing or bypassing temporary authentication codes. They may create a convincing fake Microsoft sign-in page, intercept messages or trick a mobile provider into transferring someone’s telephone number.
Microsoft is therefore encouraging businesses to use sign-in methods that are much harder to steal through phishing.
This is a positive security change, but it could also cause disruption for businesses that leave their preparations until the last minute.
What is Microsoft changing?
Microsoft Entra ID manages user identities and sign-ins for services including Microsoft 365, Teams, SharePoint and many other business applications.
Microsoft has announced a phased change to authentication in the standard public cloud version of Entra ID.
From 1 September 2026
Microsoft will begin rolling out passkeys as the default authentication experience.
Users who are enabled for SMS or voice authentication will automatically be enabled for passkeys. When they next complete a multi-factor authentication check, they may be prompted to register one.
The rollout will happen gradually, so employees in different organisations may not see the prompt on exactly the same day.
On 18 September 2026
Microsoft plans to publish information about the telecom providers that will support organisations that still require SMS or voice authentication.
This information is expected to include available providers, technical guidance, pricing and commercial terms.
From 30 October 2026
Administrators will be able to select and configure a supported telecom provider through the Microsoft Security Store.
Businesses planning to retain SMS or voice authentication for particular users will need to configure their chosen provider before Microsoft’s service ends.
On 1 February 2027
Microsoft will stop providing the telecom delivery behind SMS and voice authentication as a native Entra ID service.
Businesses that still need these methods will have to use a supported third-party provider. The organisation will be responsible for any charges made by that provider.
After this date, users who rely on SMS or voice authentication may be required to register a passkey before they can continue signing in. Microsoft says that these registration prompts will be enforced and organisations will not be able to opt out.
Is Microsoft completely removing SMS authentication?
No. Microsoft is retiring the SMS and voice delivery that it currently provides directly through Entra ID.
Organisations with a regulatory, technical or operational reason to retain these methods will be able to use a supported telecom provider.
However, this should not be treated as the automatic choice.
Moving to a third-party provider may involve additional costs, contracts, configuration and support. It also does not remove the underlying security weaknesses associated with text messages and telephone calls.
For most businesses, Microsoft recommends moving users to passkeys or another phishing-resistant authentication method.
Why are SMS and voice authentication considered less secure?
Text messages and phone calls are still safer than relying on a password alone. However, they can be targeted in several ways.
Fake sign-in pages
An employee may receive an email that appears to come from Microsoft, a supplier or a colleague.
The link takes them to a convincing copy of the Microsoft sign-in page. The employee enters their password and then types in the authentication code sent to their phone.
The criminal can collect both pieces of information and use them immediately to access the genuine account.
SIM swapping
A criminal may convince a mobile provider to transfer an employee’s telephone number to another SIM card.
Calls and text messages intended for the employee can then be redirected to the criminal.
Social engineering
An attacker may telephone an employee and pretend to be from their IT team, Microsoft or another trusted organisation.
They may ask the employee to read out a code or approve an unexpected sign-in, claiming that it is needed to fix an account problem.
Passkeys are designed to prevent this type of attack because there is no reusable code for the employee to type into a fake website or share over the telephone.
The UK National Cyber Security Centre describes FIDO2 authentication, the technology behind modern passkeys, as resistant to phishing, guessing and credential theft.
What is phishing-resistant authentication?
Phishing-resistant authentication is a sign-in method designed to prevent criminals from collecting or reusing an employee’s credentials through a fake website.
With a passkey, the employee may confirm their identity using:
- A fingerprint
- Facial recognition
- A device PIN
- Microsoft Authenticator
- A physical security key
- An approved passkey manager
The passkey is linked to the genuine website or service for which it was created. It cannot simply be entered into a fraudulent website or handed to someone pretending to be from IT support.
The private part of the passkey remains protected on the employee’s device or in their approved passkey provider. The website holds a corresponding public key that can confirm the sign-in without receiving the employee’s private credential.
This makes the process much harder for an attacker to intercept or copy.
What types of passkey can businesses use?
Microsoft Entra ID supports different passkey options. The right choice will depend on the devices employees use, the sensitivity of their work and how much control the business needs.
Synced passkeys
Synced passkeys can be stored in a supported credential manager and made available across a user’s approved devices.
They can provide a convenient and relatively low-cost option for many general business users.
Before enabling them, businesses should decide which devices and passkey providers are acceptable. Allowing employees to store business credentials on unmanaged personal devices may not be appropriate for every organisation.
Device-bound passkeys
A device-bound passkey remains on one particular device.
Examples include passkeys held in Microsoft Authenticator, passkeys stored on Windows devices and physical FIDO2 security keys.
These options may be appropriate for IT administrators, finance teams, senior employees and others who have access to sensitive systems or information.
Physical security keys
A physical security key is a small device that may connect through USB or communicate wirelessly with a phone or computer.
The employee must have the key with them and usually enter a PIN or complete another local check.
Security keys can provide strong protection for high-risk accounts. However, the business will need a process for issuing replacements and recovering access when a key is lost, damaged or left at home.
Microsoft recommends security keys for users with elevated privileges and for organisations operating in highly regulated environments.
Does this affect every Microsoft 365 user?
The immediate impact will be on users who are currently enabled for SMS or voice authentication in Microsoft Entra ID.
However, businesses should use the change as an opportunity to review authentication across the whole organisation.
An employee may normally approve sign-ins through Microsoft Authenticator but still have an old mobile number registered as an alternative method. These forgotten fallback options can create unnecessary security risks.
Businesses should also look for accounts that are easily overlooked, including:
- Microsoft 365 administrator accounts
- Finance and payroll accounts
- Temporary worker accounts
- External consultant accounts
- Shared operational accounts
- Emergency access accounts
- Accounts used for older applications or specialist equipment
The review should consider every authentication method available to each user, not just the method they use most often.
What should your business do now?
Identify affected users
Start by reviewing the authentication methods configured in Microsoft Entra ID.
Find out which users and groups are enabled for SMS or voice authentication, including those who have registered these methods as backups.
This will help you understand the size of the project and identify employees who may need additional support.
Choose the right method for each type of user
There may not be one authentication option that works for everyone.
A general office employee using a managed laptop may have different needs from an IT administrator, a warehouse employee, a travelling director or someone working from a shared computer.
Consider:
- Whether the employee uses a business-owned device
- Whether personal phones are permitted
- The sensitivity of the systems they access
- Remote and hybrid working arrangements
- Accessibility requirements
- Whether physical security keys are needed
- How access will be recovered if a device is lost
A good authentication policy should balance security with a sign-in process that employees can use reliably.
Run a controlled pilot
Do not change the whole organisation at once.
Begin with a small pilot group containing employees from different teams, locations and levels of technical confidence.
This can reveal issues involving device compatibility, unclear instructions or account recovery before the change reaches the wider business.
Microsoft Entra ID also allows administrators to run targeted registration campaigns. These campaigns can prompt selected users to set up a passkey during their normal sign-in process.
Prepare account recovery procedures
Stronger authentication still requires a secure way to recover access.
Your business should decide what will happen when an employee:
- Loses or replaces a phone
- Receives a new laptop
- Forgets a device PIN
- Damages a physical security key
- Cannot complete passkey registration
- Is locked out while working remotely
- Leaves the organisation
The recovery process should verify the employee’s identity properly. It should not simply fall back to an insecure method whenever someone contacts the helpdesk.
Protect administrator accounts first
Administrator accounts can change security settings, create users and access large amounts of business information.
Because of this, they are particularly valuable targets for criminals.
These accounts should be among the first to move to phishing-resistant authentication. Physical security keys or carefully managed device-bound passkeys may be suitable, depending on the organisation’s requirements.
Administrators should also use separate accounts for everyday work and administrative tasks wherever practical.
Explain the change to employees
Clear communication will reduce confusion and support requests.
Employees should understand:
- Why the business is making the change
- When they might see a Microsoft registration prompt
- Which device or method they should use
- How to complete the setup
- Where to get help
- What to do if they receive an unexpected prompt
They should also be warned that criminals may use Microsoft’s announcement as the basis for phishing emails.
An employee may receive a fake message telling them that they must “upgrade their Microsoft authentication” or risk losing access. Staff should follow the instructions provided directly by the business rather than clicking unexpected email links.
What if some employees cannot use passkeys?
There may be legitimate situations in which an employee cannot immediately use the organisation’s preferred passkey method.
This could be due to:
- Accessibility requirements
- Unsupported or specialist devices
- Restrictions on mobile phones
- Shared working environments
- Regulatory requirements
- Unusual operational processes
The business should identify these exceptions early and consider alternative phishing-resistant methods where possible.
Where SMS or voice authentication remains essential, the organisation will need to review Microsoft’s supported telecom providers and configure one before 1 February 2027.
Any exception should be documented and reviewed regularly rather than allowed to continue indefinitely without oversight.
Why should businesses act before February 2027?
Waiting for the deadline could lead to avoidable disruption.
Employees may be locked out, support requests may rise sharply and important accounts may be left without a suitable recovery method.
Starting early gives the business time to:
- Review existing authentication methods
- Choose appropriate passkey options
- Test different devices and working arrangements
- Resolve accessibility and compatibility issues
- Prepare account recovery procedures
- Protect high-risk accounts
- Train the IT support team
- Communicate clearly with employees
It also allows the business to benefit from stronger protection sooner.
Final Thoughts
SMS and voice authentication played an important role in moving businesses away from password-only security. However, the methods used by cybercriminals have changed, and stronger forms of authentication are now available.
Microsoft’s move towards passkeys reflects a wider shift in cybersecurity. Rather than relying on a temporary code that an employee can accidentally share, passkeys are designed to work only with the genuine service.
For many users, the new process may also be easier. Signing in with a fingerprint, face or device PIN can be quicker than waiting for a text message and typing in a code.
The key is to treat this as a planned business change rather than waiting for Microsoft’s deadline. A review, pilot and clear communication can help make the transition secure and straightforward.
Prepare your business for Microsoft’s authentication changes
Get Support can help you review your current Microsoft 365 authentication setup and prepare for the retirement of Microsoft-provided SMS and voice authentication.
We can identify affected users, recommend suitable passkey options, configure Microsoft Entra ID and protect administrator accounts. We can also run a controlled pilot, prepare employee guidance and support your team through registration and account recovery.
Where your business has a genuine requirement to retain SMS or voice authentication, we can help you review the available options and understand the technical and practical implications.
Contact Get Support to start planning your move to phishing-resistant authentication.
Frequently Asked Questions
Microsoft is ending the SMS and voice delivery that it currently provides directly through the public cloud version of Microsoft Entra ID.
Businesses that still require these methods will be able to use a supported third-party telecom provider. Additional setup and charges may apply.
Microsoft plans to retire its own SMS and voice authentication delivery on 1 February 2027.
The changes only apply to the public cloud version of Microsoft Entra ID at this stage. Microsoft says that separate dates will be announced for other cloud environments.
Users who only have SMS or voice available could experience sign-in disruption if the business has not prepared an alternative.
Microsoft says these users will be required to register a passkey to continue signing in after the deadline. Businesses should complete their transition well before February 2027.
No. Many employees will be able to use a passkey stored on an approved phone or computer.
Physical security keys may be more suitable for administrators, employees with access to sensitive information, shared working environments and organisations with strict regulatory requirements.
Get Support can review your Microsoft Entra ID authentication settings, identify affected users and recommend appropriate phishing-resistant options.
We can manage the technical configuration, pilot the new sign-in process, prepare employee communications and provide ongoing support for registration, lost devices and account recovery.
Sources
This article is based on Microsoft’s July 2026 Entra ID security announcement, current Microsoft Learn guidance on passkeys and authentication registration, and guidance from the UK National Cyber Security Centre.