Microsoft Entra passkeys become the default in September: what businesses should do now

From 1 September 2026, Microsoft Entra ID will automatically enable passkeys for users currently enabled for SMS or voice authentication. When those users next sign in and complete multi-factor authentication, Microsoft’s registration campaign will prompt them to create a passkey. The prompt can initially be postponed, but Microsoft-provided SMS and voice delivery will end on 1 February 2027.

Businesses should identify affected users, test suitable passkey options and establish a recovery process before the February deadline. Microsoft explains the change in its guidance on retiring SMS and voice authentication.

What is changing and when

A passkey uses public-key cryptography instead of a reusable password or one-time text code. Its private key remains on a device, security key or supported synced credential store. A fingerprint, face scan or device PIN normally unlocks it; biometric information is not sent to Microsoft.

Users already signing in with passkeys, Windows Hello for Business, FIDO2 security keys or another phishing-resistant method can continue doing so. The September change mainly affects users enabled for SMS or voice in the Entra Authentication Methods Policy or legacy MFA settings.

DateWhat businesses should expect
1 September 2026Affected users are automatically enabled for passkeys and brought into Microsoft’s registration campaign. The prompt has unlimited snoozes by default.
18 September 2026Microsoft plans to publish customer-managed telecom providers and related information through the Microsoft Security Store.
30 October 2026Organisations with a genuine operational or regulatory need can begin configuring a telecom provider for continued SMS or voice use.
1 February 2027Microsoft-provided SMS and voice delivery ends. Users relying only on those methods must register a passkey before continuing to sign in unless a customer-managed provider is configured.

A temporary opt-out can delay automatic passkey enablement before February, but it does not remove the 1 February 2027 enforcement. The announced timetable applies to Microsoft Entra public cloud environments.

Why Microsoft is making the change

SMS and voice codes are vulnerable to phishing, social engineering, SIM-swap attacks and interception. Passkeys are phishing-resistant because the credential is bound cryptographically to the legitimate service and there is no code for a user to reveal.

They are not a complete security solution. Attackers may still target devices, session tokens, recovery procedures or administrators. Businesses should combine the change with appropriate anti phishing services and layered email security services.

The government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a cyber breach or attack during the previous 12 months. Phishing affected 38% of all businesses and 88% of businesses that had identified an incident. Microsoft separately reported click-through rates of up to 54% for AI-assisted phishing, compared with roughly 12% for more traditional campaigns.

What to do before September

Identify users enabled for SMS or voice and confirm which devices and passkey types suit them. Pilot registration with a small group, including remote workers, shared-device users and anyone using accessibility tools.

Update onboarding so new employees receive a secure method from their first day. This is one of the IT management tasks that quietly get neglected until it creates avoidable support problems.

Plan for lost or replaced devices. Users can register more than one passkey where policy permits. If a credential becomes unavailable, an administrator can remove the old method and issue a Temporary Access Pass so the user can register a replacement.

Communicate the dates and show staff what the genuine registration prompt looks like. Organisations retaining SMS or voice should document the reason, assess provider charges and test the selected service before Microsoft’s delivery ends.

Businesses that need help with deployment can use managed IT support in London. Monitoring authentication activity through managed SOC services can help identify unusual sign-ins during the transition, while network penetration testing can assess wider weaknesses that passkeys alone will not resolve.

Common questions about Entra passkeys

Are passkeys safer than passwords?

They provide much stronger protection against credential phishing and password reuse, although secure devices and recovery controls still matter.

Do passkeys cost extra?

Microsoft states that migrating from its SMS and voice delivery to passkeys incurs no additional cost. Customer-managed telecom providers will charge according to provider, region and message volume.

What happens if someone loses their phone?

The organisation should remove the unavailable credential and use an approved recovery method, such as a Temporary Access Pass, to register a replacement.

Focus on Modern Workforce Productivity and Security

Operating safely in today’s digital landscape requires a balance between seamless productivity and robust defence. At Northern Star, we optimize your operations using Microsoft Azure services in London and custom Microsoft 365 services in London, keeping your daily tools running flawlessly. We also help your team work smarter with Microsoft Copilot consulting in London and stay secure through practical cyber awareness training.

To protect your infrastructure, we deploy advanced email security services in London alongside proactive vulnerability management in London. Our continuous managed SOC services and rapid MDR services in London detect threats instantly. If an issue arises, our expert cyber incident response and dedicated business continuity services keep your organization running smoothly. Contact us to start.

September arrives quickly, and a tested move beats a last-minute scramble. Northern Star’s IT consulting services in London can help you plan the switch, pilot it safely and support your team through it. Get in touch before the deadline lands.