← All insights

Microsoft 365 and identity security

Microsoft Entra Passkeys: What Central Florida Offices Should Do Before February 2027

Microsoft is shifting Entra ID users away from Microsoft-provided SMS and voice authentication. This practical transition plan helps office managers inventory affected users, pilot passkeys, and prevent sign-in disruption.

Office manager guiding employees through a planned Microsoft Entra passkey transition

A deadline that deserves an operating plan

Microsoft has published a major change for Entra ID authentication. Beginning September 1, 2026, users enabled for SMS or voice authentication will be brought into scope for passkey registration through Microsoft-managed settings. Beginning February 1, 2027, Microsoft-provided SMS and voice delivery will be retired. Microsoft says users whose only available method is SMS or voice will then have to register a passkey before continuing to sign in, unless the organization has configured an appropriate customer-managed telecommunications option.

For Central Florida professional offices, this is more than a technical setting. A poorly planned change could interrupt access for employees, shared workstations, remote users, executives, or staff who replace a phone. A controlled transition can improve phishing resistance while also reducing help-desk surprises.

What passkeys change

Passkeys use FIDO standards and public-key cryptography rather than a reusable password or text-message code. Microsoft describes them as phishing-resistant because the credential is tied to the legitimate service and cannot simply be typed into a look-alike site. Entra ID supports synced passkeys and device-bound options, including supported platform credential managers, Microsoft Authenticator, Windows, and FIDO2 security keys.

That does not mean every passkey option fits every office. A medical practice with shared clinical workstations, a law firm with managed laptops, and a field-service company with personal phones may need different enrollment, recovery, and device rules. Confirm current Microsoft documentation, licensing, operating-system support, and device-management requirements before choosing a design.

First: inventory people and methods

Create an authentication inventory that lists:

  • Every employee, contractor, guest, and administrator.
  • Users currently enabled for SMS or voice.
  • Users who already have Authenticator, passkeys, security keys, or Windows Hello.
  • Shared or kiosk devices that cannot follow an ordinary personal-device workflow.
  • Emergency accounts and their approved authentication methods.
  • Staff who work remotely or have limited mobile coverage.

Do not assume the current portal configuration tells the whole story. Review the Authentication Methods Policy, legacy settings, Conditional Access policies, registration campaigns, and actual registration reports. Record unknown cases for follow-up.

Pilot before broad enrollment

Select a small pilot group representing different roles and devices. Include an administrator, an ordinary office user, a remote worker, and someone who regularly replaces or shares equipment. Test registration, normal sign-in, device replacement, lost-device response, and account recovery.

Decide whether the office will permit synced passkeys, require device-bound credentials for sensitive roles, issue hardware security keys, or use more than one option. Microsoft supports profiles and authentication strengths that can target groups and sensitive resources, but those settings require careful testing. A policy that looks correct can still lock out users or conflict with older applications.

Protect the recovery path

A phishing-resistant sign-in method is weakened if recovery depends on an unverified phone call or a broadly shared administrator account. Document who may reset authentication methods, what identity evidence is required, which actions need a second approver, and how emergency access is protected.

Maintain more than one usable method where business continuity requires it. Test emergency accounts without using them for routine work. Review privileged roles and separate administrator identities from everyday email accounts. Alert on unexpected authentication-method changes when available.

Prepare employees for the experience

Tell users what the legitimate registration prompt looks like, when it will appear, which devices are approved, and whom to call before responding to an unfamiliar prompt. Warn employees that attackers may imitate migration notices. Staff should not scan an unexpected QR code, install an unapproved application, or approve a registration request initiated by someone else.

Provide a short, dated guide and a known support number. Avoid sending a vague message saying only that everyone must change MFA. Explain the business reason, approved options, deadline, and recovery process.

Confirmed versus uncertain

Confirmed: Microsoft states that passkey registration changes begin September 1, 2026, and Microsoft-provided SMS and voice authentication retire beginning February 1, 2027. Confirmed: Microsoft recommends passkeys as the primary migration path where possible.

Uncertain: the correct configuration for a particular tenant depends on its licenses, devices, applications, user population, accessibility needs, and risk. Microsoft product behavior can change, so administrators should verify the current documentation before implementing policy.

A practical transition schedule

  • This week: export affected users and document current methods.
  • Next two weeks: enable and test passkeys with a representative pilot group.
  • Within 30 days: define recovery, help-desk verification, and device-replacement procedures.
  • Before broad rollout: test Conditional Access and emergency access.
  • Before February 2027: confirm no user depends solely on Microsoft-provided SMS or voice.

The goal is not merely to replace one prompt with another. It is to create a sign-in system that is harder to phish, easier to support, and resilient when a person changes roles, loses a device, or needs urgent access.

Sources