← All insights

Microsoft 365 and identity security

Microsoft Entra Passkeys and SMS Retirement: The Office Manager’s Transition Plan

Microsoft Entra is moving organizations toward phishing-resistant authentication while Microsoft-provided SMS and voice authentication face retirement. Here is how smaller offices can prepare.

Office manager guiding an employee through secure account registration on a laptop

The confirmed Microsoft timeline

Microsoft documentation states that beginning September 1, 2026, passkeys become the default authentication experience for users enabled for Microsoft-provided SMS or voice authentication. Microsoft-provided SMS and voice authentication are scheduled for full retirement on February 1, 2027.

These dates matter to offices that use Microsoft Entra ID for Microsoft 365 sign-in. Users who rely only on SMS or voice may be prompted to register a passkey and may experience sign-in disruption if they are not prepared.

The change does not mean every authentication method disappears. Microsoft identifies passkeys, Windows Hello for Business, FIDO2 security keys, and certificate-based authentication as phishing-resistant options. The exact options available depend on tenant configuration, licensing, device platforms, and organizational policy.

Why SMS is being phased out

SMS and voice codes are better than password-only access, but they remain vulnerable to phishing and other forms of interception or social engineering. A user can be persuaded to disclose a code to an attacker operating a convincing sign-in page or phone conversation.

Passkeys use public-key cryptography and are tied to the intended website or service. A passkey is not a code that a user reads aloud. It generally requires local device interaction, such as a PIN or biometric unlock.

This does not make identity risk disappear. Attackers can still target help desks, recovery processes, devices, administrators, and poorly governed applications. The transition should therefore be treated as an identity-management project rather than a simple authentication toggle.

Who should act first

Prioritize:

  • Global administrators and other privileged users.
  • Owners of payroll, finance, legal, and client-record systems.
  • Employees who work remotely or travel with laptops.
  • Shared-service accounts and users with access to multiple tenants or vendors.
  • Employees who currently have SMS or voice as their only usable method.
  • Users whose devices or browsers may not support the selected passkey option.

Do not assume that a user who has registered Microsoft Authenticator is ready for passkeys. Review the actual authentication methods and sign-in requirements in the tenant.

A practical transition sequence

1. Inventory current methods

Export or review authentication-method activity. Identify users enabled for SMS or voice, users with no backup method, privileged accounts, and accounts with unusual or stale methods.

2. Choose approved methods

Decide whether the office will support platform passkeys, security keys, Windows Hello for Business, Microsoft Authenticator passkeys, or a combination. Document which method is required for administrators and which is acceptable for general users.

3. Prepare recovery

Every authentication program needs recovery. Define how a new employee is verified, how a lost device is replaced, and who can reset or re-register a method. Recovery should require stronger verification than simply answering questions available from social media.

4. Protect emergency access

Microsoft recommends maintaining emergency access accounts and excluding them from Conditional Access policies that could make them unusable during an outage. Store credentials securely, avoid tying the accounts to an individual’s device, monitor their use, and test them regularly.

5. Pilot before broad rollout

Use a small group representing administrators, remote workers, shared workstations, and different device platforms. Test sign-in, password reset, device replacement, browser behavior, and access to critical applications.

6. Communicate clearly

Tell staff what is changing, why SMS is being replaced, how registration works, and where to report a suspicious prompt. State that support staff will never ask for a passkey, password, or one-time code over an unsolicited call.

Conditional Access considerations

Conditional Access can require stronger authentication for administrators, high-risk applications, or access from untrusted conditions. Roll out policy changes in report-only mode when feasible, review results, and maintain documented exclusions for emergency access accounts.

Avoid creating a policy that looks secure but blocks the people responsible for recovery. Test sign-in from normal office devices, remote locations, mobile devices, and administrator accounts.

What is confirmed and what remains uncertain

Confirmed: Microsoft has published the September 1, 2026 passkey default milestone and February 1, 2027 retirement date for Microsoft-provided SMS and voice authentication. Confirmed: Microsoft recommends phishing-resistant methods.

Uncertain: the precise user experience for a particular tenant, because configuration, licenses, authentication policies, device support, and third-party applications differ. Microsoft may update technical guidance, so administrators should recheck the official documentation during the rollout.

The office-manager checklist

  • Export the current authentication-method inventory.
  • Identify SMS-only and voice-only users.
  • Require phishing-resistant methods for privileged accounts.
  • Create and test emergency access procedures.
  • Pilot registration with representative users.
  • Confirm vendor and line-of-business application compatibility.
  • Publish a recovery and support procedure.
  • Review sign-in and authentication-method reports monthly.

The strongest transition is quiet and planned. Employees should register before a forced prompt, administrators should test recovery before an outage, and management should retain evidence of the decisions made.

Sources