News & Insights
Microsoft Passkeys: Preparing for the 2027 MFA Changes
Microsoft is changing how users sign in. From September 2026, passkeys will become the default authentication experience in Microsoft Entra ID, and Microsoft-provided SMS and voice authentication will be retired on 1 February 2027.
This marks a fundamental move towards phishing-resistant security and is a necessary step in preparing for an increasingly AI-enabled workplace.
This article explains what is changing, why SMS and voice authentication are being retired, and what IT teams should do now to avoid disruption before the 2027 deadline.
Why Microsoft is making this change
For years, SMS codes and voice calls have been used as a second factor to protect user accounts. While obviously better than passwords alone, they are still vulnerable to phishing, social engineering, and SIM-swap attacks.
For example, attackers can trick users into sharing one-time codes, intercept text messages, or persuade a mobile provider to transfer a phone number. In each case, the attacker can capture the same sign-in proof intended for the legitimate user.
Passkeys work differently.
Instead of relying on a shared secret or code, passkeys use public key cryptography. The private key never leaves the user’s trusted device and is protected by biometrics, PIN, or device security controls. There simply is no code to steal, intercept, or type into a fake website.
As organisations adopt AI and cloud-first services at scale, identity becomes a more important control point. Stronger authentication reduces the risk that compromised credentials can be used to access sensitive data, automate actions, or move laterally across cloud services.
Top Tip: If your users already use Windows Hello for Business, FIDO2 security keys, or Microsoft Authenticator, you may be closer to passkey readiness than you think! The first step is to identify who still depends on SMS and voice authentication for sign-in or recovery.
What is a passkey?
Think of a passkey as a simpler and more secure way to sign in, reducing the dependency on both passwords and traditional MFA prompts.
Today, a typical sign-in journey looks like this:
- Enter username
- Enter password
- Approve Microsoft Authenticator notification or enter SMS code
With passkeys it’s like this:
- Enter username
- Approve sign-in using your phone, fingerprint, facial recognition, Windows Hello, or security key
That’s it.
In practice, this makes the sign-in process faster, simpler, and more secure for most users.
What about synced passkeys from Google or Apple?
Passkeys do not have to exist only in Microsoft services. In some scenarios, users may be able to use synced passkeys stored in platform ecosystems such as Google Password Manager or Apple iCloud Keychain.
These options can improve convenience because passkeys can move with the user across supported devices. However, they also introduce policy decisions for IT teams, particularly around managed versus personal devices, account recovery, auditability, device trust, and whether corporate access should allow consumer password manager ecosystems.
The key point is that organisations should define which passkey providers are approved, where they can be used, and how exceptions will be handled before large-scale rollout begins.
Key dates you need to know
1 September 2026 – Microsoft will begin prompting users who currently rely on SMS or voice authentication to register a passkey. The aim is to move users onto phishing-resistant methods before Microsoft-provided SMS and voice services are retired.
1 February 2027 – Microsoft-provided SMS and voice authentication services will be retired. Organisations that still require SMS or voice authentication will need to source a customer-managed telecommunications provider through the Microsoft Security Store.
After 1 February 2027 – Users whose only authentication method is SMS or voice will be required to register a passkey before they can continue signing in. This will be a blocking experience with no opt-out available.
What about temporary access passes?
Temporary Access Passes (TAPs) are not the same as SMS or voice authentication and are not being retired as part of Microsoft’s SMS and voice service retirement.
In practice, TAPs are likely to become more important during the transition. They can help users register a passkey, recover access after a lost device, or complete onboarding where a user does not yet have a phishing-resistant method configured.
IT teams should review TAP policies now, including lifetime, one-time use, who can issue them, approval controls, and audit logging.
The business benefits
While the driver is security, passkeys also deliver operational benefits:
- Reduced phishing risk – Passkeys are designed to resist credential phishing attacks that commonly bypass traditional MFA.
- Better user experience – Users spend less time entering passwords, requesting reset codes, and approving MFA prompts.
- Lower helpdesk demand – Password resets remain one of the most common service desk requests. Passwordless authentication reduces that dependency.
- Stronger compliance position – Phishing-resistant authentication aligns closely with Zero Trust principles, modern cyber insurance expectations, and regulatory security guidance.
Don’t wait for the 2027 deadline!
The organisations that begin preparing now will be in a much stronger position when passkeys become the default experience.
Microsoft recommends organisations identify users currently enabled for SMS and voice authentication before planning any migration strategy.
Typical preparation activities include:
- Identify users currently relying on SMS or voice authentication
- Review Microsoft Entra Authentication Methods Policies
- Assess passkey readiness across devices and user populations
- Evaluate Windows Hello for Business adoption opportunities
- Pilot Microsoft Authenticator passkeys with representative user groups
- Review onboarding, account recovery, and Temporary Access Pass (TAP) processes
- Launch user awareness and adoption campaigns
- Validate protection for administrator and break-glass accounts
Key questions about the transition
“Will SMS stop working completely?”
Not necessarily.
Microsoft is retiring its own telecom delivery service. Organisations that genuinely require SMS or voice verification can continue to use these methods through customer-managed telecom providers.
“Do users need special hardware?”
Usually not.
Most users can use passkeys stored in Microsoft Authenticator, Windows Hello for Business, or their mobile device. Hardware security keys remain available where appropriate.
“What about users who lose their phone?”
Recovery processes remain important. TAPs, alternative authenticators, and defined recovery workflows should form part of any deployment plan.
Final thoughts
The retirement of Microsoft-provided SMS and voice authentication is part of a broader industry move away from authentication methods that can be phished, intercepted, or socially engineered.
Organisations that start preparing now will improve security, reduce operational friction, and avoid a rushed migration ahead of February 2027.
There can be no question whether passkeys will become mainstream. Microsoft has effectively answered that question already.
For IT teams, the practical next step is to identify SMS and voice dependencies now, pilot passkeys with a controlled user group, and update recovery processes before the 2027 deadline becomes a business disruption.
In a nutshell: passkeys are not just a security upgrade. They are a practical way to reduce account compromise risk, simplify sign-in, and prepare users for a more secure Microsoft 365 experience. If you’d like to understand what Microsoft’s move away from SMS and voice-based MFA could mean for your organisation, or need help planning and implementing a passkey strategy, please feel free to get in touch.
Downloadable resources:
Microsoft Passkey transition FAQ
To support planning and adoption, please download our companion FAQ and IT team preparation checklist alongside this article. The FAQ helps answer common stakeholder questions, while the checklist gives IT teams a practical way to assess readiness, identify SMS and voice dependencies, and prepare ahead of the 2027 deadline.
![]()