What’s happening
Microsoft is moving Microsoft Entra ID tenants toward phishing-resistant authentication by default. Passkeys are becoming the default authentication experience for users who are currently enabled for SMS or voice, and Microsoft-provided SMS and voice authentication will retire on 1 February 2027.
This matters for managed service providers because Microsoft customers with users still relying on SMS or voice MFA will need assessment, migration planning, user communications and adoption support before enforcement begins.
- SMS and voice are being retired because they are weaker against phishing, SIM-swap and replay attacks.
- Passkeys are Microsoft’s recommended replacement and will become the default experience for affected users.
- There is no opt out after retirement for users whose only MFA method is SMS or voice.
1 September 2026
Users enabled for SMS or voice are automatically enabled for passkeys and will be prompted to register a passkey the next time they complete MFA.
8 September 2026
Provider options and pricing begin to be published for organisations that must retain SMS or voice through customer-managed telecom providers.
1 February 2027
Microsoft-provided SMS and voice authentication retire in Microsoft Entra ID. Users with only SMS or voice will be blocked until they register a passkey.
Technical actions
- Identify all users still enabled for SMS or voice in the Authentication Methods Policy.
- Confirm whether your tenant has alternative phishing-resistant methods available.
- Enable passkeys and plan registration campaigns before auto-enablement starts.
- Review Conditional Access, authentication method policies and break-glass account handling (add FIDO2 to your break glass accounts.)
- Document tenant readiness and track exceptions before the 2027 deadline.
Change management
- Position this as a security improvement, not just a Microsoft platform change for changes sake.
- Start stakeholder and management team conversations early so migration can happen on their schedule.
- Bundle communications, adoption support and service desk enablement into migration proposals.
- Use the deadline to prioritise users with high SMS or voice dependency.
- Discuss passkeys, governance and identity security as part of wider security roadmap work.