Microsoft Is Making Passkeys the Default: Is Your Business Ready?

Microsoft is moving Entra ID users towards phishing-resistant passkeys and retiring its own SMS and voice authentication. Here is what businesses should check before the deadlines.
Last reviewed: July 2026. Details are based on Microsoft’s announcement of 13 July 2026 and current Microsoft Learn documentation. Rollout details may be refined before the deadlines.
Microsoft is beginning a significant change to how business users sign in to Microsoft 365 and other services protected by Microsoft Entra ID. From 1 September 2026, Microsoft will begin making passkeys the default authentication experience in Entra ID. Microsoft-provided SMS and voice authentication are then scheduled for retirement on 1 February 2027.
For businesses, this means stronger phishing-resistant authentication is moving from an optional improvement towards the expected standard. The important question is no longer simply whether a business uses multi-factor authentication. It is whether the authentication method itself can resist modern phishing attacks.
What happened?
Microsoft Entra ID is the identity platform used behind many Microsoft 365 business accounts. It decides how users prove who they are when they sign in. Microsoft has announced that, from 1 September 2026, it will begin making passkeys the default authentication experience in Entra ID. The rollout may reach organisations in stages, and users currently enabled for SMS or voice authentication may be prompted to register a passkey as the rollout reaches their organisation.
Microsoft-provided SMS and voice authentication are then due to be retired on 1 February 2027. Businesses that still require SMS or voice after that date may need to review the alternative, customer-managed telecom provider options that Microsoft has said it will describe. Administrators should identify which users currently rely on SMS or voice before the deadlines.
- This is primarily an authentication and identity-security change.
- It does not mean passwords universally disappear from every Microsoft service on 1 September 2026.
- It does not mean every employee automatically becomes fully passwordless on the same day.
- It should be treated as a rollout beginning from that date, not a single overnight switch for every tenant.
What is a passkey?
A password is a secret the user knows and types. A passkey uses a cryptographic credential stored on an approved device, authenticator or security key. Passkeys use public-key cryptography: the private credential remains with the user’s approved device or passkey provider, and the user normally confirms sign-in using a PIN, fingerprint, facial recognition or another local device check.
Crucially, the passkey is associated with the genuine website or service it was registered with. That makes it considerably harder to surrender a usable credential to a fake phishing page, because there is nothing memorable to type into the wrong place.
The key idea
A passkey is designed to confirm both the user and the genuine service they are signing into.
Why is Microsoft moving away from SMS and voice?
SMS and voice authentication improved security compared with passwords alone, but they are not considered phishing-resistant. Attackers have developed reliable ways around them:
- SIM-swap attacks that move a victim’s number to a criminal’s SIM
- Social engineering of mobile providers
- Intercepted or redirected messages
- Users entering codes into fake sign-in pages
- Real-time phishing proxy attacks that relay codes as they are typed
- Attackers simply persuading users to disclose authentication codes
Having SMS MFA is generally better than having no MFA at all. However, businesses should not assume that all forms of MFA provide equal protection.
Multi-factor authentication is important, but the method used matters.
Why are passkeys more resistant to phishing?
A passkey is linked cryptographically to the legitimate service. There is no reusable password or six-digit SMS code for the user to type into a convincing fake website, and a fraudulent website should not be able to request and reuse the genuine passkey credential in the same way. A local biometric or PIN normally unlocks the credential on the user’s device; the biometric itself is not sent to the website.
That does not make an account impossible to compromise. Remaining risks include:
- Compromised devices
- Weak account-recovery processes
- Poor administrator controls
- Insecure fallback methods
- Stolen authenticated sessions
- Malicious applications
- Social engineering outside the sign-in process
- Inadequate leaver procedures
Passkeys reduce a major route into an account, but they do not replace wider identity and device security.
What types of passkey may a business encounter?
Microsoft Entra ID can support different passkey approaches, subject to configuration and platform support. Depending on the environment, these may include:
- Synced passkeys held through a supported credential provider
- Device-bound passkeys
- Passkeys held in Microsoft Authenticator
- Passkeys protected through Windows Hello
- FIDO2 hardware security keys
Not every option is available or appropriate in every environment. The right choice may depend on company-owned versus personal devices, mobile-device management, shared computers, privileged administrator accounts, regulated or high-security roles, staff working patterns, recovery requirements, support capabilities and organisation policy.
What does this mean for a small business?
A business should not wait until users encounter an unexpected registration prompt. An unmanaged rollout tends to produce predictable problems:
- Users not understanding what a passkey is
- Staff registering credentials on inappropriate personal devices
- People being unable to sign in after changing phones
- Shared devices being unsuitable for a personal credential
- Unclear recovery procedures
- Administrators continuing to use weaker fallback methods
- Helpdesk demand increasing during an unmanaged rollout
- Policies allowing passkeys without deciding which types are acceptable
Consider a simple example: a member of staff replacing or losing a phone should not discover during an urgent sign-in that nobody knows how their passkey or recovery process was configured.
Does this replace MFA?
Passkeys can satisfy strong or phishing-resistant authentication requirements when correctly configured and supported. A passkey is not merely a second factor bolted onto a password: depending on the implementation, it may provide passwordless multi-factor authentication through possession of the credential plus local user verification.
However, adopting passkeys does not remove the need for an authentication policy. Businesses still need to define acceptable methods, and Conditional Access may still be required. Recovery methods must be protected, risky sign-ins and unusual activity still need monitoring, privileged accounts may require stronger controls, and legacy authentication must remain blocked where applicable.
Practical business implications
User preparation
- What a passkey is
- Which device staff should use
- Whether personal devices are permitted
- What the sign-in prompt will look like
- What to do if a device is lost or replaced
- Who to contact for help
Device ownership
Organisations should decide whether passkeys may be stored on company-managed computers, company-managed mobile devices, personal devices or hardware security keys — and record that decision before users start registering.
Recovery
Strong authentication can be undermined by weak recovery. Businesses should document replacement-device procedures, lost-device procedures, temporary access arrangements, how identity is verified before authentication is reset, and leaver and access-removal processes.
Privileged accounts
- Dedicated administrator accounts
- Phishing-resistant authentication
- Hardware security keys where appropriate
- Emergency access accounts
- Monitoring and alerting
- Avoiding routine work from privileged accounts
Is Your Business Ready for Microsoft Passkeys?
- We know which users currently rely on SMS or voice authentication.
- We know which Microsoft 365 and Entra licences we use.
- We have reviewed the authentication-method policy in Entra ID.
- We have decided which types of passkey our organisation will permit.
- We have considered company-owned and personal devices separately.
- We know how staff will register their passkeys.
- We have tested the process with a small pilot group.
- We have documented what happens when a phone or computer is lost or replaced.
- We have protected account-recovery and authentication-reset procedures.
- Privileged administrator accounts use appropriately strong authentication.
- We have an emergency-access procedure.
- Staff will receive advance communication and basic training.
- Our IT provider has confirmed the rollout and support plan.
A tick beside “MFA enabled” is no longer enough. Businesses should know which authentication methods are enabled and how securely they are managed.
Questions to Ask Your IT Provider
- 1Which of our users still rely on SMS or voice authentication?
- 2Are passkeys already enabled in our Microsoft Entra environment?
- 3Which types of passkey will we allow?
- 4Can staff register passkeys on personal devices?
- 5How will we support shared or front-desk computers?
- 6What happens when an employee loses or replaces a device?
- 7How will new employees register securely?
- 8How are authentication methods removed when somebody leaves?
- 9Do administrator accounts use phishing-resistant authentication?
- 10Have our Conditional Access and authentication-strength policies been reviewed?
- 11Is there a tested emergency-access procedure?
- 12What communication and training will users receive before the Microsoft rollout reaches us?
- 13Are any applications still dependent on older authentication methods?
- 14Who will monitor failed registrations, unusual sign-ins and authentication changes?
The IT Club View
Microsoft’s direction is sensible. Passwords, SMS codes and approval prompts have all been repeatedly targeted by attackers because they depend heavily on the user recognising a fraudulent request. Passkeys can remove much of that burden by making the credential specific to the genuine service.
However, a secure technology can still be introduced badly. The main risk for many smaller businesses is not that passkeys are too complicated. It is that nobody takes ownership of the transition until users begin receiving prompts or SMS authentication stops working.
Businesses should use the period before February 2027 to identify affected users, agree an appropriate passkey model, test recovery and communicate the change. The goal should not simply be to comply with Microsoft’s deadline. It should be to make business accounts genuinely harder to phish.
The Operational Heartbeat
Authentication security is not a one-off project. A regular identity-security review should check for users still using weaker authentication methods, newly created accounts, administrator authentication, stale or inactive accounts, authentication-method changes, risky sign-ins, emergency-access account readiness, failed registration patterns and leaver account closure.
Strong authentication needs an operational heartbeat: it should be checked, tested and improved rather than assumed to be working forever.
Administrator Technical Note
Areas an administrator or IT provider should review in Microsoft Entra ID, subject to tenant, licence and platform support:
- Authentication Methods policy in Microsoft Entra ID
- Passkey and FIDO2 enablement
- Passkey profiles and targeted groups
- Current SMS and voice usage
- Microsoft registration campaigns
- Conditional Access
- Authentication strengths
- Temporary Access Pass for onboarding or recovery where appropriate
- Windows Hello for Business
- Microsoft Authenticator passkeys
- Supported synced passkey providers
- FIDO2 security keys
- Attestation requirements
- Administrator and privileged-access policies
- Emergency-access accounts
- Registration and sign-in logs
- User registration details
- Device compliance
- Legacy authentication
- Authentication-method reset procedures
A staged implementation model
- 1Discover — identify current authentication methods and affected users.
- 2Design — decide which passkey types, devices and roles will be supported.
- 3Pilot — test with IT staff and a representative user group.
- 4Prepare — document onboarding, recovery, replacement-device and leaver procedures.
- 5Communicate — explain the change before registration prompts appear.
- 6Deploy — use targeted groups and registration campaigns where appropriate.
- 7Monitor — review registration failures, support issues, risky sign-ins and method changes.
- 8Improve — remove unnecessary weaker fallback methods once the passkey deployment is stable.
Do not disable all existing authentication and recovery methods until the passkey pilot, support process and emergency-access arrangements have been tested. Verify any tenant-specific configuration steps against current Microsoft documentation before applying them.
Plain-English Takeaway
Microsoft is making passkeys the default authentication experience in Entra ID from September 2026 and plans to retire its own SMS and voice authentication in February 2027. Passkeys offer stronger protection against phishing, but businesses should review their authentication policies, devices, recovery procedures and user training before the change reaches them.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
WhatsApp Usernames Are Coming — Would You Recognise a Fake One?
WhatsApp usernames may improve privacy but could also create new impersonation risks. Learn how businesses can verify contacts and protect customers.
Read articleThe UK Isn’t Banning VPNs — But Is Yours Fit for Business?
The UK has decided not to restrict VPN access. Learn what the decision means and how to check whether your business VPN is properly secured.
Read articleCould Someone Be Sending Fake Emails as Your Business?
DMARC helps prevent criminals pretending to send emails from your business. Learn how it works, why it matters and what your IT provider should monitor.
Read article