Knowledge Centre
Cyber Security GuidesChecklist and Guide

Microsoft Passkey Readiness Guide

5 minutes to completeEvergreen guide — kept up to date

Microsoft is making passkeys the default authentication experience in Entra ID from 1 September 2026 and plans to retire Microsoft-provided SMS and voice authentication on 1 February 2027. This guide sets out the practical steps a business should work through before the change reaches its users.

What is changing?

  • From 1 September 2026, Microsoft begins making passkeys the default authentication experience in Entra ID, and users enabled for SMS or voice may be prompted to register a passkey.
  • On 1 February 2027, Microsoft-provided SMS and voice authentication are due to be retired.
  • Businesses still requiring SMS or voice after that date may need a customer-managed telecom provider, which Microsoft has said it will describe in more detail.

Details are based on Microsoft’s announcement of 13 July 2026 and may be refined before the deadlines. Always confirm against current Microsoft documentation.

Step 1: Find out who still uses SMS or voice

Ask your IT provider or administrator to list users whose authentication methods include SMS or voice. Microsoft provides reporting and scripts for this. These users are the ones most affected by the change, so knowing who they are turns an unpredictable rollout into a manageable project.

Step 2: Review your authentication policy

Check the Authentication Methods policy in Microsoft Entra ID. Confirm whether passkeys are already enabled, which groups they apply to, and whether weaker methods are still allowed more broadly than necessary.

Step 3: Decide which passkey types you will permit

Not every passkey type suits every business. Use this comparison as a starting point for the conversation with your IT provider:

Passkey typeBest suited toPoints to consider
Synced passkeys (platform credential managers)Staff who already use iCloud Keychain or Google Password ManagerCredential syncs across personal devices; check policy on personal-device use
Microsoft Authenticator passkeyStaff with a managed or trusted smartphoneRequires the Authenticator app; phone replacement needs a recovery process
Windows Hello for BusinessStaff with their own company Windows computerTied to the specific computer; less suited to hot-desking
FIDO2 hardware security keyAdministrators, high-risk roles, shared or front-desk computersSmall purchase cost; keys must be issued, tracked and revoked

Step 4: Agree device rules

  • May passkeys be stored on company-managed computers?
  • May passkeys be stored on company-managed mobile devices?
  • Are personal devices permitted, and for which roles?
  • How will shared or front-desk computers be handled?
  • Who is issued a hardware security key?

Step 5: Pilot before rolling out

Test registration and everyday sign-in with IT staff first, then a small representative group. The pilot should deliberately include a phone replacement and a forgotten-device scenario, because recovery is where unprepared rollouts fail.

Step 6: Document recovery procedures

  • How a user registers a passkey on a new or replacement device
  • What happens when a device is lost or stolen
  • How identity is verified before authentication is reset
  • How temporary access is granted, for example a Temporary Access Pass
  • How authentication methods are removed when somebody leaves

Step 7: Communicate with staff

Tell staff about the change before Microsoft’s prompts appear, so nobody mistakes a genuine registration prompt for a scam. A short message works well:

“Microsoft is upgrading how we sign in to Microsoft 365. Over the coming weeks you may be asked to set up a passkey — this replaces text-message codes with a more secure sign-in using your fingerprint, face or PIN. This is a genuine prompt. If you are unsure, contact [IT contact] before entering anything.”

Step 8: Review privileged accounts and monitoring

  • Administrator accounts use phishing-resistant authentication, ideally hardware security keys.
  • Emergency-access accounts exist and have been tested.
  • Registration failures, unusual sign-ins and authentication-method changes are monitored.
  • Weaker fallback methods are removed once the passkey rollout is stable.

Readiness checklist

  • We know which users currently rely on SMS or voice authentication.
  • We have reviewed the authentication-method policy in Entra ID.
  • We have decided which types of passkey we will permit.
  • We have agreed rules for company-owned and personal devices.
  • We have tested the process with a small pilot group.
  • We have documented recovery and replacement-device procedures.
  • Staff will receive advance communication before prompts appear.
  • Privileged accounts, emergency access and monitoring have been reviewed.

Do not disable existing authentication and recovery methods until the passkey pilot, support process and emergency-access arrangements have been tested.

Plain-English Takeaway

Passkeys can make Microsoft 365 accounts much harder to phish, but only if the rollout is planned. Identify affected users, agree which passkey types you will allow, test recovery before you need it and tell staff what to expect — well before Microsoft’s deadlines arrive.

Downloadable guide

Download the Microsoft Passkey Readiness Checklist

A one-page printable checklist covering the users, policies, devices and recovery procedures to review before Microsoft’s passkey deadlines.

Download PDF

Free download. No email address required.

Want the full business explanation?

The Technology Intelligence article covers why this matters, where it helps and what to watch out for.

Read the full Technology Intelligence article

Related Knowledge Centre resources

Cyber Essentials Readiness Checklist

Work through the key controls to review before applying for Cyber Essentials.

Coming Soon

WhatsApp Impersonation and Payment Fraud Checklist

Checks to help staff spot fake WhatsApp accounts and verify payment requests safely.

Coming Soon

Business Backup Review

Check what is actually backed up, how often, and whether recovery has been tested.

Coming Soon

Remote Working Security Checklist

The security basics to check for staff working from home or on the move.

Coming Soon

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.