Microsoft is making passkeys the default
If your team signs in to Microsoft 365, some of them are about to see something new.
From 1 September 2026, Microsoft begins prompting users to set up a passkey when they sign in. The prompt is legitimate. It’s coming from Microsoft, not from your IT provider, and it’s the front end of a change that ends with SMS and voice authentication being switched off entirely.
Here’s what’s actually happening, who it affects, and what you need to do.
Who this affects
Only users who currently receive their multi-factor authentication codes by SMS or voice call. Microsoft is retiring both.
If your staff already use the Microsoft Authenticator app, a FIDO2 security key, or Windows Hello, nothing changes for them. No prompt, no deadline, no action.
That distinction matters, because most businesses have a mix.
The dates
1 September 2026. Users on SMS or voice are automatically enabled for passkeys and prompted to register at sign-in. The prompt can be dismissed, but it will keep coming back.
18 September 2026. Microsoft publishes options and pricing for third-party telecom providers, for organisations that genuinely need to keep SMS or voice for specific users.
30 October 2026. Administrators can start configuring those third-party providers.
1 February 2027. Microsoft-provided SMS and voice authentication ends.
After 1 February 2027. Any user whose only method is SMS or voice must register a passkey before they can sign in. The prompt becomes blocking, it’s enforced across every tenant, and there is no opt-out.
So there are five months of “optional” followed by a hard stop. Nothing breaks in September. Something definitely breaks in February if nobody has done anything by then.
Why Microsoft is doing this
SMS-based MFA has been the weakest widely-deployed second factor for years. Codes can be intercepted, SIMs can be swapped, and, most commonly, users can be talked into reading the code out to someone who called them claiming to be from IT. None of that is exotic. It’s the standard playbook in the business email compromise cases we see.
A passkey removes the thing the attacker is trying to steal. There is no code to read out, because there is no code. The credential is bound to the device and the sign-in page it was created for, so a convincing fake login page gets nothing. That property, phishing resistance, is the whole point, and it’s why regulators and cyber insurers have been moving in the same direction.
What we recommend
Passkey in Microsoft Authenticator, for most people. It’s device-bound, it uses the phone staff already carry, and it doesn’t require buying hardware or standardising the fleet on Windows Hello.
What about staff who won’t put a work app on a personal phone
It comes up every time, and it’s a fair position. Nobody should be compelled to install company software on a device they paid for.
Until February they can simply dismiss the prompt. It isn’t blocking yet.
Before 1 February 2027 they need an alternative, and the practical one is a physical security key: a FIDO2 device roughly the size of a USB stick that stays with the user and acts as their sign-in method. There’s no app, nothing installed on a personal device, and no phone number involved.
The catch is lead time. Keys need to be specified, purchased, registered against each user’s account and physically handed over. That’s a procurement exercise, not a five-minute change. Identify those people in October, not in late January.
What to do now
If you want to get ahead of it, anyone can register a passkey today:
- Go to mysignins.microsoft.com/security-info
- Select Add a sign-in method
- Choose Passkey in Microsoft Authenticator
It takes about five minutes.
Our step-by-step guide is here: [Passkey instructions]
Not sure where you stand?
The useful first question isn’t “should we move to passkeys.” It’s “who in our business is still on SMS or voice.” That’s a report, and it takes minutes to pull.
If you’re a 3rdmill customer, we’ll be in touch about your environment ahead of the deadline. If you’d like to know sooner, or you’re not sure whether this affects your team at all, get in touch and we’ll check.
Sources: Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID and Passkeys by default and retirement of Microsoft-provided SMS and voice authentication, Microsoft Learn.