Entra ID Just Made Passkeys the Default. Here's What MSPs Need to Do Before February
Entra ID began making passkeys the default authentication method on September 1, 2026, with SMS and voice retiring in February 2027. Here is what MSPs managing multiple tenants need to check before the prompts start appearing on their own.
The default just changed
Starting September 1, 2026, Microsoft Entra ID began making passkeys the default sign-in experience for every tenant. As the rollout reaches your customers, any user still enabled for SMS or voice authentication is automatically enrolled in a passkey registration prompt the next time they complete multifactor authentication. No admin action is required to trigger it, which means it can start showing up in your customers' environments before your team has said a word about it.
This is the opening move in a longer retirement. Microsoft-provided SMS and voice delivery ends February 1, 2027. After that date, anyone whose only MFA method is SMS or voice will be blocked at sign-in until they register a passkey. There is no opt out from that enforcement, and it applies to every tenant.
What to do before the prompts arrive
- Identify which users in each tenant are still enrolled in SMS or voice, using Microsoft's reporting script or the authentication methods activity report
- Turn on a registration campaign deliberately, rather than letting Microsoft's automatic enrollment be the first thing users see
- Tell users what is changing and why before the prompt appears, not after the help desk tickets start
- If a tenant has a genuine regulatory need to keep SMS or voice, plan for a customer-managed telecom provider through the Microsoft Security Store, available from October 30
The multi-tenant problem
Doing this well for one tenant is a checklist. Doing it consistently across dozens of customer tenants, each on its own point in Microsoft's rollout schedule, is a different problem entirely, especially when you have no single view of which tenants still lean on SMS as a fallback.
Before the help desk calls start, it is worth checking now: how many of your tenants still have users with SMS or voice as an active MFA method, and do you know which ones?