All posts
Microsoft 365 Security 2 min read

Entra makes passkeys the default. SMS/voice retire in 2027. MSPs: here’s the 30‑day plan.

Starting Sept 1, 2026, Entra will prompt SMS/voice MFA users to register passkeys. Microsoft-provided SMS/voice retires Feb 1, 2027, with no opt‑out. Here’s how MSPs prevent sign‑in breaks across tenants.

M Michael July 22, 2026

AI‑enabled phishing now drives materially higher click‑through than traditional campaigns. Microsoft’s response: make passkeys the default in Entra and phase out Microsoft‑provided SMS and voice for MFA.

Key dates MSPs must track

  • Sept 1, 2026: Passkeys become the default sign‑in experience for Entra tenants. Users enabled for SMS/voice will be auto‑enabled and prompted to register a passkey during MFA.
  • Feb 1, 2027: Microsoft‑provided SMS/voice is fully retired. Users whose only MFA is SMS/voice will hit a blocking prompt to register a passkey. There’s no opt‑out.
  • Sept 18, 2026: Microsoft will publish details on customer‑managed telecom options via the Microsoft Security Store for orgs that must keep SMS/voice.

What to do in the next 30 days (multi‑tenant)

  1. Inventory risk:
    • Report who actually uses SMS/voice today and where passkeys are already enabled. Prioritize high‑impact roles and shared/device‑restricted users.
  2. Set your target authentication baseline:
    • Enable passkeys for all users capable of phishing‑resistant auth (passkeys, Windows Hello for Business, FIDO2). Define exceptions per customer.
  3. Update Conditional Access:
    • Require phishing‑resistant MFA for admins and sensitive apps. Add registration requirements so passkey prompts land before your deadlines, not during a critical login.
  4. Ready the endpoints:
    • Confirm platform/browser support, security key availability, and managed device policies. Test passkey profiles and attestation behavior.
  5. Communications + support:
    • Send tenant‑branded guides, schedule desk‑side enrollments for frontline users, and script help‑desk flows for blocked sign‑ins after Feb 1, 2027.
  6. Decide on SMS/voice continuity (if required):
    • If regulation or edge cases demand OTP by phone, plan a customer‑managed telecom provider via the Microsoft Security Store and budget for carrier fees.

Practical takeaway

This shift is coming with hard dates. If you don’t move users to phishing‑resistant methods, they will be forced to register passkeys during sign‑in—and production will stop while they do it. What percentage of your customers’ users still rely on SMS/voice today? Start with that number and work it down weekly.

See TenantForge in your own tenants

Connect a tenant read-only and get your first baseline comparison in minutes. 14-day trial, no credit card.

Start free trial