Passkeys become the default in Entra ID starting September 1 2026
Microsoft will roll out passkeys as the default sign in experience in Entra ID starting September 1, 2026 and retire Microsoft-provided SMS and voice delivery on February 1, 2027. Here is a practical MSP checklist to audit, pilot, and avoid helpdesk chaos across your tenants.
What changed
Microsoft will start rolling out passkeys as the default authentication experience in Microsoft Entra ID on September 1, 2026. By February 1, 2027 Microsoft-provided SMS and voice delivery will be retired unless customers configure a telecom partner. That means tenants using SMS or voice for MFA will be auto-prompted to register passkeys during sign in, and later will be blocked until they have a phishing-resistant method registered.
Why this matters for MSPs
Phishable factors remain a high risk vector. The change shifts tenants toward phishing-resistant methods like passkeys, Windows Hello for Business, and FIDO2. If you manage many tenants you can expect registration prompts, helpdesk tickets, and possible login interruptions if users are not prepared.
Action checklist for MSPs
- Audit: run Microsoft’s recommended scripts or reports to find users still enabled for SMS or voice in each tenant. Start with high risk and admin accounts.
- Pilot: create passkey profiles and target a pilot group (helpdesk, power users, admins). Use synced passkeys for broad rollout and device-bound for high assurance roles.
- Registration campaign: set up and monitor registration campaigns, and run report-only Conditional Access checks before enforcing policies.
- Communications: prepare step by step user guidance and preemptive support hours for the first 2 weeks of rollout.
- Telecom fallback: if a customer must keep SMS or voice, plan to configure a customer-managed provider via the Microsoft Security Store and budget for telecom costs.
Practical takeaway
Treat this as a scheduled platform change not an optional feature. Start tenant-level discovery today, pilot synced passkeys, and add passkey readiness checks to your baselines so configuration drift does not cause sign in outages. Which tenants will you pilot first?