Passkeys Are Now Default in Microsoft 365: What Perth Businesses Must Check

Microsoft has switched Entra ID to passkeys by default and is retiring SMS and voice sign-in codes by February 2027. Here's what Perth businesses need to check now. From Computer Mechanics, Perth IT specialists since 1997.

AmirAmir · Cloud System Engineer
16 September 2026
5 min read
Microsoft 365
Passkeys
MFA
Perth Business
Keyboard representing signing in to a Microsoft 365 account

Microsoft has started switching Entra ID — the sign-in system behind every Microsoft 365 account — over to passkeys by default. Since 1 September 2026, eligible users have been prompted to register a passkey when they sign in. The bigger deadline is 1 February 2027, when Microsoft-provided SMS and voice authentication codes are retired for good. If your business leans on a text message or a phone call as its multi-factor authentication (MFA), that method stops working unless someone configures a replacement before then.

This isn't an optional feature announcement. It's a default change rolling through every Microsoft 365 tenant, and the retirement date is fixed. Here's what it actually means and what to check.

What Microsoft has changed

Two things are happening on different timelines:

  • From 1 September 2026, Microsoft turned on its "Registration Campaign" for passkeys as Microsoft-managed in tenants that hadn't already configured it. Users doing MFA sign-in now see a prompt to set up a passkey — tied to Windows Hello, a phone's fingerprint or face unlock, or a physical security key. Staff can skip the prompt for now, so nothing breaks immediately.
  • From 1 February 2027, Microsoft-provided SMS and voice codes disappear entirely. Not deprioritised — retired. Any account still depending on a text or phone call for MFA will be locked out of that method the day it switches off.

If your business runs Microsoft 365 Business Basic, Standard or Premium, this applies to you regardless of size. There's no tier that's exempt.

Why this matters more than a routine feature update

We've written before about how SIM-swap and mobile number port-out fraud is rising in WA — criminals hijacking a phone number to intercept exactly these SMS codes. Microsoft's own security team has flagged SMS and voice as the weakest MFA methods it offers, because they depend on the mobile network rather than something cryptographically tied to your account. Passkeys close that gap: a passkey can't be phished, forwarded, or intercepted by a SIM-swap, because the private half never leaves the device it was created on.

So this change is Microsoft pushing every tenant toward a materially stronger default. The trade-off is that it happens automatically, on Microsoft's timeline, whether or not your business has planned for it.

What to check in your tenant now

A few practical things worth doing before the retirement date, not after:

1. Find out who is still using SMS or voice MFA

In the Entra admin centre, under Protection > Authentication methods, you can see which users are registered for SMS or voice as an MFA method. In many small businesses this is a handful of people — often whoever set up their account first, or anyone using a landline for the "call me" option.

2. Get passkeys registered before staff are forced into it

Rather than letting the prompt catch people mid-work, register passkeys deliberately: on a work laptop with Windows Hello, or through the Microsoft Authenticator app on a phone. It takes under a minute per person and avoids a scramble later.

3. Decide what happens to anyone who genuinely can't use a passkey

Field staff sharing a device, warehouse logins, or a service account tied to a landline are the edge cases. If you need phone-based codes to keep working past February 2027, Microsoft requires configuring a third-party telecom provider through the Microsoft Security Store — Microsoft's own SMS/voice won't be there as a fallback any more.

4. Don't forget shared and service accounts

Shared mailboxes and automation accounts sometimes have MFA configured against a mobile number nobody remembers assigning. These are easy to miss because no one signs into them day-to-day, and they're exactly the kind of account that goes quietly locked out in February.

The upside, if you get ahead of it

Handled proactively, this is a security improvement that costs nothing and takes minimal setup time. Passkeys are faster to use than typing in a six-digit code, they can't be phished the way a fake login page tricks someone into handing over a password, and they remove one of the more exploitable MFA methods from your business's attack surface entirely. For more on how passkeys work day-to-day, see our plain-English passkeys guide.

Left until the deadline, it's the opposite: a wave of "why can't I log in" calls in early 2027 from anyone who never got round to registering a passkey.

Where this fits with your wider Microsoft 365 setup

This sits alongside the broader security settings worth reviewing in any Microsoft 365 tenant — see our Microsoft 365 guide for Perth businesses for the fuller picture, or our IT security solutions if you'd rather have someone check the tenant configuration for you. We're a Perth-based MSP that's been supporting local businesses since 1997, and tenant-wide changes like this one are exactly the sort of thing we flag for clients before they become a deadline crunch.

If you're not sure whether your business is affected, the safest assumption is that it is — every Microsoft 365 tenant gets this change, and the fix is a five-minute check per user rather than a project.

Amir
Written by
Amir
Cloud System Engineer · 10+ years in IT

Amir is a Cloud System Engineer with over a decade of experience across server management, networking, cloud solutions and virtualisation. He designs and secures the Microsoft 365, Azure and network environments that Perth businesses rely on, turning complex infrastructure into scalable, efficient solutions.

Meet the IT Support Perth team →
Amir
16 September 2026
5 min read
Microsoft 365
Passkeys
MFA
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Two Chrome Zero-Days in a Week, Plus a Firewall Alert: What to Check Now

Google patched two actively exploited Chrome zero-days within a week, while CISA flagged actively exploited flaws in Cisco, Citrix and Fortinet security gear. Here's what Perth businesses should check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Copilot Is Now Built Into Microsoft 365 Business: Decide Before 30 September

Microsoft has made Copilot a permanent part of its small business plans, with a discounted add-on price ending 30 September 2026. Here's what Perth businesses should check first. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

September 2026 Patch Tuesday Was Microsoft's Biggest Ever: What Perth Businesses Should Check

Microsoft's September 2026 Patch Tuesday fixed a record 966 flaws, including two zero-days already under attack — one inside Windows Update itself. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Copilot Is Now Built Into Microsoft 365 Business: Decide Before 30 September
Microsoft 365
Copilot

Copilot Is Now Built Into Microsoft 365 Business: Decide Before 30 September

Microsoft has made Copilot a permanent part of its small business plans, with a discounted add-on price ending 30 September 2026. Here's what Perth businesses should check first. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/11/2026
4 IT Gaps Small Businesses Overlook (and How to Close Them)
Cybersecurity
Small Business

4 IT Gaps Small Businesses Overlook (and How to Close Them)

Most Perth businesses aren't undone by one huge disaster — it's the small IT gaps that stack up: missing MFA, delayed patching, old access nobody removed, and untested backups. Here's how teams under 50 users can close them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
7/15/2026
Passkeys vs Passwords: A Plain-English Guide for Perth Businesses
Cybersecurity
Passkeys

Passkeys vs Passwords: A Plain-English Guide for Perth Businesses

Passwords are behind most account breaches. Here's how passkeys work, why they're safer, and how your Perth business can start using them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
7/13/2026
Call us