Microsoft has started switching Entra ID — the sign-in system behind every Microsoft 365 account — over to passkeys by default. Since 1 September 2026, eligible users have been prompted to register a passkey when they sign in. The bigger deadline is 1 February 2027, when Microsoft-provided SMS and voice authentication codes are retired for good. If your business leans on a text message or a phone call as its multi-factor authentication (MFA), that method stops working unless someone configures a replacement before then.
This isn't an optional feature announcement. It's a default change rolling through every Microsoft 365 tenant, and the retirement date is fixed. Here's what it actually means and what to check.
What Microsoft has changed
Two things are happening on different timelines:
- From 1 September 2026, Microsoft turned on its "Registration Campaign" for passkeys as Microsoft-managed in tenants that hadn't already configured it. Users doing MFA sign-in now see a prompt to set up a passkey — tied to Windows Hello, a phone's fingerprint or face unlock, or a physical security key. Staff can skip the prompt for now, so nothing breaks immediately.
- From 1 February 2027, Microsoft-provided SMS and voice codes disappear entirely. Not deprioritised — retired. Any account still depending on a text or phone call for MFA will be locked out of that method the day it switches off.
If your business runs Microsoft 365 Business Basic, Standard or Premium, this applies to you regardless of size. There's no tier that's exempt.
Why this matters more than a routine feature update
We've written before about how SIM-swap and mobile number port-out fraud is rising in WA — criminals hijacking a phone number to intercept exactly these SMS codes. Microsoft's own security team has flagged SMS and voice as the weakest MFA methods it offers, because they depend on the mobile network rather than something cryptographically tied to your account. Passkeys close that gap: a passkey can't be phished, forwarded, or intercepted by a SIM-swap, because the private half never leaves the device it was created on.
So this change is Microsoft pushing every tenant toward a materially stronger default. The trade-off is that it happens automatically, on Microsoft's timeline, whether or not your business has planned for it.
What to check in your tenant now
A few practical things worth doing before the retirement date, not after:
1. Find out who is still using SMS or voice MFA
In the Entra admin centre, under Protection > Authentication methods, you can see which users are registered for SMS or voice as an MFA method. In many small businesses this is a handful of people — often whoever set up their account first, or anyone using a landline for the "call me" option.
2. Get passkeys registered before staff are forced into it
Rather than letting the prompt catch people mid-work, register passkeys deliberately: on a work laptop with Windows Hello, or through the Microsoft Authenticator app on a phone. It takes under a minute per person and avoids a scramble later.
3. Decide what happens to anyone who genuinely can't use a passkey
Field staff sharing a device, warehouse logins, or a service account tied to a landline are the edge cases. If you need phone-based codes to keep working past February 2027, Microsoft requires configuring a third-party telecom provider through the Microsoft Security Store — Microsoft's own SMS/voice won't be there as a fallback any more.
4. Don't forget shared and service accounts
Shared mailboxes and automation accounts sometimes have MFA configured against a mobile number nobody remembers assigning. These are easy to miss because no one signs into them day-to-day, and they're exactly the kind of account that goes quietly locked out in February.
The upside, if you get ahead of it
Handled proactively, this is a security improvement that costs nothing and takes minimal setup time. Passkeys are faster to use than typing in a six-digit code, they can't be phished the way a fake login page tricks someone into handing over a password, and they remove one of the more exploitable MFA methods from your business's attack surface entirely. For more on how passkeys work day-to-day, see our plain-English passkeys guide.
Left until the deadline, it's the opposite: a wave of "why can't I log in" calls in early 2027 from anyone who never got round to registering a passkey.
Where this fits with your wider Microsoft 365 setup
This sits alongside the broader security settings worth reviewing in any Microsoft 365 tenant — see our Microsoft 365 guide for Perth businesses for the fuller picture, or our IT security solutions if you'd rather have someone check the tenant configuration for you. We're a Perth-based MSP that's been supporting local businesses since 1997, and tenant-wide changes like this one are exactly the sort of thing we flag for clients before they become a deadline crunch.
If you're not sure whether your business is affected, the safest assumption is that it is — every Microsoft 365 tenant gets this change, and the fix is a five-minute check per user rather than a project.


