Entra · Security

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication - A guide to stay calm

· Updated 29 September 2026 · 7 min read · Entra, Security

On this page

I don’t have all the answers, but I promise to keep this post updated with all the details I find.

Microsoft dropped a bomb by announcing it will stop funding phone-based MFA, such as SMS and voice, and that passkeys will become the new standard.

For reference, here are the supporting articles:

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication - Microsoft Entra ID | Microsoft Learn

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID | Microsoft Security Blog

That does not mean SMS and voice is going away soon. It’s just that Microsoft is not going to pay the bill anymore, and ‘gently’ will start pushing passkeys. And in their defence, it’s the most secure and user-friendly option, so it makes total sense.

Timelines#

Microsoft is pretty aggressive about timelines because the first milestone will be in 50 days from the day the news came out. Here in the Netherlands, everyone is packing or has already packed for a 30-day sabbatical (summer holiday), which leaves us with about 20 days of preparation before the first milestone.

DateMilestoneWhat you should do
September 1, 2026Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in.Notify end users of the changes happening. Use the passkey deployment guide to prepare your environment for passkey use.
February 1, 2027Microsoft-provided SMS and voice authentication is retired for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1 retirement.Make sure users in scope for the February 1 retirement are on a phishing-resistant method (passkeys, Windows Hello, or FIDO2) before this date, or they might experience sign-in disruption.
After February 1, 2027Users in scope for the February 1 retirement whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account. There is no opt out from this February 1 behavior for users in scope of the February 1 retirement.Migrate users in scope for the February 1 retirement to a phishing-resistant method or choose a telephony provider to continue using SMS or voice.
July 1, 2027Microsoft-provided SMS and voice authentication is retired for Global Administrators and external users. Internal guest users aren’t included in this July 1 group and still follow the February 1, 2027 retirement date.Make sure Global Administrators and external users are on a phishing-resistant method before this date, or they might experience sign-in disruption.
After July 1, 2027Global Administrators and external users whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account. There is no opt out from this July 1 behavior for Global Administrators and external users.Migrate Global Administrators and external users to a phishing-resistant method or choose a telephony provider to continue using SMS or voice.

The first milestone#

This is a guide to not panicking, so let’s take it step by step. Let’s see how organizations will survive the summer. We deal with the other milestones in later posts.

What will happen on September 1st?

On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP), or in legacy MFA settings, will be auto-enabled for passkeys in AMP. These in scope users will be put into a passkey profile allowing all types of passkeys. Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys, and will automatically bring these users into scope.

When these users next sign-in and complete MFA, the registration campaign will nudge them to register a passkey. By default, users will have unlimited snoozes of the nudge prompt. If you do not want this to occur, move users out of SMS or Voice in AMP before September 1st.

Screenshot from the article

Hmm, that sounds like a big change to me. Going from phone-based MFA to passkeys is a huge step, and I’m sure companies need much more time to make that transition. What about other methods like:

  • Microsoft Authenticator App push
  • Microsoft Authenticator App TOTP
  • Passwordless Phone Sign-in
  • Software OTP
  • Hardware OTP
  • QR code sign-in

Here is the catch:

A temporary opt-out will be available for the September 1, 2026 through February 1, 2027 changes. This allows you to delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods. API support and information for opting out will be available starting August 1, 2026.

So that leaves us with two options for now:

  • Ditch your summer plans, and move everyone over to passkeys within the next 50 days
  • Take a break and use the opt-out/delay API to breathe deeply and develop a good plan to move forward. No need to panic.

(Update) The opt-out setting is now available and explained here.

Graph API
PATCH https://graph.microsoft.com/beta/policies/authenticationmethodspolicy
Content-Type: application/json

{
   "optOutSettings": {
     "passkeyDynamicMigration": true
   }
}

By setting this to true, automatic passkey enablement and Registration Campaign rollout will be ignored untill February 1, 2027.

Conclusion#

I fully agree with Microsoft that we need to eliminate weak MFA methods, but I think we need a bit more time and guidance to get there. I’ll try to keep you posted on any news around this topic.

The message is clear: we will stop paying for your phone-based MFA, and passkeys are the way forward. Thanks for the heads-up, Microsoft, but we need a lot more details to land this plane properly.

Stay safe.

Update July 19#

A new update was added to the Microsoft Learn documentation:

When will passkey support be available for B2B users?#

Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.

Update July 23#

A new update was added to the Microsoft Learn documentation:

Are external MFA methods impacted by SMS and voice retirement?#

No, only SMS and voice authentication method policies and legacy MFA policies are retired.

On September 1, 2026, users who are enabled for SMS or voice in the authentication method policies or legacy MFA policies are auto-enabled for passkeys and nudged to register. External MFA users aren’t in scope unless they’re also enabled for SMS or voice.

Update August 7#

A temporary opt-out is added and explained here. (Also added earlier in the article)

I also learned this retirement will also impact SSPR (self-service password reset). If you want to continue using phone-number as SSPR method, you need to buy a subscription at one of the SMS and voice telecommunications providers.

As security questions are also going away, that leaves you with the Authenticator App or (personal) email for SSPR as alternative options. If you migrate to passkeys, you can consider disabling SSPR as well and fully relying on the Temporary Access Pass for bootstrapping and recovery.

Update September 15#

The timeline for B2B guests and Global admin account changed. It’s now pushed back to July 1st.

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication - Microsoft Entra ID | Microsoft Learn

Screenshot from the article

Update September 25#

First public documentation around telephony providers for SMS and voice authentication

Entra ID telephony providers for SMS and voice MFA: first look - JanBakker.tech

Update September 29#

As stated here, SMS first-factor sign-in will be retired entirely. The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as a multifactor authentication method. If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios.

Comments

Comments load when you scroll here.