Summary
- From 1 September, Entra users enabled for SMS or voice are automatically brought into Microsoft's passkey registration process.
- Microsoft-provided SMS and voice authentication delivery is scheduled to end on 1 February 2027.
- The change makes phishing-resistant authentication a platform default while leaving organisations with a five-month migration and operational-planning period.
Microsoft has started making passkeys the default authentication experience in Entra ID, beginning a transition that will end with the retirement of Microsoft-provided SMS and voice authentication delivery on 1 February 2027.
From 1 September, users who are currently enabled for SMS or voice authentication are being automatically enabled for passkeys and brought into Microsoft’s registration campaign. When those users next complete multi-factor authentication, eligible devices can prompt them to register a passkey.
The change does not mean SMS and voice authentication disappeared on 1 September. Microsoft has created a transition period lasting until February and is allowing organisations to opt out temporarily from the automatic passkey enablement while migration work continues.
The February deadline is different. Microsoft says its native delivery of SMS and voice authentication will be retired on 1 February 2027 and that there will be no opt-out from that platform change. Users whose only available authentication method remains Microsoft-provided SMS or voice could face a blocking passkey-registration step before they can continue signing in.
Organisations with an operational or regulatory reason to retain telecom-based authentication will be able to use customer-managed providers through Microsoft’s Security Store. Provider information is due to become available from 18 September, with configuration expected from 30 October.
The migration pushes a long-running identity-security recommendation into the default behaviour of one of the enterprise market’s largest identity platforms. SMS and voice have remained widely used because they are familiar, broadly accessible, and relatively simple to deploy, but both depend on telecommunications channels that are vulnerable to phishing, SIM-swapping, interception, and social-engineering attacks.
Passkeys replace shared secrets and one-time codes with cryptographic credentials tied either to a device or to a credential manager that can synchronise them securely across devices. Microsoft describes them as resistant to phishing, replay, and SIM-swap attacks.
Entra supports both synced and device-bound passkeys, including credentials stored in platform managers, Microsoft Authenticator, Windows, and hardware security keys. Existing users of Windows Hello for Business and other phishing-resistant methods can continue to use those systems.
The operational effect will differ substantially between tenants. Organisations that have already reduced reliance on SMS and voice may see little more than a change in Microsoft’s default policy. Environments where those methods remain the primary multi-factor mechanism face a larger identity migration involving user registration, device compatibility, support processes, recovery, and exception handling.
That distinction matters because authentication changes can create availability problems as well as security improvements. A strong credential that users cannot enrol or recover reliably can become an access disruption, particularly across large workforces, contractors, shared devices, or environments with constrained mobile-device policies.
Microsoft’s customer-managed telephony option also shifts part of the operational responsibility. Organisations that retain SMS or voice will need to choose a provider, assess regional coverage and compliance requirements, manage the commercial relationship, and monitor delivery rather than relying on Microsoft’s native service.
The broader identity direction is nevertheless clear. Passwordless and phishing-resistant authentication has been moving from specialist deployments towards mainstream platform support for several years. Entra’s change turns that trajectory into a default migration path for users who remain on two of the most phishable authentication channels.
The five-month interval between automatic passkey enablement and the February retirement gives organisations time to control that change rather than treating 1 September as an immediate forced cutover. After February, however, Microsoft’s platform will no longer treat its own SMS and voice delivery as a permanent fallback.




