Entra makes passkeys the default. SMS/voice retire in 2027. MSPs: here’s the 30-day plan.
Starting Sept 1, 2026, Entra will prompt SMS/voice MFA users to register passkeys. Microsoft-provided SMS/voice retires Feb 1, 2027, with no opt-out. Here’s how MSPs prevent sign-in breaks across tenants.
AI-enabled phishing now drives materially higher click-through than traditional campaigns. Microsoft’s response: make passkeys the default in Entra and phase out Microsoft-provided SMS and voice for MFA.
Key dates MSPs must track
- Sept 1, 2026: Passkeys become the default sign-in experience for Entra tenants. Users enabled for SMS/voice will be auto-enabled and prompted to register a passkey during MFA.
- Feb 1, 2027: Microsoft-provided SMS/voice is fully retired. Users whose only MFA is SMS/voice will hit a blocking prompt to register a passkey. There’s no opt-out.
- Sept 18, 2026: Microsoft will publish details on customer-managed telecom options via the Microsoft Security Store for orgs that must keep SMS/voice.
What to do in the next 30 days (multi-tenant)
- Inventory risk:
- Report who actually uses SMS/voice today and where passkeys are already enabled. Prioritize high-impact roles and shared/device-restricted users.
- Set your target authentication baseline:
- Enable passkeys for all users capable of phishing-resistant auth (passkeys, Windows Hello for Business, FIDO2). Define exceptions per customer.
- Update Conditional Access:
- Require phishing-resistant MFA for admins and sensitive apps. Add registration requirements so passkey prompts land before your deadlines, not during a critical login.
- Ready the endpoints:
- Confirm platform/browser support, security key availability, and managed device policies. Test passkey profiles and attestation behavior.
- Communications + support:
- Send tenant-branded guides, schedule desk-side enrollments for frontline users, and script help-desk flows for blocked sign-ins after Feb 1, 2027.
- Decide on SMS/voice continuity (if required):
- If regulation or edge cases demand OTP by phone, plan a customer-managed telecom provider via the Microsoft Security Store and budget for carrier fees.
Practical takeaway
This shift is coming with hard dates. If you don’t move users to phishing-resistant methods, they will be forced to register passkeys during sign-in, and production will stop while they do it. What percentage of your customers’ users still rely on SMS/voice today? Start with that number and work it down weekly.