All posts
Microsoft 365 Security 2 min read

Entra makes passkeys the default. SMS/voice retire in 2027. MSPs: here’s the 30-day plan.

Starting Sept 1, 2026, Entra will prompt SMS/voice MFA users to register passkeys. Microsoft-provided SMS/voice retires Feb 1, 2027, with no opt-out. Here’s how MSPs prevent sign-in breaks across tenants.

M Michael July 22, 2026

AI-enabled phishing now drives materially higher click-through than traditional campaigns. Microsoft’s response: make passkeys the default in Entra and phase out Microsoft-provided SMS and voice for MFA.

Key dates MSPs must track

  • Sept 1, 2026: Passkeys become the default sign-in experience for Entra tenants. Users enabled for SMS/voice will be auto-enabled and prompted to register a passkey during MFA.
  • Feb 1, 2027: Microsoft-provided SMS/voice is fully retired. Users whose only MFA is SMS/voice will hit a blocking prompt to register a passkey. There’s no opt-out.
  • Sept 18, 2026: Microsoft will publish details on customer-managed telecom options via the Microsoft Security Store for orgs that must keep SMS/voice.

What to do in the next 30 days (multi-tenant)

  1. Inventory risk:
  • Report who actually uses SMS/voice today and where passkeys are already enabled. Prioritize high-impact roles and shared/device-restricted users.
  1. Set your target authentication baseline:
  • Enable passkeys for all users capable of phishing-resistant auth (passkeys, Windows Hello for Business, FIDO2). Define exceptions per customer.
  1. Update Conditional Access:
  • Require phishing-resistant MFA for admins and sensitive apps. Add registration requirements so passkey prompts land before your deadlines, not during a critical login.
  1. Ready the endpoints:
  • Confirm platform/browser support, security key availability, and managed device policies. Test passkey profiles and attestation behavior.
  1. Communications + support:
  • Send tenant-branded guides, schedule desk-side enrollments for frontline users, and script help-desk flows for blocked sign-ins after Feb 1, 2027.
  1. Decide on SMS/voice continuity (if required):
  • If regulation or edge cases demand OTP by phone, plan a customer-managed telecom provider via the Microsoft Security Store and budget for carrier fees.

Practical takeaway

This shift is coming with hard dates. If you don’t move users to phishing-resistant methods, they will be forced to register passkeys during sign-in, and production will stop while they do it. What percentage of your customers’ users still rely on SMS/voice today? Start with that number and work it down weekly.

See TenantForge in your own tenants

Connect a tenant read-only and get your first baseline comparison in minutes. 14-day trial, no credit card.

Start free trial