Business TechSoftware

Microsoft is pushing Entra ID users away from SMS passkeys are now the default

Microsoft has started a major change to how millions of business users sign in to corporate accounts.

From 1 September 2026, Microsoft Entra ID now treats passkeys as the default authentication method for users who still rely on SMS or voice verification.

Microsoft will automatically enable those users for passkeys as the rollout reaches their organisation.

The next time they complete multifactor authentication, Entra ID can prompt them to register a passkey.

The change marks the beginning of a much bigger transition.

On 1 February 2027, Microsoft plans to stop providing SMS and voice authentication natively through Entra ID.

For businesses that still depend on verification codes sent to phones, the clock has started.

Microsoft wants businesses to move beyond SMS codes

SMS-based multifactor authentication helped companies add a second layer of security beyond passwords.

However, attackers have become much better at defeating it.

Criminals can steal verification codes through phishing sites. They can also use social engineering, SIM-swap attacks and other methods to intercept phone-based authentication.

Passkeys work differently.

Instead of sending a secret code that a user types into a website, a passkey uses cryptographic credentials.

The private part of the credential stays on the user’s device or inside a trusted credential manager.

The website or service receives proof that the correct credential exists.

There is no reusable code for an attacker to steal.

That makes passkeys resistant to many common phishing attacks.

What changes for Entra ID users now?

Microsoft is not disabling SMS authentication immediately.

The September change starts the migration.

Users who have SMS or voice enabled can automatically become eligible for passkeys.

When they next complete an MFA sign-in, Microsoft can ask them to create one.

Users can initially postpone the registration prompt.

That gives companies time to prepare employees and update internal support processes.

However, organisations should not treat that flexibility as permanent.

Microsoft has already set the next deadline.

From 1 February 2027, the company will stop delivering SMS and voice authentication messages itself.

Businesses that fail to prepare could face sign-in problems.

What happens on 1 February 2027?

The February deadline creates the biggest change.

Microsoft-provided SMS and voice authentication will end in public-cloud Entra ID environments.

Users who only have SMS or voice available will then need another authentication method.

If they do not have one, Microsoft will require them to register a passkey before they can continue signing in.

Unlike the earlier migration prompts, companies will not be able to opt out of that requirement.

Microsoft recommends moving employees to passkeys or another phishing-resistant method before the deadline.

Businesses that genuinely need SMS or voice will still have another option.

They will need to use a third-party telecommunications provider instead of Microsoft handling those messages directly.

Businesses can still keep SMS if they really need it

Microsoft is not removing the ability to use phone-based verification entirely.

Some organisations operate in industries where regulations or unusual technical environments may still require SMS or voice.

Those businesses will be able to choose a telecommunications provider through the Microsoft Security Store.

The company plans to make information about supported providers available from 18 September 2026.

Administrators will be able to configure supported providers from 30 October 2026.

The organisation will then manage the relationship with that provider.

Microsoft clearly sees this as an exception rather than the preferred path.

For most users, it wants passkeys to replace SMS.

Entra ID supports more than one type of passkey

Microsoft supports both synced and device-bound passkeys.

A synced passkey can live inside a credential manager and move between a user’s devices.

Examples include passkeys stored through Google Password Manager or Apple’s iCloud Keychain.

This approach can make passkeys easier for ordinary employees because they follow the user across supported devices.

A device-bound passkey stays tied to a specific device or security key.

Microsoft Authenticator can store device-bound credentials.

Windows devices can also use Entra passkeys.

Businesses can use physical FIDO2 security keys for employees who need stronger hardware-backed authentication.

Organisations can therefore choose different options for different types of users.

Passkeys remove one of phishing’s most useful tricks

Passwords and verification codes share a major weakness.

Users can type them into the wrong website.

An attacker can build a convincing copy of a Microsoft sign-in page and persuade an employee to enter a password.

The attacker can then ask for the MFA code.

If the victim supplies it quickly enough, the criminal may gain access.

A passkey checks the website it belongs to.

A credential created for Microsoft’s legitimate service will not authenticate an attacker-controlled phishing site.

That makes the sign-in process much harder to relay through a fake page.

Passkeys also remove the need for users to read and type temporary codes.

For businesses, stronger security could therefore come with a simpler login process.

This matters even more as AI improves phishing

Microsoft has linked the authentication change to the changing security environment.

Generative AI has made it easier to create convincing phishing messages.

Attackers can produce better-written emails, personalised messages and believable fake conversations at scale.

They can also automate more parts of an attack.

This increases the value of security controls that do not depend on a person spotting every scam.

Security awareness training still matters.

However, even well-trained employees make mistakes.

A phishing-resistant authentication method can block an attack even when a user clicks the wrong link.

That is one reason Microsoft is moving passkeys from an optional security feature towards the default.

South African businesses should start checking their Entra environments

The change has direct relevance to South African organisations.

Microsoft Entra ID forms part of the identity infrastructure behind many Microsoft 365 and enterprise deployments.

Businesses, schools, government organisations and other institutions use it to control access to applications and cloud services.

IT departments should identify employees who still rely on SMS or voice MFA.

They should then plan how those users will move to passkeys or another supported phishing-resistant method.

Large organisations should not wait until January 2027.

A migration can create support questions.

Employees may need help registering credentials on phones, laptops or hardware security keys.

Companies also need recovery procedures for lost or replaced devices.

Testing those processes before Microsoft removes native SMS delivery will reduce the risk of disruption.

Passkeys do not mean passwords disappear everywhere overnight

The word “passkey” often gets mixed up with the broader idea of passwordless computing.

The two concepts overlap, but businesses should not assume this change instantly removes every password.

An employee may still encounter passwords in older applications or systems that do not support modern authentication.

Some organisations also use several identity platforms.

Microsoft’s change specifically targets the authentication experience in Entra ID.

Its goal is to move more users towards phishing-resistant credentials.

The wider transition away from passwords will take longer.

IT departments can temporarily delay the September change

Microsoft does provide a temporary opt-out during the transition period.

Administrators that need extra time can prevent the automatic passkey enablement and registration campaign from applying immediately.

That option lasts only during the migration window.

It does not cancel the February 2027 deadline.

From that date, Microsoft will enforce the new sign-in requirements across affected public-cloud tenants.

Businesses that use the temporary delay should therefore treat it as preparation time rather than a way to avoid the change.

Microsoft is making identity security a bigger part of its platform

Microsoft’s decision reflects a broader change in enterprise cybersecurity.

Identity has become one of the most valuable targets for attackers.

A stolen employee account can provide access to email, documents, cloud services and business applications.

Administrative accounts create even greater risks.

Microsoft has responded by putting more security controls into Entra, Windows and its wider cloud platform.

Passkeys fit into that strategy.

The company already supports Windows Hello for Business, FIDO2 security keys and other passwordless authentication options.

Making passkeys the default pushes those technologies towards a much larger group of users.

Who is Microsoft today?

Microsoft was founded in 1975 by Bill Gates and Paul Allen.

The company built its early success around software for personal computers before Windows and Office turned it into one of the world’s largest technology businesses.

Today, Microsoft operates across cloud computing, enterprise software, cybersecurity, gaming, artificial intelligence and consumer technology.

Satya Nadella serves as chairman and chief executive officer.

Microsoft Azure has become one of the company’s most important platforms, while Microsoft 365 remains central to its enterprise business.

Entra forms Microsoft’s identity and access-management portfolio.

It includes Entra ID, the service previously known as Azure Active Directory.

The company renamed Azure AD to Microsoft Entra ID in 2023 as it expanded the Entra security brand.

The February deadline matters more than the September prompt

For employees, the visible change may begin with a simple message asking them to create a passkey.

For IT departments, the significance runs much deeper.

Microsoft has now set an end date for one of the most common enterprise MFA methods it provides.

SMS authentication will not vanish from the world on 1 February 2027.

However, Microsoft no longer wants to provide it as the default safety net for Entra customers.

Businesses now have two choices.

They can move users towards phishing-resistant authentication.

Or they can take responsibility for maintaining phone-based authentication through another provider.

Microsoft has made its preferred option clear.

The future of Entra ID sign-ins is built around passkeys, not text messages.