
Yesterday, 22nd July, Microsoft notified us all of their big change to move authentication away from voice and SMS, to Passkeys going forward. Let’s go over why, when, and what you should do to prepare.
So, what are the most important things for you to know?
The short answer is: SMS and voice authentication are no longer considered sufficiently secure.
While adding a code sent to your phone is certainly better than relying on a password alone, cybercriminals have become increasingly effective at bypassing these methods. We live in a time where tactics like SIM swapping and AI-assisted social engineering can all be used to intercept or trick users into handing over authentication codes.
Passkeys, on the other hand, are tied to a trusted device, such as your laptop or smartphone. Rather than typing a code, you’ll typically authenticate using Windows Hello, Face ID, Touch ID or your device PIN. Because there isn’t a reusable code to steal or a password to enter, passkeys are considered phishing-resistant and significantly harder for attackers to compromise. Here’s an example below:

Not every business can move away from SMS or voice authentication overnight, so if this is you, don’t worry!
Microsoft has acknowledged this by allowing organisations to continue using these authentication methods through customer-managed telecom providers available via the Microsoft Security Store. However, keep in mind that Microsoft’s own SMS and voice delivery service will no longer be provided after February 1st, 2027.
Although the deadline may seem some way off, it’s worth preparing sooner rather than later.
We’d recommend:
Taking these steps now can help avoid disruption and hassle later down the line when Microsoft begins enforcing passkeys.

