Solutions4IT Logo
Money Back Guarantee
6 Month Trial Period
Plain English IT Support
No jargon, no tricky words
Trustworthy & Reliable
4.9* Google Reviews
Happy clients
99% Customer Satisfaction

Microsoft Moves to Passkeys- The Death of SMS & Voice Authentication!

Yesterday, 22nd July, Microsoft notified us all of their big change to move authentication away from voice and SMS, to Passkeys going forward. Let’s go over why, when, and what you should do to prepare.

 

The Key Details

So, what are the most important things for you to know?

  1. Any user that has SMS or voice authentication will be nudged to register a passkey the next time they complete MFA. This will happen on September 1st, 2026.
  2. Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID. This will happen on February 1st, 2027.
  3. After February 1st, 2027, users will be blocked from signing in until they register a passkey.

 

Why is Microsoft making this change?

The short answer is: SMS and voice authentication are no longer considered sufficiently secure.

While adding a code sent to your phone is certainly better than relying on a password alone, cybercriminals have become increasingly effective at bypassing these methods. We live in a time where tactics like SIM swapping and AI-assisted social engineering can all be used to intercept or trick users into handing over authentication codes.

Passkeys, on the other hand, are tied to a trusted device, such as your laptop or smartphone. Rather than typing a code, you’ll typically authenticate using Windows Hello, Face ID, Touch ID or your device PIN. Because there isn’t a reusable code to steal or a password to enter, passkeys are considered phishing-resistant and significantly harder for attackers to compromise. Here’s an example below:

Microsoft Passkey

 

What if your organisation still needs SMS authentication?

Not every business can move away from SMS or voice authentication overnight, so if this is you, don’t worry!

Microsoft has acknowledged this by allowing organisations to continue using these authentication methods through customer-managed telecom providers available via the Microsoft Security Store. However, keep in mind that Microsoft’s own SMS and voice delivery service will no longer be provided after February 1st, 2027.

 

What should businesses do now?

Although the deadline may seem some way off, it’s worth preparing sooner rather than later.

We’d recommend:

  • Reviewing how your users currently authenticate with Microsoft 365 and Entra ID.
  • Identifying anyone still relying on SMS or voice-based MFA.
  • Ensuring devices support Windows Hello, Face ID, Touch ID or another passkey-compatible authentication method.
  • Communicating the upcoming changes to employees before Microsoft’s registration prompts begin in September 2026.
  • Running a pilot group to familiarise users with passkeys before rolling them out across the business.

Taking these steps now can help avoid disruption and hassle later down the line when Microsoft begins enforcing passkeys.

© Copyright Solutions 4 IT Ltd 2026. All Rights Reserved. Terms & Conditions Privacy Policy
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.