Microsoft is replacing text and phone-call verification codes with a stronger, phishing-resistant credential, and it's giving every tenant a deadline to make the switch.
What's changing
Microsoft is moving away from SMS and voice codes because they're the weakest link in MFA. Text messages can be intercepted, phone numbers can be hijacked through SIM-swap attacks, and voice calls are an easy target for social engineering. Passkeys, built on the FIDO2 standard, close those gaps. They come in two flavors: synced passkeys stored in something like iCloud Keychain or Google Password Manager, and device-bound passkeys tied to Windows Hello, Microsoft Authenticator, or a physical security key.
Two dates matter here.
September 1, 2026: Passkeys become the default authentication method in Entra ID. Anyone currently set up for SMS or voice is automatically enabled for passkeys and nudged to register one, but SMS and voice still work as a fallback during this window.
February 1, 2027: That fallback disappears. Microsoft-provided SMS and voice authentication is retired entirely. Any user whose only MFA method is SMS or voice hits a blocking prompt requiring passkey registration before they can sign in. There is no opt-out for this date. It applies to every tenant.
Why this matters for mid-market companies
A six-month runway sounds generous until you map it against a normal IT workload and a workforce that isn't all in one office.
Mid-market IT teams are usually small, and MFA rollouts touch every single employee, including the ones who are hardest to reach: remote workers, field staff, executives who resist change, and anyone using a shared or older device that doesn't support passkeys cleanly.
There's also a real business-continuity risk buried in the February 2027 date. If a meaningful share of your workforce hasn't registered a passkey by then, you're looking at a wave of locked-out users on the same day. Your help desk fields the fallout. That's an entirely avoidable problem if the migration is planned rather than reactive.
Start with a "break-glass" account
Before you make major configuration changes to your tenant, one piece of advice.
We always recommend that an organization has at least one "break-glass" account that has been assigned as a Global Administrator of your tenant. This account should be exempt from Conditional Access Policies so at least one person (or team) can log in if an erroneous condition is implemented. This is obviously a very high-level access account, so protect it accordingly. Configuring the account with a physical device like a YubiKey is a great method to eliminate unauthorized use. Label the YubiKey and lock it away in a safe to limit access to it.
What to do now
Six concrete steps get you ahead of both deadlines.
1. Find out who's actually affected. Microsoft has published a PowerShell script that identifies which users in your tenant currently rely on SMS or voice for MFA. Run it early so you can plan a migration around your current deployment.
2. Turn on passkeys and start rollout planning. Enable passkey (FIDO2) as an authentication method in Entra ID and work through Microsoft's passkey deployment guide. Prioritize your highest-risk users first: finance, executives, and anyone with elevated access.
3. Use a registration campaign to drive adoption. Entra's admin center lets you configure a registration campaign targeted at your SMS/voice user group, so affected employees get prompted to set up a passkey the next time they sign in, rather than relying on a one-time email that gets ignored.
4. Communicate early and more than once. Microsoft provides end-user templates for awareness, step-by-step registration instructions, and reminders. Mid-market companies especially benefit from over-communicating this one: a short heads-up three months out, a how-to two months out, and a reminder for stragglers two weeks before your internal cutoff.
5. Decide if you have a genuine exception case. Some organizations have regulatory or operational reasons to keep telecom-based SMS/voice around. If that's you, Microsoft is enabling customer-managed telecom providers through the Microsoft Security Store, but that path needs to be configured by October 30, 2026. Treat this as an exception you have to justify and set up on a deadline of its own, not a default option.
6. Set an internal deadline well before Microsoft's. Don't plan around February 1, 2027. Set your own target for October or November 2026 so you have breathing room to handle stragglers, device compatibility issues, and help-desk tickets before Microsoft's enforcement kicks in.
The companies that get ahead of this will barely notice the transition.
The ones that wait will be doing it in a panic in January 2027.
The bottom line
This change is a net positive for security. Passkeys are a meaningfully stronger defense against the phishing and account-takeover attacks that target businesses every day. But the value only shows up if the migration is planned. Treat this like any other compliance deadline: assign an owner, set milestones well ahead of Microsoft's dates, and communicate early.
If you want help auditing your tenant, planning the rollout, or building the internal communication plan, that's exactly the kind of project our Security Practice and Managed Services team handles every day. Reach out and we'll help you map it out.
Co-authored by Josh Gilbert, Security Consultant at Digital Elevation.