Microsoft’s passkey default and the SMS deadline

Microsoft Is Making Passkeys the Default: What Phishing-Resistant MFA Means for Your Business

Microsoft is making passkeys the default in Entra ID and retiring text-message codes on February 1, 2027. What changes, who has to act first, and how to roll it out.

Cybersecurity & Compliance

Book a 15-minute call

In shortWhat changes, who acts first, and how to roll out

On September 1, 2026, Microsoft began rolling out passkeys as the default sign-in method in Microsoft Entra ID, and on February 1, 2027, it stops delivering SMS and voice verification codes. For every business on Microsoft 365, that makes phishing-resistant MFA the default path and puts a hard date on text-message codes. Here is what is changing, who has to act, and how to move your organization before the deadline instead of on it.

What Microsoft Is Changing and When

According to Microsoft Learn’s guidance on passkeys by default and the SMS and voice retirement, the change arrives in two stages:

  • From September 1, 2026: passkeys become the default authentication experience. Users enabled for SMS or voice are automatically enabled for passkeys and prompted to register one the next time they complete MFA. The rollout reaches tenants at different times, so some organizations are seeing prompts now and others have not yet.
  • From February 1, 2027: Microsoft retires its own delivery of SMS and voice verification codes. Organizations with a genuine business need can keep those methods only by configuring their own telephony provider.

Microsoft offers a temporary opt-out that delays passkey enablement until February 1, 2027, but not for everyone. Global Administrators and external users whose only MFA method is SMS or voice must register a passkey during sign-in, and that prompt cannot be skipped. Microsoft explains its reasoning in the Microsoft Security blog announcement on passkeys as the Entra ID default.

Why Text-Message Codes Are Going Away

SMS and voice codes were a big step up from passwords alone, but attackers have caught up. SIM-swap fraud redirects a victim’s phone number to a device the attacker controls. Adversary-in-the-middle phishing kits sit between the user and the real Microsoft login page, capturing the password, the one-time code, and the session token in a single visit. A code typed into a convincing fake page works just as well for the attacker as for the employee.

Passkeys close that gap. They use public-key cryptography tied to the real website, so there is no code to intercept and nothing a fake login page can reuse. That is why this change matters more than a routine settings update: it closes off one of the most common ways business email accounts get taken over, which is where much business email compromise and wire fraud begins. Our managed cybersecurity program treats identity as the first line of defense for exactly that reason.

What Counts as Phishing-Resistant MFA

  • Passkeys, including passkeys stored in Microsoft Authenticator.
  • Windows Hello for Business, which signs users in with a face, fingerprint, or PIN tied to the device.
  • FIDO2 security keys, physical keys that work well for shared workstations or staff without a company phone.
  • Certificate-based authentication and smart cards.

Push approvals in Microsoft Authenticator are far stronger than text messages, but they are not phishing-resistant: a tired employee can still approve a prompt an attacker triggered, or approve a sign-in on a fake page. Users already on a phishing-resistant method keep using it without interruption.

Who Needs to Act First

  • Anyone whose only MFA method is SMS or a phone call.
  • Global Administrators and other privileged accounts, where the registration prompt is mandatory.
  • External and guest users who sign in to your tenant.
  • Shared accounts, front-desk workstations, and staff without a smartphone, who will need a security key or Windows Hello.
  • Business apps you sign in to through Microsoft 365 that set their own MFA requirements for admins.

A Rollout Plan That Avoids a Help Desk Flood

  1. Inventory current methods. Use the Entra ID authentication methods reports to see exactly who still relies on SMS or voice.
  2. Start with administrators. Move every privileged account to a passkey or security key first, since those prompts cannot be deferred.
  3. Tell users before Microsoft does. A short notice explaining the prompt, why it is legitimate, and how long it takes prevents a wave of “is this a phishing email?” tickets.
  4. Cover the edge cases. Issue FIDO2 keys for shared stations and staff without phones, and enable Windows Hello on managed laptops.
  5. Enforce with Conditional Access. Require phishing-resistant authentication strength for administrators, then expand to all users. Progress shows up in your Microsoft Secure Score, which tracks MFA coverage among its identity recommendations.
  6. Remove SMS and voice. Once every user has a stronger method, disable the old ones before February 1, 2027.

How VirtuWorks Is Handling the Transition

VirtuWorks is moving all of the roughly 300 Microsoft tenants it manages to phishing-resistant MFA ahead of Microsoft’s February 1, 2027 cutoff, with user communication sent before the registration prompts appear. In the Full User plan, the identity baseline includes Conditional Access enforcement of MFA, ongoing MFA compliance monitoring, and 365-day sign-in log retention. The Compliance and AI Readiness Add-On extends that with risk-based Conditional Access, Privileged Identity Management for time-bound administrator access, and full Identity Protection analytics. Attackers are also using AI to make fake login pages harder to spot, as we covered in our look at AI-generated phishing and deepfake business email compromise.

Getting Ahead of the Deadline

The organizations that handle this well will make the move on their own schedule, with users warned and edge cases covered, rather than reacting to prompts and a February deadline. If you are not sure how many of your users still rely on text-message codes, Schedule a Call and we will pull the numbers from your tenant and map the transition.

Frequently asked questions

Is Microsoft getting rid of text-message MFA?
Microsoft retires its own delivery of SMS and voice codes on February 1, 2027. Organizations can keep those methods only by configuring their own telephony provider, and Microsoft no longer positions them as secure.
When will our users see the passkey prompt?
The rollout began September 1, 2026 and reaches tenants at different times. Users enabled for SMS or voice are prompted to register a passkey the next time they complete MFA.
Can we delay the change?
A temporary opt-out delays passkey enablement until February 1, 2027. It does not apply to Global Administrators and external users whose only method is SMS or voice.
What about employees without a company phone?
FIDO2 security keys and Windows Hello for Business are both phishing-resistant and do not require a smartphone.
Will users already using passkeys or Windows Hello be affected?
No. Users on any phishing-resistant method continue signing in as they do today.

Referenced in this article

Written by the VirtuWorks team

VirtuWorks has run IT and security operations for Miami professional-services firms since 1994. ISO 27001, ISO 20000 and ISO 9001 certified, SOC 2 Type II attested, with a 24/7 US-based helpdesk.

Published 5 October 2026

VirtuWorks service

Managed Cybersecurity

Protection for every endpoint and identity, monitored by the VirtuWorks Security Operations Center.

Explore Managed Cybersecurity