Microsoft Entra ID to Default to Passkeys, Retiring SMS and Voice MFA
Key Takeaways Microsoft is transitioning Microsoft Entra ID to use passkeys as the default authentication method. SMS and voice-based multifactor authentication (MFA) provided by Microsoft will be...
Key Takeaways
- Microsoft is transitioning Microsoft Entra ID to use passkeys as the default authentication method.
- SMS and voice-based multifactor authentication (MFA) provided by Microsoft will be retired, with a full cessation of native telecom delivery by February 1, 2027.
- This change aims to enhance security by moving away from phishing-susceptible authentication methods.
- Organizations must proactively migrate users to passkeys or other phishing-resistant MFA options to avoid service disruption.
Microsoft is making a significant shift in its authentication strategy for Microsoft Entra ID, designating passkeys as the new default sign-in experience. This move is part of a broader initiative to phase out authentication methods vulnerable to phishing, such as SMS and voice-based multifactor authentication (MFA).
Table Of Content
Phasing Out Vulnerable MFA Methods
The company will discontinue its direct provision of SMS and voice authentication for MFA, steering organizations toward more robust, phishing-resistant credentials. This change will commence on September 1, 2026, when users currently configured for SMS or voice authentication will automatically have passkeys enabled for their accounts. During subsequent MFA sign-ins, these users will receive prompts encouraging them to register a passkey.
Microsoft will manage this passkey registration campaign by default, though users will have the option to defer the registration prompt during the transition period. The primary motivation behind this change is to mitigate the security risks associated with SMS and voice-based authentication, which are susceptible to various attack vectors including phishing kits, SIM swapping, social engineering, number porting, and interception.
In contrast, passkeys leverage cryptographic credentials tightly bound to a specific device or a secure credential manager. This design eliminates the need for a reusable shared secret that could be entered on a malicious website, thereby providing robust protection against phishing and replay attacks. Microsoft Entra ID supports both synced and device-bound passkeys.
Understanding Passkey Implementations
Synced passkeys offer flexibility, as they can be stored within credential managers like Apple’s iCloud Keychain or Google Password Manager, allowing users to access them across multiple devices. Device-bound passkeys, on the other hand, remain resident on a single device. Examples include Windows Hello for Business, Microsoft Authenticator passkeys, Entra Passkey on Windows, and FIDO2 hardware security keys.
A critical deadline for this transition is February 1, 2027. By this date, Microsoft will fully retire its native telecom delivery services for SMS and voice MFA within Entra ID. Organizations that still require these channels post-retirement will need to engage a customer-managed telecom provider, which can be sourced through the Microsoft Security Store. Microsoft plans to publish information regarding available providers starting September 18, 2026, with customer selection and configuration expected to be possible from October 30, 2026.
After the February 2027 retirement date, any user whose sole MFA option remains SMS or voice will encounter a mandatory passkey registration prompt during sign-in. Account access will be blocked until a passkey is successfully registered. Microsoft has confirmed there will be no opt-out from this enforcement, underscoring the importance of early migration to prevent disruptions to account access.
What You Should Do
- Identify Affected Users: Administrators should immediately identify users within their organization who are still relying on SMS or voice authentication. Microsoft provides a PowerShell-based analyzer tool to assist in locating these users via the Entra Authentication Methods Policy or legacy MFA configurations.
- Enable Passkey (FIDO2): Activate Passkey (FIDO2) as an available authentication method within your Entra ID tenant.
- Create Targeted User Groups: Organize users into groups to facilitate a phased rollout and registration campaign for passkeys.
- Launch Staged Registration: Initiate a proactive, staged passkey registration campaign for users before the automatic enablement phase begins on September 1, 2026.
- Consider Temporary Opt-Out (with caution): While Microsoft offers a temporary opt-out for the automatic passkey enablement phase (September 1, 2026, to February 1, 2027) via Microsoft Graph’s
passkeyDynamicMigrationproperty, this merely delays the inevitable. It does not circumvent the February 2027 retirement or the mandatory registration requirement. Use this only if absolutely necessary for short-term operational continuity. - Prioritize Phishing-Resistant Methods: Treat SMS and voice MFA as legacy fallback options, not long-term security controls. Prioritize the deployment of passkeys, Windows Hello for Business, and FIDO2 security keys. Customer-managed telecom services for SMS/voice should be reserved for specific regulatory or operational needs only.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.