Microsoft has officially turned the page on legacy authentication. If your organization still leans on SMS and voice-based multifactor authentication (MFA) within Microsoft Entra ID, the clock is now ticking. Starting in September 2026, Microsoft is making passkeys the default authentication method. This isn't just a minor update—it's a critical shift in the platform’s identity security posture, and for those of us focused on risk mitigation, it's about time.
The reality of modern credential theft, particularly as AI-enabled phishing platforms become more sophisticated, has rendered SMS and phishable MFA factors increasingly fragile. Microsoft’s move effectively forces a transition that many organizations have been delaying, largely because phone-based authentication feels easy for end-users to adopt. However, the ease of access for users is precisely why it’s become a massive vulnerability for the enterprise.
The Shift to Passkeys: A Strategic Imperative
For a long time, we’ve talked about the "phishing-resistant" necessity. When Microsoft enabled SMS and voice, it was a practical compromise. That compromise is now a liability. AI-driven campaigns have reached click-through rates as high as 54%, a drastic leap over the 12% we historically associated with traditional phishing. Attackers aren't just sending emails anymore; they are using sophisticated automation to bypass traditional MFA in real-time.
By making passkeys the default, Microsoft is essentially building a stronger defensive wall around Entra ID. For users currently using SMS or voice, this won't be a manual opt-in. When the rollout hits your organization, they will be automatically enabled, and the very next time they need to sign in, they will be prompted to register a passkey. This automation is both a blessing and a challenge for IT departments. While it drives faster adoption, it also means your helpdesk needs to be ready for the inevitable influx of "what is this?" support calls.
Users already settled into phishing-resistant workflows—those of you using FIDO2 keys, Windows Hello for Business, or smart cards—won't see a change. Your current authentication methods remain perfectly valid.
The Security & Compliance Analyst Perspective
From my desk, this transition isn't merely an IT upgrade. It's a compliance event. If you are preparing for audits, particularly those centered around access management, this shift is a clear, documented improvement move by Microsoft.
One of the biggest struggles I see in security programs is the difficulty of enforcing MFA standards across an entire organization. Legacy telephony-based MFA has been the "easiest" way for non-technical users to comply with authentication requirements without needing to manage a security token. But it's also the easiest one to spoof.
With this change, the entire environment effectively gets an upgrade. You’re trading a weak, easy-to-intercept factor for a cryptographic standard that is fundamentally tied to the origin of the request. It’s an essential step in protecting against current SaaS data-theft campaigns. The threat actors—like the ShinyHunters gang—have been specifically homing in on these SSO accounts, making this shift particularly urgent. For security teams constantly battling to stay ahead of identity-focused attacks, this is a much-needed reduction in the attack surface.
The Retirement Timeline
We have to map this transition carefully. The shift begins in September 2026, when passkeys become the default. That’s your soft landing. The hard stop comes on February 1, 2027.
On that date, Microsoft is retiring its own telecom delivery for SMS and voice authentication entirely. It will no longer exist as a native Entra ID capability. Whether your organization is ready or not, that plug is being pulled. There is no opt-out for this behavior. If your internal compliance policy relies heavily on SMS for MFA, you need to be testing your migration strategy now.
Practical Steps for Admins
You don't have to wait for the rollout to start. If you are in a Global Reader, Authentication Policy Administrator, or Security Reader role, you already have the tools to begin your audit.
Microsoft has provided the Entra SMS/Voice Policy Scanner PowerShell script. Run it. Do not skip this step. This script will identify exactly which users are still relying on phone-based authentication. Knowing the scale of the migration is half the battle. Once you've identified these users, you can segment them by technical maturity and start your transition planning.
For those rare scenarios—some industrial or highly specialized environments, perhaps—where telephony-based authentication is still an absolute business necessity, you are not entirely out of options. You will need to move to third-party telecom providers, which can be configured through the Microsoft Security Store. This process obviously introduces extra complexity and cost, so it should only be reserved for genuinely unavoidable use cases.
Ensuring a Smooth Migration
Migration is rarely seamless, regardless of the platform. The most effective approach here is communication. Don't wait for your users to see the registration prompt before you tell them why it's happening.
Draft a clear communication strategy explaining that this change is about securing access to corporate resources against professional-grade phishing attacks. Emphasize that the user experience is designed to be as straightforward as possible, even if it feels different at first. By demystifying the move to passkeys, you reduce the friction and the load on your IT support staff.
This is a pivot, not a suggestion. Microsoft is effectively taking the choice of "weak authentication" off the table for every tenant. For security professionals, it’s a big win, even if it comes with the short-term headache of a large-scale migration project. Start running your reports, identify your dependencies, and use the upcoming months to transition effectively. In an environment where the stakes for identity security have never been higher, this is the kind of platform-wide change we need.