Microsoft 365 Passkeys: Prepare Your Team for the SMS MFA Changes

/ Key takeaways
- What should your business do now?
- Which dates matter, and who is affected?
- What is a passkey, in plain English?
What should your business do now?
Find the people who still use SMS or voice calls to sign in, then test a phishing-resistant replacement with a small group. Microsoft is changing the authentication experience in Entra ID, the identity service behind Microsoft 365 work accounts. A successful rollout needs working devices, clear instructions, and a recovery route for someone who loses their phone or security key.
Picture a colleague travelling to a client meeting. They replace a phone over the weekend and arrive on Monday unable to open Outlook. The office may have enabled a stronger sign-in method, but nobody explained how to recover it. That is the kind of interruption worth preventing while you still have time to test.
Which dates matter, and who is affected?
Microsoft's current retirement guidance separates ordinary users from Global Administrators and external users. The change concerns Microsoft-provided SMS and voice delivery, so avoid treating it as a ban on every authentication option other than passkeys.
| Milestone | Affected accounts | Planning implication |
|---|---|---|
| From 1 September 2026 | Users enabled for SMS or voice | Automatic passkey enablement and registration prompts begin. Check what your tenant is showing users. |
| 1 February 2027 | Users other than Global Administrators and external users | Prepare for retirement of Microsoft-provided SMS and voice delivery. Internal guest users follow this date. |
| 1 July 2027 | Global Administrators and external users | These groups have a later retirement date. Include them in a separate readiness check. |
Guidance checked on 24 September 2026. Confirm the current Microsoft documentation and your tenant notices before setting a change window. Where there is a genuine need to retain telephony, assess Microsoft's provider options separately rather than assuming existing text-message sign-ins will carry on unchanged.
What is a passkey, in plain English?
A passkey uses a cryptographic credential to prove that you are signing in. You unlock it with an approved device or security key instead of typing a text-message code into a website. The credential is tied to the legitimate service, which helps resist the fake sign-in pages used in phishing.
That does not make the whole account invulnerable. Device security, access permissions, recovery checks, and session protection still matter. Treat the rollout as one part of your identity security controls, with a clear owner after launch.
Choose a method people can actually use
Start with the work people do. A finance employee using one managed laptop has a different day from a warehouse supervisor moving between shared terminals. Buying the same key for everyone before checking those situations can create avoidable support work.
| Work pattern | What to assess | Test before rollout |
|---|---|---|
| Staff with assigned devices | Supported platform credentials or device-bound passkeys | Normal browser sign-in, device replacement, and remote work |
| People using shared computers | An individually assigned hardware key where supported | USB or NFC compatibility and the shared-device sign-out process |
| Administrators | A separately governed phishing-resistant credential | Privileged access and recovery without depending on one person's phone |
| Contractors and external users | The identity and access arrangement for each group | Which organisation owns registration, support, and account removal |
Use Microsoft's passkey configuration guidance to check supported devices, authentication policies, and registration requirements. A familiar product name on a purchase order is not a compatibility test.
Run a small pilot before changing everyone's sign-in
- Build an account list.Record current authentication methods, device types, account owners, and any users who cannot follow the standard process. Keep credentials and recovery secrets out of the spreadsheet.
- Choose a representative group.Include someone remote, someone on a shared device, and someone who relies on a less common business application. A pilot made up only of IT staff misses useful problems.
- Test everyday work.Check email, collaboration tools, browser sessions, and applications using the work account. Record the exact device and browser when something fails.
- Rehearse recovery.Walk through a missing key or replaced phone using an authorised test account. Confirm who verifies the request and who can approve recovery.
- Expand in manageable groups.Give each group a support contact and a clear change window. Resolve repeated issues before inviting the next group.
For teams split between the US and UK, assign support cover for each rollout window. A helpdesk that has finished for the day cannot rescue a colleague whose sign-in method has just changed. Record local times in the communication, along with the name of the person coordinating the rollout.
Make account recovery part of the plan
An urgent request to replace an authentication method deserves a reliable identity check. Do not let a convincing phone call become the easiest route around the new controls. The service desk needs a written recovery process, a way to escalate unusual requests, and a record of the decision.
Administrative recovery needs its own preparation. Microsoft recommends at least two emergency access accounts, protected and tested for use when normal administrator access fails. Follow that guidance with your identity administrator. Do not improvise broad policy exemptions during a busy rollout.
- Affected account groups have a named owner.
- The pilot covers the devices and applications people actually use.
- Lost-device and lost-key recovery has been tested.
- Administrators have a separately tested emergency access route.
- Users know when the change happens and where to get help.
- Exceptions have a reason, an owner, and a review date.
If those checks are still unanswered, start with a focused Entra ID and identity review. It gives the rollout a workable scope before it becomes a stream of support tickets. Businesses already reviewing Microsoft 365 support can include authentication, device management, and account recovery in the same conversation.
Need a workable passkey rollout plan?
Tell us how many people use Microsoft 365, which devices they use, and who manages sign-ins today. We can help identify the accounts, pilot checks, and recovery arrangements that need attention.
Get Free IT Assessment/ Article map
What should your business do now?
Which dates matter, and who is affected?
What is a passkey, in plain English?
Choose a method people can actually use
Run a small pilot before changing everyone's sign-in
Make account recovery part of the plan
Sources
Frequently Asked Questions
Does installing Microsoft Authenticator mean someone already uses a passkey?
No. The app name alone does not tell you which sign-in method is configured. Check the registered method and policy, then test the actual sign-in experience before marking that person ready.
Do all employees need a hardware security key?
Not necessarily. The suitable method depends on supported devices, your authentication policies, and how each person works. Test those requirements before buying hardware for the whole company.
Should we disable SMS authentication immediately?
Use a controlled transition. Identify affected users, test their replacement method and recovery process, and confirm the current Microsoft timeline before changing access policies.
What should we ask an IT provider to deliver?
Ask for an account inventory, a documented pilot, user instructions, tested recovery steps, an exception list, and evidence that the agreed sign-in paths work. A policy screenshot alone does not demonstrate a successful rollout.
/ Choose the next step
Move from article guidance to a practical review path.
Pick the route that best matches the issue behind the article so the next conversation starts with the right scope.
Security path
Use the assessment to review exposure first
The free assessment is the right first move when identity, endpoint protection, backup readiness, email security, or Microsoft Defender coverage needs review.
Service path
See cybersecurity coverage in practice
Review how BPro Technologies handles access hardening, endpoint protection, visibility, remediation, and evidence without using scare tactics or vague promises.
Team path
Send the current security concern
If the issue is urgent, share what changed, what tools you have, and what is already protected so the team can review the safest next step.