Reviewed by Brian Kinane · SetupPasskeys product author · 27 July 2026
Microsoft Entra passkeys become the default: what IT must do before 2027
Microsoft has announced a two-stage change to authentication in Entra ID. The first stage begins on 1 September 2026, when Microsoft starts making passkeys the default for users enabled for SMS or voice. The second arrives on 1 February 2027, when Microsoft-provided SMS and voice delivery ends in public-cloud tenants.
The announcement creates urgency, but it does not create an organisational rollout plan. Identity teams still have to find the affected population, decide which passkey providers to support, test the device journeys, prepare employees and support teams, manage recovery, and enforce phishing-resistant authentication safely.
September starts a transition, not a universal lockout. February is the firmer operational date for affected public-cloud users who still depend on Microsoft-provided SMS or voice. Microsoft documents customer-managed telecom as an alternative, so check your tenant and provider configuration before assuming every SMS user follows the same path.
Check your likely impact and build a rollout-readiness score →
The two Microsoft dates, precisely
| Date | Microsoft change | What it means for IT |
|---|---|---|
| 1 September 2026 | Microsoft begins rolling out passkeys as the default authentication method for users enabled for SMS or voice. Microsoft provides a temporary opt-out during the transition. | Users may see a passkey registration experience before your internal programme is ready. Prepare communications, support, pilot evidence, and approved providers ahead of the prompt. |
| 1 February 2027 | Microsoft-provided SMS and voice delivery retires in Entra ID public-cloud tenants. Microsoft documents customer-managed telecom as an alternative. | Users who rely only on the retired Microsoft-provided methods encounter blocking passkey registration before they can continue. The transition-period opt-out no longer avoids this behaviour. |
These details come from Microsoft’s Entra security announcement and the Microsoft Learn retirement guidance.
The September date begins Microsoft’s default-method transition. The February date retires Microsoft-provided delivery in public-cloud tenants and introduces the blocking registration behaviour for affected users. Tenant type, existing authentication methods, and customer-managed telecom all affect the practical impact.
Who should treat this as a priority?
Start with organisations that use Microsoft Entra ID in the public cloud and still have a meaningful population registered for SMS or voice authentication. The most exposed groups are usually not identical to the easiest pilot group.
- Users whose only usable MFA is Microsoft-provided SMS or voice. They need another supported route before February.
- Frontline, shared-device, or restricted-device users. Their registration and recovery path may need different testing from office workers.
- Executives, administrators, and high-risk users. They benefit from early phishing-resistant authentication but also require carefully rehearsed recovery.
- Teams with mixed mobile platforms and passkey providers. The prompts and storage choices differ across iPhone, Android, Samsung, Windows, hardware keys, and cross-device sign-in.
- Help desks without a tested recovery path. Registration questions, replaced devices, lost authenticators, and Temporary Access Pass processes can create avoidable support demand.
Do not infer method usage from licensing, a domain check, or the presence of Microsoft 365. Use Entra authentication-method reporting to identify the real population, then segment it by user risk, device pattern, and support needs.
Why passkeys matter beyond the deadline
A passkey is bound to the genuine service origin, so it is designed not to release a reusable secret to a lookalike phishing site. The user unlocks the credential with the device mechanism they already use, such as biometrics or a PIN. That can remove password entry and one-time-code handling from the normal sign-in journey.
The business case is therefore wider than compliance with a Microsoft change: phishing-resistant authentication, fewer password and code interactions, a faster routine sign-in, and less dependence on telecom delivery. Those benefits still depend on sound policy, supported devices, recovery controls, and user adoption. A passkey licence or enabled toggle alone does not deliver them.
A practical six-part rollout plan
- Measure the starting population. Export registration data, identify SMS/voice dependencies, confirm whether customer-managed telecom is in use, and segment cohorts by device and risk.
- Choose the supported passkey model. Define approved providers, attestation and AAGUID choices, synced versus device-bound credentials, hardware-key use cases, and Temporary Access Pass policy.
- Pilot every real journey. Test registration, routine sign-in, cross-device sign-in, device replacement, lost-device recovery, and support escalation on the platforms your people actually use.
- Prepare trust-building communications. Explain why the prompt appears, what a legitimate screen looks like, where the passkey will be stored, what IT will never ask for, and how to get verified help.
- Rehearse enforcement. Build a phishing-resistant Conditional Access policy in report-only mode. Validate dependencies and exclusions, and protect cloud-only emergency access accounts before widening scope.
- Roll out in measured cohorts. Track registration, sign-in success, support demand, recovery events, and policy results weekly. Use the evidence to decide when the next group is ready.
What Microsoft provides — and what your organisation still owns
Microsoft provides the Entra authentication capability, policy controls, reporting, and product documentation. Its automatic experience helps users register. It does not know your supported devices, approved authenticator providers, help-desk model, internal change calendar, employee language, emergency procedures, or risk appetite.
That last mile is where many deployments slow down. Someone has to turn product documentation into a coherent programme: an admin sequence, device-specific employee guides, support scripts, recovery steps, staged communications, and a safe Conditional Access plan. Creating those materials from a blank page, keeping their terminology consistent, and checking every device journey is real project work.
How the SetupPasskeys kit shortens that work
SetupPasskeys packages the rollout layer into two complete administrator playbooks, eight branded device-specific employee guides and fourteen ready-to-personalise email drafts, plus quick-start, licence and integrity files. The package covers passkey policy, Conditional Access enforcement, representative testing, device-specific registration and sign-in, hardware security keys, cross-device use, recovery, monitoring and help-desk support.
You enter a company domain to see the material in your organisation’s branding before purchase. The goal is not to replace Microsoft Entra or make configuration decisions for you. It is to give your identity team a detailed, branded starting programme so it can spend time validating its environment instead of writing and screenshotting every user journey from scratch.
See the programme with your branding first.
Build a free preview, inspect the employee and administrator material, then buy the complete package for €299 as a one-time purchase only if it fits.
Build my branded demo →Frequently asked questions
Does every Entra tenant have to stop using SMS on 1 February 2027?
The published change retires Microsoft-provided SMS and voice delivery in public-cloud Entra tenants. Microsoft documents customer-managed telecom as an alternative. Confirm tenant scope and configuration rather than treating the announcement as a universal ban on every SMS implementation.
Will Microsoft automatically complete our passkey rollout?
No. The product can enable and prompt for registration, but your organisation still owns cohort design, device support, employee preparation, help-desk readiness, recovery, enforcement, exceptions, and measurement.
Can we opt out?
Microsoft documents a temporary opt-out during the transition beginning in September. That can provide planning time, but it should not become the plan: from February, affected users who still depend on Microsoft-provided SMS or voice encounter blocking passkey registration before continuing.
Does passkey registration make the whole organisation phishing-resistant?
It is a major authentication control, not a blanket security guarantee. The outcome also depends on which sign-in methods remain available, Conditional Access policy, account and device security, recovery paths, exceptions, and user adoption.
Official sources
- Microsoft Security Blog — “Passkeys are the default authentication method in Entra ID”
- Microsoft Learn — SMS and voice authentication retirement
- Microsoft Learn — plan a phishing-resistant passwordless authentication deployment
SetupPasskeys is an independent product and is not affiliated with or endorsed by Microsoft. Product names are used for identification. This guide was reviewed against the linked Microsoft material on 27 July 2026; always confirm current Microsoft documentation before changing production policy.