Skip to content

Microsoft Entra passkeys become the default: what IT must do before 2027

Microsoft has announced a two-stage change to authentication in Entra ID. On 1 September 2026, users enabled for SMS or voice are automatically enabled for passkeys, placed in a profile that allows all passkey types, and brought into a Microsoft-managed registration campaign. The second stage arrives on 1 February 2027, when Microsoft-provided SMS and voice delivery ends in public-cloud tenants.

The announcement creates urgency, but it does not create an organisational rollout plan. Identity teams still have to find the affected population, decide which passkey providers to support, test the device journeys, prepare employees and support teams, manage recovery, and enforce phishing-resistant authentication safely.

The short version

September starts a transition, not a universal lockout. February is the firmer operational date for affected public-cloud users who still depend on Microsoft-provided SMS or voice. Microsoft documents customer-managed telecom as an alternative, so check your tenant and provider configuration before assuming every SMS user follows the same path.

Check your likely impact and build a rollout-readiness score →

The two Microsoft dates, precisely

Date Microsoft change What it means for IT
1 September 2026 Users enabled for SMS or voice are automatically enabled for passkeys and placed in a passkey profile allowing all passkey types. Registration Campaign moves to Microsoft Managed for those users and nudges them after MFA sign-in, with unlimited snoozes by default. Microsoft provides a temporary opt-out during the transition. Review the affected population and define the profiles, passkey types and providers you actually approve before the automatic all-types profile appears. Prepare communications, support and tested device routes before users are prompted.
1 February 2027 Microsoft-provided SMS and voice delivery retires in Entra ID public-cloud tenants. Microsoft documents customer-managed telecom as an alternative. Users who rely only on the retired Microsoft-provided methods encounter blocking passkey registration before they can continue. The transition-period opt-out no longer avoids this behaviour.

These details come from Microsoft’s Entra security announcement and the Microsoft Learn retirement guidance.

Avoid the “every tenant is blocked in September” interpretation.

The September date begins Microsoft’s default-method transition. The February date retires Microsoft-provided delivery in public-cloud tenants and introduces the blocking registration behaviour for affected users. Tenant type, existing authentication methods, and customer-managed telecom all affect the practical impact.

Do not let the automatic “all passkey types” profile become your policy by accident.

Microsoft’s current guidance says in-scope SMS and voice users will be placed in a passkey profile that allows all passkey types. Before September, decide whether each audience should use synced passkeys, device-bound passkeys, specific providers or security keys; configure and test those profiles in Entra; then give each audience only the matching employee instructions. Entra remains the enforcement point.

Who should treat this as a priority?

Start with organisations that use Microsoft Entra ID in the public cloud and still have a meaningful population registered for SMS or voice authentication. The most exposed groups are usually not identical to the easiest pilot group.

Do not infer method usage from licensing, a domain check, or the presence of Microsoft 365. Use Entra authentication-method reporting to identify the real population, then segment it by user risk, device pattern, and support needs.

Why passkeys matter beyond the deadline

A passkey is bound to the genuine service origin, so it is designed not to release a reusable secret to a lookalike phishing site. The user unlocks the credential with the device mechanism they already use, such as biometrics or a PIN. That can remove password entry and one-time-code handling from the normal sign-in journey.

The business case is therefore wider than compliance with a Microsoft change: phishing-resistant authentication, fewer password and code interactions, a faster routine sign-in, and less dependence on telecom delivery. Those benefits still depend on sound policy, supported devices, recovery controls, and user adoption. A passkey licence or enabled toggle alone does not deliver them.

A practical six-part rollout plan

  1. Measure the starting population. Export registration data, identify SMS/voice dependencies, confirm whether customer-managed telecom is in use, and segment cohorts by device and risk.
  2. Choose the supported passkey model. Define approved providers, attestation and AAGUID choices, synced versus device-bound credentials, hardware-key use cases, and Temporary Access Pass policy.
  3. Pilot every real journey. Test registration, routine sign-in, cross-device sign-in, device replacement, lost-device recovery, and support escalation on the platforms your people actually use.
  4. Prepare trust-building communications. Explain why the prompt appears, what a legitimate screen looks like, where the passkey will be stored, what IT will never ask for, and how to get verified help.
  5. Rehearse enforcement. Build a phishing-resistant Conditional Access policy in report-only mode. Validate dependencies and exclusions, and protect cloud-only emergency access accounts before widening scope.
  6. Roll out in measured cohorts. Track registration, sign-in success, support demand, recovery events, and policy results weekly. Use the evidence to decide when the next group is ready.

What Microsoft provides — and what your organisation still owns

Microsoft provides the Entra authentication capability, policy controls, reporting, and product documentation. Its automatic experience helps users register. It does not know your supported devices, approved authenticator providers, help-desk model, internal change calendar, employee language, emergency procedures, or risk appetite.

That last mile is where many deployments slow down. Someone has to turn product documentation into a coherent programme: an admin sequence, device-specific employee guides, support scripts, recovery steps, staged communications, and a safe Conditional Access plan. Creating those materials from a blank page, keeping their terminology consistent, and checking every device journey is real project work.

How a hosted SetupPasskeys guide shortens that work

SetupPasskeys gives employees one hosted route into the right passkey setup for their device and agreed audience: picture-by-picture on validated visual routes, with concise written guidance where browser UI varies. Your IT team supplies and approves the passkey profiles, providers and devices in scope; each employee route includes only those approved instructions. Your version can also carry the logo, colours and support details people already recognise.

It does not replace Microsoft Entra or make policy decisions for you. It turns your approved rollout choices into consistent, audience-specific employee journeys. The supported route library covers Apple Passwords, Google Password Manager, Microsoft Authenticator, Samsung Pass, Windows Hello and security keys, but a live guide does not expose a route merely because the library supports it. SetupPasskeys does not inspect your tenant; Microsoft Entra remains the policy enforcement point.

Frequently asked questions

Does every Entra tenant have to stop using SMS on 1 February 2027?

The published change retires Microsoft-provided SMS and voice delivery in public-cloud Entra tenants. Microsoft documents customer-managed telecom as an alternative. Confirm tenant scope and configuration rather than treating the announcement as a universal ban on every SMS implementation.

Will Microsoft automatically complete our passkey rollout?

No. The product can enable and prompt for registration, but your organisation still owns cohort design, device support, employee preparation, help-desk readiness, recovery, enforcement, exceptions, and measurement.

Can a hosted guide match our Entra passkey profiles?

Yes. Your IT team supplies and approves the relevant profiles, target audiences, providers and supported devices. We configure each agreed entry route to show only those setup instructions. The public branding preview does not read tenant policy or identify a user’s group.

Can we opt out?

Microsoft documents a temporary opt-out from automatic passkey enablement and Registration Campaign rollout by setting passkeyDynamicMigration through the Microsoft Graph beta API. That can provide planning time, but it does not opt a tenant out of the February enforcement. From 1 February 2027, affected users who still depend on Microsoft-provided SMS or voice encounter blocking passkey registration before continuing.

Does passkey registration make the whole organisation phishing-resistant?

It is a major authentication control, not a blanket security guarantee. The outcome also depends on which sign-in methods remain available, Conditional Access policy, account and device security, recovery paths, exceptions, and user adoption.

Official sources

SetupPasskeys is an independent product and is not affiliated with or endorsed by Microsoft. Product names are used for identification. This guide was reviewed against the linked Microsoft material on 16 August 2026; always confirm current Microsoft documentation before changing production policy.