Microsoft Entra ID Passkeys = the new default for your business

Cyber security threats continue to evolve, and attackers are becoming increasingly sophisticated in how they target user credentials. In response, Microsoft has announced a significant change to its identity security strategy, making passkeys the default authentication method for Microsoft Entra ID from September 2026 and retiring Microsoft-provided SMS and voice authentication in February 2027.

For organisations relying on Microsoft 365 and Entra ID, now is the time to understand what these changes mean and begin planning for the transition.

What is changing?

Microsoft has confirmed that from 1 September 2026, passkeys will become the default authentication experience in Microsoft Entra ID. Users currently relying on SMS or voice-based authentication will automatically be enabled for passkeys and prompted to register them during future sign-in attempts.

The next major milestone is 1 February 2027, when Microsoft-provided SMS and voice authentication services will be retired from Entra ID. Organisations that continue to require these methods will need to use approved third-party telecom providers through the Microsoft Security Store.

Users who already authenticate using phishing-resistant methods such as:

  • Passkeys
  • Windows Hello for Business
  • FIDO2 security keys
  • Smart cards
  • Other supported passwordless authentication methods

will be able to continue using these methods without disruption.

Why is Microsoft making this change?

Traditional authentication methods such as passwords, SMS codes and voice verification have become increasingly vulnerable to modern cyber attacks. Techniques such as phishing, SIM swapping, credential theft and social engineering continue to bypass traditional security controls.

Passkeys use public key cryptography rather than shared secrets and one-time codes. This means there is no password or verification code for attackers to steal, making passkeys significantly more resistant to phishing attacks.

Microsoft has stated that stronger, phishing-resistant authentication is essential to support the growing use of AI technologies and cloud services across enterprise environments.

What are passkeys?

A passkey is a passwordless sign-in method that allows users to authenticate using:

  • Fingerprint recognition
  • Facial recognition
  • Device PIN
  • Hardware security keys

Instead of entering a password and receiving a text message code, users verify their identity directly through a trusted device. This creates a faster, simpler and more secure sign-in experience.

For businesses, passkeys offer several benefits:

  • Reduced risk of phishing attacks
  • Improved user experience
  • Fewer password reset requests
  • Stronger compliance and security posture
  • Lower risk of account compromise

What should organisations do now?

Although the changes do not fully take effect until 2027, Microsoft is encouraging organisations to begin preparing immediately.

Key steps include:

Review current authentication methods

Identify users who still rely on SMS or voice authentication and understand how widely these methods are used across your environment.

Enable passkeys and phishing-resistant authentication

Consider rolling out passkeys, Windows Hello for Business and FIDO2 security keys to users in advance of Microsoft’s automated transition.

Update user awareness training

Many users are unfamiliar with passkeys and passwordless authentication. User education will play a key role in ensuring a smooth adoption process.

Review security policies

Authentication should form part of a wider identity and access management strategy, including Conditional Access policies, Multi-Factor Authentication and Zero Trust security principles.

As a Microsoft Solutions Partner, CSG helps organisations across the UK and Wales design, implement and manage secure Microsoft environments. Our team works with businesses to strengthen identity security, improve cyber resilience and ensure they are prepared for Microsoft’s latest platform changes.

Whether you’re looking to:

  • Assess your current Microsoft 365 security posture
  • Deploy passkeys and passwordless authentication
  • Implement Microsoft Entra ID best practices
  • Review Conditional Access policies
  • Strengthen your Zero Trust strategy
  • Prepare for the retirement of SMS and voice authentication

our specialists can help you plan and execute a smooth transition with minimal disruption to users.

Final thoughts

Microsoft’s move toward passkeys represents another major step in the industry’s shift away from passwords and vulnerable authentication methods. While February 2027 may seem some distance away, organisations that plan early will benefit from stronger security, better user experiences and reduced risk.

The question is no longer whether passwordless authentication will become standard. Microsoft has made it clear that the future of identity security is phishing-resistant authentication, and passkeys are leading the way.

Need help preparing for these changes? Contact CSG’s Microsoft and cyber security experts to review your Microsoft 365 environment and develop a roadmap for adopting passkeys securely and effectively.

Explore our resources to see how we’ve supported businesses across the UK with disaster recovery.

Speak to an IT Specialist

To find out more or to talk to one of our experts, contact us today.