On September 1st, 2026, Microsoft Entra will automatically enable passkeys for every user who currently relies on SMS or voice as their multifactor authentication method. This is not a future announcement. This is not a beta. It is a confirmed date with documented behavior, already published in the Message Center (MC1426371).
And most enterprise tenants have not communicated anything to their users yet.
When a user completes MFA on that day or after, they will see a prompt asking them to register a passkey. Without any prior context, that prompt looks like a phishing attack. And the helpdesk is going to get tickets.
You have 20 days to prevent that scenario.
The window that's going to confuse half your company
A passkey is not a password. It is a confirmation that comes from your own device.
When the system asks for it, a window appears asking whether you want to link your phone or computer as a verification method. You accept, your device asks for the fingerprint, face recognition, or PIN you already use to unlock it, and that's it. The next time you sign in, instead of waiting for an SMS code, the system simply asks "is it you?" and your device responds.
No code. No waiting for a message. No risk of someone intercepting that SMS along the way.
SMS worked for years because everyone has a phone. The problem is that a text code can be intercepted, forwarded, or copied into a fake site in seconds. Passkeys don't travel anywhere: the verification happens on your device and only there.
What happens exactly on September 1st
Microsoft activates two things simultaneously. First, it enables passkeys as an available method for all users who still depend on SMS or voice. Second, it sets the Registration Campaign to "Microsoft Managed" mode, meaning the system will start showing the passkey registration prompt every time those users complete a multifactor authentication.
Users can skip it. For now. That changes on February 1st, 2027, when SMS and voice are permanently retired from Microsoft's infrastructure and the prompt becomes blocking: no skip button, no opt-out, for all tenants without exception.
The window between September and February exists precisely so organizations can migrate in order, not in panic.
Who is in scope (and what people forget to check)
The change applies to any user with SMS or voice enabled in their Entra profile, even if they have other methods registered. The system may still show them the passkey prompt.
The cases that usually get overlooked: Self-Service Password Reset (SSPR) also uses SMS and voice, and has its own configuration independent of the login flow. Guest and B2B users are also in scope, although Microsoft plans to extend full passkey support for external users by the end of 2026.
To understand the real size of the problem in your tenant: Protection > Authentication Methods > Activity in the Entra portal. The "active SMS or Voice users" report shows exactly who has that method active and who has it as their only registered method. Those last users are the ones who will be locked out in February if nothing is done.
The email you need to send this week
This is the text you can adapt and send to your users before September 1st. The goal is simple: when they see the prompt, they recognize it and complete it instead of closing it or calling the helpdesk.
Subject: Change in identity verification starting September 1st
Hi,
Starting September 1st, when you sign in with two-step verification, you may see a new screen asking you to link your phone or computer as a verification method. This change comes from Microsoft and applies to the entire organization.
When that screen appears, your device will ask for the fingerprint, face recognition, or PIN you already use to unlock it. There is nothing to install and no code to wait for by SMS.
When it appears:
- Click "Continue" or "Set up now".
- Follow the on-screen instructions.
- The process takes less than two minutes.
For now you can skip this step if you are not ready, but we recommend completing it when it appears. It will become mandatory soon.
If you have questions or the process does not work on your device, write to [internal support] or open a ticket in [ticketing system].
Thank you,
[IT team name]
Adapt the support channel names and tone to your organization's style. If you have an intranet or Teams channel for IT communications, this message works equally well in those formats.
If you still need SMS or voice
Some organizations have legitimate reasons to keep phone-based authentication: regulatory requirements, users without passkey-compatible devices, specific accessibility flows. For those cases, Microsoft will make approved external telecom providers available in the Microsoft Security Store starting October 30th, 2026.
That option is paid (per-message billing, variable by provider and region) and requires configuration before the retirement date. It is not a last-minute alternative.
The point
September 1st is not the end of the world. It is a registration campaign with a prompt that users can ignore. The problem is when nobody told them it was going to appear.
An email this week turns a helpdesk ticket into a change the user completes on their own in two minutes. That is the difference between managing the change and putting out the fire.
Sources
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication — Microsoft Learn
- MC1426371 — Microsoft Entra: Passkeys by default and retirement of SMS/voice — Microsoft Message Center
- Microsoft Entra ID security updates: Passkeys are the default — Microsoft Security Blog
