News thumbnail
Technology / Mon, 05 Oct 2026 LinkedIn

Microsoft Urges Entra ID Administrators To Accelerate Passkey Migration

When they next sign in and complete multifactor authentication, Entra ID can prompt them to create a passkey. They must still complete passkey registration, and Microsoft currently allows them to postpone the registration prompt. According to Microsoft’s updated migration and retirement guidance, Microsoft-provided SMS and voice authentication will be retired for most Entra ID users on February 1, 2027. Microsoft Entra External ID is also not covered by this particular rollout and is expected to receive a separate announcement. Integrate in your team 👇🏻SMS is not disappearing from Entra ID entirelyThe announcement does not mean that Entra ID will become technically incapable of supporting SMS or voice authentication.

Microsoft is urging organizations using Entra ID to move employees away from SMS and voice-based authentication and register them for passkeys before the company withdraws its native telecommunications-based verification services in 2027.

The transition has already entered its first phase. Since September 1, 2026, Microsoft has automatically enabled passkeys for Entra ID users who are configured to use SMS or voice authentication under either the Authentication Methods Policy or legacy multifactor authentication settings.

Those users are now included in a Microsoft-managed registration campaign. When they next sign in and complete multifactor authentication, Entra ID can prompt them to create a passkey.

However, automatic enablement does not mean that users have already been fully migrated. They must still complete passkey registration, and Microsoft currently allows them to postpone the registration prompt. Unless administrators actively monitor adoption and follow up with users who continue to defer enrollment, organizations could reach the enforcement deadline with substantial numbers of accounts still dependent on SMS or telephone calls.

Microsoft’s warning is therefore less about enabling a technical setting and more about completing what could become a large identity-management project across enterprise environments.

According to Microsoft’s updated migration and retirement guidance, Microsoft-provided SMS and voice authentication will be retired for most Entra ID users on February 1, 2027. Global Administrators and external users have a later deadline of July 1, 2027, while internal guest users remain subject to the February cutoff.

After the applicable deadline, affected users whose only available MFA method is SMS or voice will encounter a mandatory passkey registration prompt during sign-in. They must complete that process before they can continue accessing their account.

Microsoft says there will be no opt-out from this enforcement.

Passkeys are enabled, but users still need to register

The September 1 change automatically adjusted Entra ID policy settings for users enabled for SMS or voice. Those accounts were placed in a passkey profile supporting the available passkey types, while Microsoft-managed registration campaigns began encouraging enrollment.

By default, however, users can repeatedly snooze that prompt. Consequently, an organization may appear ready at the policy level while still having a significant population that has never created a working passkey.

Administrators will need to distinguish between users who are eligible to register, users who have completed registration and users who still rely on a telecommunications channel for authentication or account recovery.

Microsoft recommends identifying every account enabled for SMS or voice before moving further into the rollout. The company provides a PowerShell-based discovery process for this purpose, which requires an appropriate role such as Global Reader, Authentication Policy Administrator or Security Reader.

Any organization that identifies active SMS or voice users should regard itself as being within the scope of the change. Administrators must also examine legacy MFA configurations, because the migration is not limited to tenants that have fully adopted the newer Authentication Methods Policy.

This inventory stage is particularly important in large environments where authentication configurations may differ between employees, contractors, administrators, service desks, subsidiaries and recently acquired businesses.

Dormant accounts, break-glass access arrangements and users who rarely authenticate interactively could be overlooked by a campaign based mainly on sign-in prompts. Organizations should therefore verify registration status rather than assuming that every user has seen or acted on the notification.

Microsoft will end native SMS and voice delivery in two stages

Microsoft’s retirement schedule separates most users from two categories receiving additional time.

For ordinary workforce users and internal guests, Microsoft-provided SMS and voice delivery will end on February 1, 2027. If an affected user has no alternative method and the organization has not configured a customer-managed telecommunications provider, the user will be required to register a passkey before proceeding with sign-in.

Global Administrators and external users receive an extension until July 1, 2027. The additional time is especially significant for external identities because support for passkeys among business-to-business and internal guest scenarios is still being expanded. Microsoft says passkey support for B2B users and internal guests is planned by the end of 2026.

Internal guest accounts should not be confused with external users for deadline purposes. Microsoft’s retirement FAQ confirms that internal guests remain part of the February 1 retirement group.

The timetable currently applies to Microsoft’s public cloud environments. Sovereign and other cloud environments are expected to move on a different schedule, with Microsoft promising advance notice.

Azure AD B2C is outside the scope of the present change. Microsoft Entra External ID is also not covered by this particular rollout and is expected to receive a separate announcement.

Achieve 3x faster SOC performance with threat intelligence from 16K organizations. Integrate in your team 👇🏻

SMS is not disappearing from Entra ID entirely

The announcement does not mean that Entra ID will become technically incapable of supporting SMS or voice authentication.

Instead, Microsoft is ending the telecommunications delivery service it currently provides natively. Organizations with a legitimate operational, regulatory or technical requirement can continue using those channels by contracting with a supported customer-managed telecom provider through the Microsoft Security Store.

Microsoft began publishing information about participating providers on September 18, 2026, and says customers will be able to select and configure providers beginning October 30.

This option will introduce a different commercial and operational model. Pricing is expected to vary according to the provider, region and message volume, with organizations paying for delivery rather than relying on Microsoft’s existing native service.

Enterprises considering this route will need to assess regional coverage, availability, contractual responsibilities, data handling, regulatory requirements and resilience. They must also ensure that every user who needs to retain SMS or voice is migrated to the new provider before the relevant cutoff date.

Microsoft is positioning customer-managed telecom as an exception for defined use cases, not as the recommended default for an entire workforce. Its preferred outcome is for organizations to move users to phishing-resistant credentials wherever possible.

The retirement also affects SMS and voice usage in Entra self-service password reset. This means administrators must examine recovery and password-reset workflows as well as interactive MFA policies. A tenant could successfully migrate routine sign-ins while retaining an unnoticed dependency on SMS for account recovery.

Why Microsoft is moving away from telephone-based authentication

SMS and voice calls improved security when deployed as a second factor alongside passwords, particularly compared with password-only authentication. Nevertheless, both depend on the telephone network and on secrets that users can read, disclose or enter into another device.

Attackers can obtain one-time codes through phishing pages, adversary-in-the-middle services, social engineering, SIM-swap fraud, number-porting attacks, compromised mobile accounts and abuse of telecom infrastructure. A code may expire quickly, but it remains transferable while valid.

Passkeys operate differently. They use asymmetric public-key cryptography rather than a password or one-time secret shared with a website.

During registration, the authenticator creates a cryptographic key pair. The service stores the public key, while the private key remains under the control of the user’s device, authenticator or credential manager. When the user signs in, the authenticator uses the private key to prove possession without transmitting that private key to Microsoft.

The credential is also associated with the legitimate service. That origin binding is what makes standards-based passkeys resistant to conventional credential-phishing attacks: a passkey created for Microsoft’s real sign-in domain should not authenticate a lookalike phishing site.

Passkeys also reduce exposure to replay attacks because there is no reusable password or manually entered one-time code for an attacker to capture and submit elsewhere.

This does not make every account using a passkey invulnerable. Attackers may still target active sessions, compromised endpoints, malicious applications, OAuth consent processes, account recovery channels or weaker fallback authentication methods. The protection offered by a strong credential can be undermined if users are permitted to fall back to a phishable alternative.

Administrators should therefore treat passkey deployment as part of a wider identity-security architecture rather than as a simple replacement for an MFA checkbox.

Synced and device-bound passkeys

Microsoft Entra ID supports both synced and device-bound passkeys.

Synced passkeys are stored in a platform credential manager, such as Apple’s iCloud Keychain or Google Password Manager, and can be made available across a user’s authorized devices. This can improve usability and recovery, particularly for employees already operating within a supported device ecosystem.

Device-bound passkeys remain associated with a particular device or authenticator. Microsoft identifies Windows-based Entra passkeys, passkeys in Microsoft Authenticator and FIDO2 hardware security keys among the possible device-bound options.

The correct choice will vary by risk profile. Synced credentials can simplify adoption for general workforce populations, while organizations may prefer device-bound authenticators or hardware security keys for highly privileged personnel, regulated environments and accounts requiring tighter control over credential portability.

Enterprises should test their chosen approach across every supported combination of operating system, browser, mobile platform and device-management state. Shared workstations, virtual desktops, frontline devices, accessibility needs and users without corporate smartphones may require different enrollment or authentication options.

Administrators can temporarily delay automatic migration

Microsoft allows tenants to opt out temporarily from the automatic passkey enablement and registration campaign introduced in September.

The opt-out is designed to give organizations time to complete another migration path, configure a customer-managed telecommunications provider or prepare their environment. It requires the Policy.ReadWrite.AuthenticationMethod permission and a Microsoft Graph update to the tenant’s authentication methods policy.

The temporary setting does not cancel the retirement. For most users, it stops providing relief on February 1, 2027; Global Administrators and external users follow their July 1 deadline. Once enforcement applies, an organization cannot use the temporary opt-out to preserve Microsoft-provided SMS or voice authentication.

Tenants should therefore avoid treating the option as a permanent exemption. At most, it provides additional preparation time.

A migration must cover more than credential registration

A controlled rollout should begin with a representative pilot group rather than the entire workforce. Administrators need to verify enrollment, normal sign-in, device replacement, recovery, help-desk procedures and emergency access before expanding deployment.

Microsoft recommends enabling Passkey (FIDO2) in the Authentication Methods Policy and placing the relevant SMS and voice users within a passkey-enabled scope before starting a registration campaign.

Organizations should then communicate the change in phases: first explaining why SMS and voice are being retired, then providing device-specific registration instructions, and finally contacting users who have not completed enrollment.

Clear communication also has a security function. A large authentication migration can create fertile ground for phishing. Attackers may imitate Microsoft notifications, help-desk messages or passkey-registration instructions in an attempt to steal passwords, one-time codes or session tokens.

Official notices should tell employees exactly where registration begins, what information support personnel will never request and how users can report suspicious prompts. Help-desk teams should be trained to verify identities securely and should never solve enrollment problems by reverting users to an unnecessarily weak method.

Administrators should also establish a reliable recovery route before enforcing passkeys. A user who loses a device must be able to regain access without allowing an attacker to exploit an easily manipulated reset process. Microsoft Temporary Access Passes, securely issued replacement credentials and documented high-assurance recovery procedures may form part of that design, depending on the organization’s licensing and policies.

Privileged accounts require particular attention. Although Global Administrators have until July 2027 under Microsoft’s schedule, delaying their migration would leave some of the tenant’s most powerful identities using weaker authentication for longer. Organizations may reasonably choose to migrate those accounts first, while preserving separately controlled emergency-access accounts.

Conditional Access policies should also be reviewed so that sensitive applications and administrative operations require an appropriate authentication strength. If weaker fallback methods remain broadly available, attackers may attempt to steer users toward those alternatives instead of confronting the passkey directly.

The operational deadline is earlier than February

February 1, 2027 is the enforcement date for most users, but it should not be treated as the practical completion date.

Enterprises need time to identify dependencies, test authenticator combinations, support users who cannot follow the standard path, update onboarding and offboarding workflows and measure actual registration levels. They must also account for year-end change freezes, employee holidays and reduced staffing during December and January.

Organizations choosing customer-managed SMS or voice face additional procurement, legal, privacy and integration work. Waiting until the final weeks could leave insufficient time to establish a provider, test delivery in every operating region and migrate affected accounts.

Microsoft’s transition represents a broader change in the meaning of strong authentication. Traditional MFA proves that a user can supply more than one credential, but it does not necessarily prevent those credentials from being phished. The emerging standard is phishing-resistant authentication in which the credential cannot be readily entered into, or replayed through, an attacker-controlled service.

For Entra ID customers, the immediate priority is to determine who is still dependent on SMS or voice and whether those users have completed passkey registration—not merely whether the tenant now permits it.

Organizations that finish that work well ahead of February will reduce both account-compromise risk and the possibility of a disruptive wave of mandatory enrollment prompts when Microsoft’s native telecom service is switched off.

© All Rights Reserved.