What happened
Microsoft announced on 13 July 2026 that passkeys are becoming the default authentication method in Entra ID, and the rollout has now begun. From 1 September 2026, users enabled for SMS or voice-based MFA are automatically enabled for passkeys and prompted to register one at their next sign-in.
The endgame is fixed: on 1 February 2027, Microsoft-provided SMS and voice authentication retires entirely. After that date, users whose only MFA method is SMS or voice will be required to register a passkey before they can sign in — and Microsoft has stated plainly that there is no opt-out. Organisations that genuinely need SMS will have to contract (and pay for) a third-party telecom provider through the Microsoft Security Store.
Why it matters to your business
SMS one-time codes have quietly become one of the weakest links in business security — they're interceptable, phishable and vulnerable to SIM-swap fraud, which South Africans know well. Microsoft's move is the strongest mainstream endorsement yet of phishing-resistant authentication: passkeys use cryptographic keys tied to a device, so there's no code to steal or intercept.
If your business runs on Microsoft 365, this change is coming to your tenant whether you plan for it or not. Users who ignore the prompt will face a hard registration wall in February 2027 — potentially locked out at the worst possible moment.
What you should do
Audit your MFA methods now. Identify every user still relying on SMS or voice for MFA.
Move users early. Enable passkeys (or Microsoft Authenticator / FIDO2 keys) before the February deadline forces the issue.
Communicate the change. Staff should expect the passkey registration prompt and know it's legitimate — surprise prompts are a phishing risk in themselves.
Ask your IT partner to run the rollout. Managed clients can have this handled across every device as part of their bundle — no helpdesk chaos required.
Source: Microsoft Security Blog