Identity · 62 days ago
Microsoft is turning passkeys from an option into the sign-in path Entra ID expects by default. That means the old assumption that SMS or voice MFA can stay in place unchanged is gone, and the login flow itself becomes the enforcement point for the migration.
The rollout starts September 1, 2026, when SMS- or voice-enabled users are auto-enabled for passkeys and prompted to register one at their next MFA sign-in. On February 1, 2027, users who still rely on SMS or voice must have a passkey before they can sign in, and Microsoft will stop providing native SMS and voice delivery as an Entra capability. Organizations that still need those factors will have to contract with third-party telecom providers through Microsoft Security Store and pay the related charges themselves.
This shifts MFA from a Microsoft-managed service to a customer-owned telecom and compliance problem. Teams that still depend on SMS or voice will be managing enrollment, provider selection, billing, and regulatory coverage, not just an identity setting.
3 sources covering this story
Microsoft is forcing an enterprise transition to passkeys
Beginning in September, Microsoft Entra ID will replace SMS and voice authentication with passkeys, signaling that traditional credentials are too risky to remain the standard amidst AI-powered attacks.
Microsoft Entra ID gets passkeys default authentication starting September
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026.
Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security
Microsoft will make passkeys the default authentication experience in Entra ID and phase out native SMS and voice authentication.
Part of the PlainSec briefing for 2026-07-15