Microsoft is turning passkeys from an option into the sign-in path Entra ID expects by default. That means the old assumption that SMS or voice MFA can stay in place unchanged is gone, and the login flow itself becomes the enforcement point for the migration.
The rollout starts September 1, 2026, when SMS- or voice-enabled users are auto-enabled for passkeys and prompted to register one at their next MFA sign-in. On February 1, 2027, users who still rely on SMS or voice must have a passkey before they can sign in, and Microsoft will stop providing native SMS and voice delivery as an Entra capability. Organizations that still need those factors will have to contract with third-party telecom providers through Microsoft Security Store and pay the related charges themselves.
This shifts MFA from a Microsoft-managed service to a customer-owned telecom and compliance problem. Teams that still depend on SMS or voice will be managing enrollment, provider selection, billing, and regulatory coverage, not just an identity setting.