Passkeys Become the Default in Entra from September: Preparing Your Users
For years, Microsoft has been encouraging businesses to move away from passwords.
In September 2026, that transition takes another significant step.
From 1 September 2026, Microsoft Entra ID will make passkeys the default authentication experience. Users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys and brought into Microsoft's passkey registration campaign.
This does not mean every Microsoft 365 user wakes up on 1 September unable to use their existing sign-in method.
But it does mean organisations still relying heavily on text messages and telephone calls for MFA need to start preparing now.
And there is an even more important deadline behind it:
Microsoft-provided SMS and voice authentication will be retired on 1 February 2027.
For businesses managing Microsoft 365 and Entra ID, passkeys are moving from something worth investigating to something that should now be part of the authentication strategy.
First: What Exactly Is Changing on 1 September?
There is an important distinction here because Microsoft's announcement can easily be misunderstood.
From 1 September 2026, users who are enabled for SMS or voice authentication through the Entra Authentication Methods Policy or relevant legacy MFA settings will be automatically enabled for passkeys.
Microsoft will also move the Registration Campaign into a Microsoft-managed state for those users.
After they sign in and successfully complete MFA, they may then be prompted to register a passkey.
Microsoft says users will initially have unlimited opportunities to snooze that registration prompt.
So September isn't an immediate:
“Create a passkey now or you're locked out.”
But the direction is very clear.
Microsoft wants businesses to move away from authentication methods that can be phished or intercepted and towards credentials that are resistant to phishing.
Then Comes 1 February 2027
This is the date businesses should really have circled.
Beginning 1 February 2027, Microsoft will retire its own SMS and voice delivery for authentication in Microsoft Entra ID.
If a user's only available MFA method is Microsoft's SMS or voice service, they will be required to register a passkey before they can continue signing in.
At that stage, the prompt becomes blocking.
Microsoft is explicit that there will be no opt-out from that February enforcement.
Businesses therefore have several months between September and February to get people migrated properly.
That is enough time.
Provided somebody actually starts the project.
Why Is Microsoft Doing This?
Because SMS and voice aren't particularly strong authentication methods anymore.
Passwords can be phished.
SMS codes can be socially engineered.
SIM-swap attacks can redirect telephone numbers.
Attackers can create convincing fake Microsoft login pages that capture passwords and one-time codes in real time.
Passkeys work differently.
They use public-key cryptography and are linked to the legitimate service rather than asking the employee to manually type a secret into whatever page happens to be in front of them.
Microsoft describes passkeys as phishing-resistant authentication and says the shift is intended to move organisations away from vulnerable methods such as SMS and voice.
For a Microsoft 365 environment, that's a significant security improvement.
What Is a Passkey?
A passkey effectively replaces a traditional password with a cryptographic credential.
The private portion stays with the user's device or approved credential provider.
The service holds the corresponding public key.
When the user authenticates, the two work together to prove the user possesses the correct credential.
Crucially, there isn't a reusable password for an attacker to steal through a fake login page.
Microsoft Entra supports both synced passkeys and device-bound passkeys.
Synced Passkeys
These can be stored within supported credential managers and synchronised between a user's devices.
Examples include platform credential ecosystems such as iCloud Keychain or Google Password Manager where supported.
This can make them convenient for employees who use multiple devices.
Device-Bound Passkeys
These remain associated with a particular device or hardware credential.
Microsoft's examples include passkeys in Microsoft Authenticator, Entra passkeys on Windows and FIDO2 hardware security keys.
For organisations, the right model may depend on the user, device-management strategy and level of assurance required.
Isn't Windows Hello Already Passwordless?
For many Windows-based businesses, some users may already be much further down this road than they realise.
Windows Hello for Business provides phishing-resistant authentication and Microsoft confirms that users already signing in using passkeys, Windows Hello for Business or another phishing-resistant method can continue doing so.
That means a well-managed organisation may discover that many employees already have an appropriate authentication method available.
The problem is usually the users who remain dependent on:
Password + SMS code
or:
Password + telephone call
Those are the people to identify first.
Your First Job: Find Out Who Still Uses SMS or Voice
Don't begin by emailing the entire company saying:
“Microsoft is removing MFA.”
It isn't.
That will simply create unnecessary panic.
Instead, establish the actual position inside your Entra tenant.
Microsoft recommends identifying users who remain enabled for SMS or voice before planning the migration and provides guidance for retrieving that information using Microsoft Graph/PowerShell and the authentication-method reporting tools.
You want to know:
How many users are affected?
Are any administrators still using SMS?
Do executives rely on telephone authentication?
Are there shared or unusual accounts?
Do some employees lack suitable smartphones or managed devices?
Are there users with accessibility requirements?
Do you have contractors or temporary employees who need a different approach?
Once you know the population, you can plan rather than guess.
Don't Forget Administrator Accounts
If you're going to prioritise anybody, prioritise privileged accounts.
A Global Administrator protected with a password and SMS code represents far greater risk than an ordinary account with limited access.
Administrative accounts should be using strong, phishing-resistant authentication wherever possible.
This is also a good opportunity to ask whether employees genuinely need the administrator roles they currently possess.
Improving authentication while leaving twenty unnecessary Global Administrators in the tenant would be rather like fitting a stronger front door while leaving every window open.
Run a Pilot Before Everybody Gets the Prompt
One of the easiest ways to turn a good security improvement into a support nightmare is to roll it out to everybody without testing it.
Choose a representative pilot group.
Not just IT employees.
Include people using:
Windows laptops.
Macs.
iPhones.
Android devices.
Different job roles.
Remote-working setups.
Perhaps a couple of people who wouldn't describe themselves as technically confident.
Let them register and use passkeys.
Find out what questions appear.
Document the process.
Identify edge cases.
Then broaden the rollout.
Microsoft allows organisations to proactively run a passkey registration campaign before the September automatic enablement, which can be a useful way of controlling the transition rather than waiting for users to encounter Microsoft's prompts unexpectedly.
Communication Will Matter Almost as Much as Configuration
From the user's perspective, this may look suspicious.
They sign into Microsoft 365.
Microsoft suddenly asks them to create a new sign-in method.
What has every security-awareness course taught them?
Be suspicious when login pages unexpectedly ask you to change authentication information.
So tell them in advance.
Explain:
What is changing.
When it is changing.
Why Microsoft is doing it.
What the genuine registration screen should look like.
Which devices they can use.
Where they should go if they need help.
And, importantly:
Never register a passkey after following a suspicious email link asking them to “upgrade their MFA”.
Cyber criminals will almost certainly use this transition as phishing bait.
Expect emails with subjects such as:
URGENT: Microsoft Passkey Upgrade Required
or:
Your MFA Expires September 1
The real security change can itself become an opportunity for attackers if users haven't been properly prepared.
The Buff IT Guy's Authentication Workout
The Buff IT Guy likes passkeys.
Not because they're fashionable.
Because they're stronger where it matters.
A six-character SMS code may look like another security layer, but if an attacker can persuade the user to type it into a fraudulent website, that extra layer isn't lifting much weight.
Passkeys remove much of that attack opportunity.
The Buff IT Guy's approach would be:
Find the weak authentication.
Replace it with phishing-resistant authentication.
Protect administrators first.
Train the users.
Then remove the old method.
No need to make authentication complicated for the sake of it.
Good security should make attacks harder without making an ordinary Monday morning impossible for employees.
What Happens if You Aren't Ready by September?
Microsoft provides a temporary opt-out from the automatic September passkey enablement and Registration Campaign changes.
Organisations can configure the relevant authentication-method policy through Microsoft Graph during the transitional period.
However, this should be treated as a migration tool rather than an excuse to ignore the change.
The temporary opt-out only helps with the period between September 2026 and February 2027.
There is no equivalent opt-out from the February 2027 retirement of Microsoft's SMS and voice service.
So postponing the project simply compresses the migration into a smaller window later.
What if Your Business Genuinely Needs SMS or Voice?
Microsoft recognises that there may still be operational or regulatory scenarios where organisations need a telecommunications-based authentication channel.
Rather than Microsoft delivering SMS and voice itself, organisations will be able to select customer-managed telecommunications providers through the Microsoft Security Store.
Microsoft says provider information becomes available from 18 September 2026, with configuration available from 30 October 2026.
But Microsoft's recommendation is clear:
Use phishing-resistant methods wherever possible and reserve telecom-based authentication for situations where there is a genuine requirement.
For most ordinary Microsoft 365 users, passkeys, Windows Hello for Business or another appropriate phishing-resistant method should be the destination.
What About Self-Service Password Reset?
This change affects more than just MFA.
Microsoft says the retirement of its native SMS and voice delivery also applies to Self-Service Password Reset (SSPR).
That means businesses need to consider users who currently depend on telephone methods for account recovery as well as normal sign-in.
Microsoft is developing additional capabilities around passwordless users and password changes, but the important point today is simple:
Don't audit MFA in isolation.
Audit the user's whole authentication and recovery journey.
What About Guest Users?
Another area to watch is business-to-business collaboration.
Microsoft currently says passkey support for B2B users and internal guest users is planned by the end of calendar year 2026.
If your organisation has a large guest population, external consultants or partner organisations accessing resources through Entra, factor that into your planning.
The September/February transition applies to public-cloud environments first; Microsoft says other cloud environments will follow on a different schedule.
A Practical Preparation Plan
For an SME, this does not need to become a giant identity project.
A sensible rollout looks like this:
August 2026: identify SMS and voice users, review privileged accounts and decide your target passkey strategy.
Early pilot: enable passkeys for a controlled group and document the user experience.
Before 1 September: brief staff so Microsoft's registration prompts don't come as a surprise.
September–October: broaden registration and track remaining SMS/voice users.
Before the end of 2026: address exceptions, contractors and users requiring alternative arrangements.
January 2027: verify that nobody's only remaining authentication route depends on Microsoft-provided SMS or voice.
Before 1 February 2027: complete the migration.
Waiting until late January and sending everybody an email entitled:
“URGENT — YOU NEED TO CHANGE HOW YOU LOG IN BY FRIDAY”
is technically a migration strategy.
It's just not a very good one.
How Hamilton Group Can Help
Microsoft identity security is one of those areas where a relatively small configuration mistake can affect every employee.
Hamilton Group can help businesses prepare for Microsoft's Entra passkey changes without turning the rollout into a helpdesk disaster.
We can help with:
- Reviewing current Entra authentication methods
- Identifying users dependent on SMS and voice
- Enabling and configuring passkeys
- Reviewing Windows Hello for Business
- Designing pilot groups
- Microsoft Entra ID security
- Multi-factor authentication
- Conditional Access
- Administrator-account protection
- User communications and rollout planning
- Microsoft 365 security reviews
- Employee onboarding and offboarding
- Troubleshooting registration and sign-in issues
- Wider Microsoft 365 management
More importantly, we can look at the whole identity environment rather than simply switching on another authentication method.
Passkeys are an opportunity to review whether your Microsoft 365 security has evolved alongside the business.
Who has administrator access?
Are old accounts still present?
Is Conditional Access sensible?
Are devices properly managed?
Are leavers removed promptly?
Do users have suitable recovery methods?
The September change is a useful deadline for answering those questions.
Don't Wait for Your Users to Discover This Themselves
The best passkey rollout is probably one employees barely remember.
They receive clear communication.
Registration works.
Support is available.
Their sign-in becomes more resistant to phishing.
And the organisation moves away from weaker SMS and voice authentication without widespread disruption.
That's considerably better than waiting until Microsoft's February enforcement starts blocking users whose only MFA method is a telephone number.
The Buff IT Guy would call this progressive overload.
Strengthen authentication before the old method gets taken away.
We'd simply call it good Microsoft 365 management.
Hamilton Group can help your organisation assess its current Entra authentication methods and prepare users for the September 2026 passkey rollout.
Call Hamilton Group on 0330 043 0069
Email: hello@hgmssp.com
Visit: hgmssp.com