Passkeys Instead of SMS: Planning Your Entra ID Migration Before 1 September 2026 – A 5-Step Guide
From 1 Sept 2026, Microsoft enables passkeys for SMS MFA users automatically. SMS shuts down on 1 Feb 2027. A 5-step migration guide for your Entra tenant.
In one week – on 1 September 2026 – Microsoft will automatically change multi-factor authentication for all Entra ID users who currently log in via SMS or voice call. From that date, those users will be prompted to register a passkey on their next login. And on 1 February 2027, Microsoft will shut down the SMS option entirely – no exceptions, no opt-out.
Organisations that are prepared will experience a smooth transition. Those that are not will confront their employees with a blocking login prompt and a flood of helpdesk tickets.
What Happens When?
Microsoft has announced two binding dates:
- 1 September 2026: Microsoft launches a Registration Campaign for all Public Cloud tenants. Users who currently have Microsoft-native SMS or voice set up as their MFA method will be invited to register a passkey on their next login. For now, they can dismiss this prompt indefinitely ("unlimited snoozes").
- 1 February 2027: SMS and voice are shut down completely. Users without an alternative MFA method will see a blocking login prompt from this date and will be unable to continue. This deadline applies to all Public Cloud tenants – no opt-out is possible.
The time between these two dates is your window. The September campaign starts automatically – that's helpful. But without preparation, communication, and a fallback plan, the February deadline will become a real problem.
If you need more time: admins can temporarily delay the September wave via the Microsoft Graph API by setting the passkeyDynamicMigration property to true. This postpones the nudge, but not the hard shutdown on 1 February 2027.
Am I Affected?
Yes, if at least one user in your tenant has Microsoft-native SMS or voice set up as an MFA method. You can find the full picture in the Entra Admin Center under Reports → Authentication Methods Activity – filter by SMS and voice.
Not affected by this timeline: Azure AD B2C (separate announcement to follow), special cloud environments (GCC, China Cloud). B2B guest users fall within scope, but Microsoft is preparing a separate solution for them before the end of 2026. Self-Service Password Reset (SSPR) configured with SMS is also affected and must be included in your planning.
What Are Passkeys, Exactly?
A passkey replaces both a password and an SMS code with a cryptographic confirmation on the user's own device – verified via biometrics (Face ID, fingerprint) or device PIN. Entra ID supports two types:
- Synced Passkeys (e.g., iCloud Keychain, Google Password Manager): Synchronised across devices; no loss of access when switching devices.
- Device-bound Passkeys (Microsoft Authenticator, FIDO2 hardware security keys): Valid on a single device only; highest security level.
Passkeys are available at no additional cost in all Entra ID editions, including the free tier. To enforce passkey use via Conditional Access (phishing-resistant MFA required), you need Entra ID P1 – already included in Microsoft 365 Business Premium, M365 E3, and E5.
Compatibility requirements at a glance:
| Platform | Web sign-in | Microsoft Authenticator / native apps |
|---|---|---|
| Windows | Windows 10 | Windows 11 22H2 |
| iOS / iPadOS | iOS 14.3 | iOS 17 |
| Android | Chrome/Edge from Android 9 | Android 14 |
| macOS | macOS 11 (Big Sur) | macOS 14 (Sonoma) |
Browsers: Chrome, Edge, Firefox, and Safari are supported. Firefox on Android is currently not supported.
The 5-Step Plan for Your Entra Tenant
Whether you manage a tenant for a small office in Recklinghausen or a mid-sized company in the Ruhr region, the approach is the same everywhere:
Step 1: Inventory – who is still using SMS or voice? Download the Authentication Methods Activity report in the Entra Admin Center and filter by SMS and voice. This gives you an exact picture of how many users are affected and lets you estimate the effort involved.
Step 2: Pilot group – start with admins Enable passkeys in the Authentication Methods Policy for a small test group first – ideally IT administrators and technically confident employees. Test all sign-in scenarios (browser, desktop app, mobile app) before rolling out more broadly.
Step 3: Secure with Conditional Access (recommended) With Entra ID P1, you can create a policy that enforces phishing-resistant MFA. This prevents users from falling back to weaker methods and simultaneously supports many cyber insurance and compliance requirements.
Step 4: Define a fallback Plan for what happens when a user loses their device or cannot use their passkey. Options include the Microsoft Authenticator app (TOTP), a FIDO2 hardware key, or a Temporary Access Pass (TAP). Without a fallback plan, helpdesk load will rise sharply after 1 February 2027.
Step 5: Communicate with users – now, not on 1 September Inform your employees proactively: what a passkey is, why Microsoft is making this change, and how the registration works (Settings → Security Info → Add passkey). A short internal email or a one-page guide will prevent dozens of support calls.
Special Case: Frontline Workers and Shared Devices
Cashiers, warehouse staff, and other frontline workers who share a terminal run into a structural problem: a passkey is bound to a specific device and user – this does not work smoothly on shared devices. Microsoft has announced an alternative solution starting 30 October 2026: through the Microsoft Security Store, tenants will be able to connect an external telecommunications provider that continues to deliver SMS and voice. Details on pricing and available providers will be published from 18 September onwards. FIDO2 hardware security keys (personally assigned, portable) are not subject to this limitation.
If your organisation has frontline worker scenarios, place this user group on your watchlist and monitor Microsoft's announcements in September.
Note: This post is not legal or compliance advice. It provides a technical overview based on official Microsoft documentation. Current as of August 2026.
Conclusion
1 September 2026 may sound like a deadline – but it is actually the start of a grace period. The hard cutover is 1 February 2027. Organisations that run their inventory now, roll out to a pilot group in the next two weeks, and communicate with users before September will navigate this transition without stress.
Want to know how many of your users are still relying on SMS MFA – and what the migration looks like for your specific tenant? Get in touch. We support Entra ID projects in the Ruhr region and beyond.
Note: The articles on this blog are produced with the help of AI and are editorially reviewed before publication. Editorial responsibility lies with Emre Yurtbay (see the Impressum).