IT Admin Change Calendar Microsoft 365

Entra ID makes passkeys the default and retires Microsoft-provided SMS/voice MFA

From September 1, 2026 Entra ID auto-enables passkeys for SMS/voice MFA users; Microsoft-provided SMS and voice retire on February 1, 2027.

HighSecurity changeAction requiredIn 7 daysVerified

Product

Microsoft Entra ID

Announced

13 July 2026

Effective from

1 September 2026

Completes

1 February 2027

Who is affected

All Entra ID users whose MFA methods include Microsoft-provided SMS or voice. Users already on passkeys, Windows Hello for Business, or FIDO2 are unaffected.

Admin roles to involve: Identity admin, Security admin, Authentication policy admin, Helpdesk

What administrators should do

Identify users still relying on SMS or voice MFA (Microsoft provides a PowerShell script), plan a passkey rollout, and communicate the change. From September 1, 2026 those users are auto-enabled and nudged to register passkeys. If a regulated segment must keep SMS/voice, configure a customer-managed telecom provider through the Microsoft Security Store before February 1, 2027. A temporary Graph-based opt-out exists for the transition period, but the February 1, 2027 enforcement has no opt-out.

What happens if this is ignored

After February 1, 2027, users whose only MFA method is SMS or voice hit a blocking passkey-registration prompt and cannot sign in until they register one.

Why this is rated high: severity comes from a fixed rubric — this entry is a security change that requires administrator action. Time-to-deadline is shown separately and never changes the rating.

Official source

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Published by Microsoft · Source dated 10 August 2026 · Checked 24 August 2026

Last verified 24 August 2026