Passkeys by default in Entra ID: what Microsoft's SMS and voice retirement means for your organization

On July 13, 2026, Microsoft announced a major shift in Entra ID: passkeys become the default authentication method, and Microsoft-provided SMS and voice authentication will be retired. By February 1, 2027, text messages and phone calls are gone as Microsoft-provided MFA methods.
This is a change worth welcoming. It is also a migration project with a hard deadline, and it starts with one question: who in your organization still signs in with SMS or voice?
If you had to guess just now, this article is for you. It covers why passkeys win, the dates that matter, and what to do if you genuinely still need SMS or voice, then walks through a step-by-step plan to move everyone across before the deadline.
Why passkeys are the right call
SMS and voice codes served MFA well for years. Attackers caught up. A code sent over the phone network can be phished, intercepted through a SIM swap, or captured and replayed. Every one of those attacks works because the code is a shared secret the user can be tricked into handing over.
Passkeys remove the secret. The private key never leaves the user's device, so there is no code to steal and no fake login page worth building.
The attacks are also getting better. Microsoft cites AI-enabled phishing campaigns achieving a 54% click-through rate, against 12% for traditional attacks. Retiring the most phishable methods first is the right response.
Cost points the same way. Migrating users to passkeys costs nothing extra, while keeping SMS or voice alive through a third-party telecom provider carries a per-message cost. The secure path is also the cheaper one.
The timeline
The retirement rolls out in four steps, documented in Microsoft's retirement guidance:
September 1, 2026. Users enabled for SMS or voice are automatically enabled for passkeys and nudged to register one at MFA sign-in. The prompt can be snoozed without limit by default.
September 18, 2026. Telecom provider options and pricing are published in the Microsoft Security Store.
October 30, 2026. Customers who need SMS or voice can configure a customer-managed telecom provider.
February 1, 2027. Microsoft-provided SMS and voice are fully retired, for self-service password reset as well as MFA. Users whose only MFA method is SMS or voice get a blocking passkey registration prompt. No opt-out. Enforced for every tenant.
A temporary deferral is available for the September changes (API details arrive August 1, 2026), but the February 2027 retirement applies to every tenant, no exceptions. The opt-out buys you time, not an exit.
To be clear about scope: only Microsoft-provided SMS and voice are being retired. Microsoft Authenticator push notifications and authenticator app one-time codes (TOTP) continue to work, and users who have them registered will not hit the February block. They are still not phishing-resistant, though. For segments that cannot reach passkeys before the deadline, moving them to Authenticator push or TOTP is a workable interim step. The goal remains passkeys.
If you still need SMS or voice
The methods themselves do not disappear on February 1, 2027. What ends is Microsoft's own telecom delivery.
Organizations with a genuine regulatory or operational need, for example a compliance regime that requires an out-of-band SMS channel, can contract directly with a telecom provider through the Microsoft Security Store. You pick a carrier that meets your regional and compliance requirements, pay per message, and the users you cover keep signing in with SMS or voice under your own policies. No blocking prompt. This route covers self-service password reset as well.
The trade-off is clear, though: you take on a carrier contract and a per-message bill to keep a method Microsoft classifies as its weakest. Document which user segments need it and pilot with a small group first, Microsoft recommends having a provider configured at least four weeks before the February deadline. Default everyone else to passkeys, or at least to a method that is not being retired.
What to do before September
Three actions cover what most organizations should do:
Find your SMS and voice users. Pull the numbers now. Knowing whether you have 30 affected users or 1,300 changes the size of everything downstream.
Plan the registration campaign. Communicate early and clearly: what a passkey is, why it is better, and what users will see at sign-in from September 1. Users who understand the nudge will not snooze it forever.
Evaluate the telecom-provider exception, narrowly. If a regulated segment has a documented need for phone-based methods, plan the Security Store route described above. For everyone else it is a last resort, not a fallback plan.
You can't migrate users you can't see
The announcements cover what changes and when. They do not cover who: which users still rely on SMS or voice as their default method, where they sit, and who manages them. Visibility is step zero.
This is what Bsure's Authentication Methods report shows. You get the distribution of default MFA methods across your organization, sliced by department, country, or manager, and you can drill down to individual users and export the list. In one view you see how many users default to SMS or voice, who they are, and who has not registered MFA at all. That export is your migration campaign, ready to run.
The same report answers all three steps above:
Find your SMS and voice users. The report shows the default method for every user, so the export is done in minutes rather than as a scripting exercise.
Plan the registration campaign. Slice the same list by department, country, or manager, so each team gets a message that fits and the follow-up does not land on IT alone.
Evaluate the exception, narrowly. Filter to the segment that genuinely needs a telecom provider, and keep the paid route as small as it should be.

Bsure's Authentication Methods report: each user's default MFA method in one view, including who still relies on SMS or voice and who has no MFA at all.
The takeaway
Passkeys by default is the right direction, and February 2027 is closer than it looks. The organizations that land this smoothly will be the ones that know their numbers before the first nudge goes out.
Microsoft tells you what is changing. Bsure shows you who is affected.
If you are a Bsure customer, open the Authentication Methods report and pull your SMS and voice numbers today. If you are not yet, book a demo or contact us and see your own organization's picture in minutes.
Know your users. Plan the move. Retire the phone codes before Microsoft does it for you.
Resources
Microsoft Entra ID security updates: passkeys are the default authentication method in Entra ID
Retirement of Microsoft-provided SMS and voice authentication (Microsoft Learn)
Plan a phishing-resistant passwordless authentication deployment (Microsoft Learn)
Passkeys by default, SMS retired: it's happening (Merill Fernando, community post)
Get the latest from Bsure
Subscribe to newsletter






