On February 1, Microsoft stops sending sign-in codes by text message and voice call. We have already written a lot about the technical changes, but this article is about the people side: how you talk your colleagues into passkeys before the deadline. You get five things your plan should include, plus four prompts to help you with the communication.
When we talk to heads of IT about this change, we hear the same thing again and again. The technical side is under control. What worries them is getting the rest of the organization to actually go through with the change. If that sounds familiar, you are in good company.
We humans are creatures of habit. Every January, plenty of us buy a gym membership, and by February a good number of us are back on the sofa. Your colleagues will meet the passkey prompt in much the same way, with "Skip for now" right there. Luckily, a passkey has more in common with the sofa than the treadmill: it is quicker and easier than typing a code. People just need to hear about it in the right way.
1. Own the why, and make it about them
If the email opens with "Microsoft requires", people hear that IT has been handed a chore and is passing it on. Use Microsoft's date to create urgency, by all means, but give the reason in your own words and start with what changes for the person reading. And if you need to mention a risk, tell people what to do in the very next sentence. A warning without a clear next step mostly makes people look away, and here, looking away means pressing "Skip for now".
Example: Instead of "Microsoft is retiring SMS codes, and you must register a passkey by February 1", try "Signing in is about to get faster. Next time you sign in, you will be asked to set up a passkey. It takes a couple of minutes, and then there are no more codes to wait for."
Pro tip: Admit that you are taking away a habit. A line like "we know you are used to codes" softens people up more than one more argument.
2. Make the change as concrete as possible
Nobody needs to understand how a passkey works. What they need to know is what to do when the prompt shows up. Describe that one moment exactly, so the change becomes as concrete as possible.
Example: "After you sign in, you will see a passkey prompt. Click Next and follow the steps on your phone or laptop. You may be asked again on another device, and that is how it is supposed to work." That last sentence will save you a fair few tickets. Without it, the second prompt looks like something broke.
Pro tip: If you limit how many times people can skip, tell them up front. "You can skip this three times" sounds fair, while discovering the limit on the fourth try feels like a trap.
3. Pilot before you broadcast
If you send one email to everyone, you find out what was unclear from the whole company on the same morning. So start with a small group for a limited period instead. Use the feedback from that pilot to improve the rollout before it goes out to everyone.
Example: One IT organization we work with started with its own staff, then moved on to the leadership group in one of the municipalities it serves. IT got to find the problems on itself first, and the leaders became messengers who had already done it.
Pro tip: Ask the management team to register first. A manager who has done it has something real to say, and "I did it on Monday, and it was quicker than I thought" works better than any template. Sit next to a few of them while they do it, too. Watching is often the best way to get feedback.
4. Right message, right messenger
We take different questions to different people. When a message comes from a manager, or from someone we already have a relationship with, we are more likely to listen. So spread the task out across the organization.
Example: When an email comes from your own manager, you open it, because it is usually about you and your work. When a generic email arrives from the IT department, it often goes straight to the archive, because it goes to the whole company and probably does not concern you. The same message lands very differently depending on who sends it.
Pro tip: Department managers are often very busy, so it is easy to feel "ghosted". Usually they just have a lot to do, so make it easy for them: ask for two minutes in a meeting they already have, write a template for them so all they have to do is send it or read it out, and let their own boss be the one who asks.
Bsure tip: From My Team or My Organization in Bsure, you can delegate the list of people still on SMS to each manager. They get an email with a direct link to their part of the list, and they do not need a Bsure account to receive it.
5. Show progress, then close the old door
People are far more willing to move once they see others doing it. Share the numbers per department as you go, so every team can see where it stands. A bit of friendly comparison usually does the rest.
And as long as SMS is still there, some people will keep using it. Once someone has a passkey on every device they use, remove SMS and voice from their account. Better to do it yourself, in waves and during office hours, than to let Microsoft do it all at once on a Monday morning in February.
Example: A short weekly post in Teams: "Finance and HR are done. Sales is catching up. Thanks to everyone who has already switched." Feel free to name the department in last place, with a twinkle in your eye.
Pro tip: Let new employees start with a passkey from day one. There is no reason to hand newcomers the method you have just spent months retiring.
Bsure tip: Bsure keeps the number of people on SMS or voice up to date per department and manager, with a trend over time, so you do not need a new script every time someone asks how it is going.
Free prompts for your own communication
Microsoft has written several good email templates for this change. The catch is that they are written for every company at once. The prompts below help you turn them into messages that sound like you. They work in Copilot, ChatGPT, Claude or whichever assistant you are allowed to use.
1. Rewrite any template so people act on it
Rewrite the Microsoft email template below for employees at [company], a [sector] organization with about [number] employees. Write it in [English / Norwegian / Swedish]. The message asks them to register a passkey before SMS and phone-call sign-in codes stop working on February 1, 2027.
Structure it in this order:
1. What changes for the reader, in one sentence: a faster sign-in with nothing to type.
2. The one thing they need to do: complete the passkey prompt when it appears after they sign in.
3. What to expect: it takes a couple of minutes, and they may be asked again on another device. That is expected.
4. Where to get help.
Tone: friendly, plain and confident. Write like a helpful colleague, not like IT or a vendor. Sign it from a named person, not "IT Department".
Rules:
- Use February 1, 2027, as the date. Some Microsoft templates say January 28.
- No technical terms, no threats and no "Microsoft requires".
- Do not say people will lose access or be locked out. Anyone whose only method is SMS or a phone call will be asked to set up a passkey before they can continue.
- Keep the template's step-by-step instructions and links, using the button and menu names people see on their own screens. Cut everything else that is not needed.
- Keep it under 150 words, and add a subject line and a two-line Teams version.
Message:
[paste the template]
Rewrite the Microsoft email template below for employees at [company], a [sector] organization with about [number] employees. Write it in [English / Norwegian / Swedish]. The message asks them to register a passkey before SMS and phone-call sign-in codes stop working on February 1, 2027.
Structure it in this order:
1. What changes for the reader, in one sentence: a faster sign-in with nothing to type.
2. The one thing they need to do: complete the passkey prompt when it appears after they sign in.
3. What to expect: it takes a couple of minutes, and they may be asked again on another device. That is expected.
4. Where to get help.
Tone: friendly, plain and confident. Write like a helpful colleague, not like IT or a vendor. Sign it from a named person, not "IT Department".
Rules:
- Use February 1, 2027, as the date. Some Microsoft templates say January 28.
- No technical terms, no threats and no "Microsoft requires".
- Do not say people will lose access or be locked out. Anyone whose only method is SMS or a phone call will be asked to set up a passkey before they can continue.
- Keep the template's step-by-step instructions and links, using the button and menu names people see on their own screens. Cut everything else that is not needed.
- Keep it under 150 words, and add a subject line and a two-line Teams version.
Message:
[paste the template]
Rewrite the Microsoft email template below for employees at [company], a [sector] organization with about [number] employees. Write it in [English / Norwegian / Swedish]. The message asks them to register a passkey before SMS and phone-call sign-in codes stop working on February 1, 2027.
Structure it in this order:
1. What changes for the reader, in one sentence: a faster sign-in with nothing to type.
2. The one thing they need to do: complete the passkey prompt when it appears after they sign in.
3. What to expect: it takes a couple of minutes, and they may be asked again on another device. That is expected.
4. Where to get help.
Tone: friendly, plain and confident. Write like a helpful colleague, not like IT or a vendor. Sign it from a named person, not "IT Department".
Rules:
- Use February 1, 2027, as the date. Some Microsoft templates say January 28.
- No technical terms, no threats and no "Microsoft requires".
- Do not say people will lose access or be locked out. Anyone whose only method is SMS or a phone call will be asked to set up a passkey before they can continue.
- Keep the template's step-by-step instructions and links, using the button and menu names people see on their own screens. Cut everything else that is not needed.
- Keep it under 150 words, and add a subject line and a two-line Teams version.
Message:
[paste the template]
2. Give managers the words
Write a short script a team manager can say in two minutes at a team meeting. The team is [team/department] and mostly uses [devices]. The manager has already registered a passkey and should say so in their own words. Cover: why we are doing this, what it means for the team, the one thing to do, and who to ask.
Use only these facts: SMS sign-in codes stop working on [date], people will see a passkey prompt after they sign in, and help is at [help desk contact]
Write a short script a team manager can say in two minutes at a team meeting. The team is [team/department] and mostly uses [devices]. The manager has already registered a passkey and should say so in their own words. Cover: why we are doing this, what it means for the team, the one thing to do, and who to ask.
Use only these facts: SMS sign-in codes stop working on [date], people will see a passkey prompt after they sign in, and help is at [help desk contact]
Write a short script a team manager can say in two minutes at a team meeting. The team is [team/department] and mostly uses [devices]. The manager has already registered a passkey and should say so in their own words. Cover: why we are doing this, what it means for the team, the one thing to do, and who to ask.
Use only these facts: SMS sign-in codes stop working on [date], people will see a passkey prompt after they sign in, and help is at [help desk contact]
3. Answer the questions before they become tickets
Write a short FAQ for employees moving from SMS codes to passkeys. Our users mainly use [Windows laptops / Macs / iPhones / Android]. Include these questions in plain language: "I already have a passkey, why is it asking again?", "What if I lose my phone?", "Can I skip this?" and "Who do I contact?".
Answer only from these facts about our setup: people can skip the prompt [number] times, if someone loses their phone [what our help desk does], and our help desk is [contact]. If you do not have the facts for an answer, write [CHECK]
Write a short FAQ for employees moving from SMS codes to passkeys. Our users mainly use [Windows laptops / Macs / iPhones / Android]. Include these questions in plain language: "I already have a passkey, why is it asking again?", "What if I lose my phone?", "Can I skip this?" and "Who do I contact?".
Answer only from these facts about our setup: people can skip the prompt [number] times, if someone loses their phone [what our help desk does], and our help desk is [contact]. If you do not have the facts for an answer, write [CHECK]
Write a short FAQ for employees moving from SMS codes to passkeys. Our users mainly use [Windows laptops / Macs / iPhones / Android]. Include these questions in plain language: "I already have a passkey, why is it asking again?", "What if I lose my phone?", "Can I skip this?" and "Who do I contact?".
Answer only from these facts about our setup: people can skip the prompt [number] times, if someone loses their phone [what our help desk does], and our help desk is [contact]. If you do not have the facts for an answer, write [CHECK]
4. Test your message before you send it
Read the message below as a busy, slightly skeptical employee who did not ask for this change. Tell me: what you would misunderstand, what would make you click "Skip for now", and which sentence you would stop reading at. Then suggest the three smallest edits that would fix it.
Message:
[paste your draft]
Read the message below as a busy, slightly skeptical employee who did not ask for this change. Tell me: what you would misunderstand, what would make you click "Skip for now", and which sentence you would stop reading at. Then suggest the three smallest edits that would fix it.
Message:
[paste your draft]
Read the message below as a busy, slightly skeptical employee who did not ask for this change. Tell me: what you would misunderstand, what would make you click "Skip for now", and which sentence you would stop reading at. Then suggest the three smallest edits that would fix it.
Message:
[paste your draft]