Passkeys become the default while SMS and voice authentication are phased out
Passkeys will become the default authentication experience in Microsoft Entra starting September 1, 2026. The change is part of Microsoft's broader move toward phishing-resistant authentication and reflects a continued shift away from authentication methods that remain vulnerable to phishing, interception, and social engineering attacks.
Organizations currently relying on SMS or voice authentication should review their authentication strategy well before the transition begins. Starting in September 2026, passkeys will be automatically enabled for users who currently use SMS or voice authentication, and users may be prompted to register a passkey during multifactor authentication sign-ins. Microsoft will also enable passkey registration campaigns in Microsoft-managed mode for eligible tenants.
The transition introduces a new requirement for organizations that need to continue using telephony-based authentication methods. Beginning October 30, 2026, customers will be able to select a telecom provider through the Microsoft Security Store. After February 1, 2027, SMS and voice authentication will only be available through customer-configured telecom providers. Organizations that continue to rely solely on Microsoft's SMS and voice services risk authentication disruptions after the retirement date.
Even though this change is something Microsoft has announced a long time ago, they will offer a temporary opt-out period between September 1, 2026 and February 1, 2027. This may provide valuable time for organizations that need additional planning, testing, user communication, or telecom provider onboarding. However, the opt-out should be viewed as a transition mechanism rather than a long-term solution. The underlying change is still coming, and organizations should use this period to prepare rather than postpone planning.
The rollout begins on September 1, 2026, with passkeys automatically enabled for eligible users and passkey registration campaigns activated. Organizations that need to continue using SMS or voice authentication will be able to select a telecom provider through the Microsoft Security Store starting October 30, 2026. Microsoft-provided SMS and voice authentication will be retired on February 1, 2027.
For additional details, see the following resources:
https://learn.microsoft.com/entra/identity/authentication/concept-sms-voice-retirement
As with any feature that is still rolling out, release dates and implementation details may change. Monitor the Microsoft 365 Message Center for the latest updates. At the time of writing this post, I was unable to find and "Microsoft Roadmap" related posts.
More granular passkey management with passkey profiles and synced passkeys
Passkey profiles and synced passkeys are now generally available in Microsoft Entra ID. The update introduces a more flexible way to manage passkeys by allowing administrators to control whether users can register device-bound passkeys, synced passkeys, or both.
The new passkey profiles support group-based configuration, making it easier to apply different passwordless authentication policies to different user populations. Organizations already using Passkeys (FIDO2) should review their current configuration and understand how the new passkey profile model fits into their authentication strategy.
Administrators should also review any authentication methods registration campaigns that target passkeys. Depending on the current configuration, users may receive prompts to register passkeys as part of the organization's move towards passwordless authentication.
For additional details, see the Microsoft Learn documentation:
https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-passkey-profiles
https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-synced-passkeys
Improved passkey restore experience in Microsoft Authenticator for iOS
Microsoft has announced an improved restore experience for device-bound passkeys in Microsoft Authenticator on iOS. The update is designed to make device migrations easier by providing clearer guidance when users restore Authenticator on a new device.
The new experience introduces a more guided restore workflow that helps users understand whether they are setting up a new device or restoring from an existing one. Microsoft is also improving the guidance around cross-device sign-in scenarios involving passkeys. The goal is to reduce user confusion during device replacement while maintaining the security benefits of passkey-based authentication.
Although no administrative configuration changes are required, organizations may want to review their user guidance and helpdesk procedures for device replacement and Authenticator recovery scenarios. Users moving to a new iPhone may encounter a different experience than support teams are familiar with today.
This update applies only to iOS devices. Users who have iCloud and iCloud Keychain backup enabled and have passkeys stored on their previous device will see the updated experience when restoring Microsoft Authenticator on a new device. The feature is enabled by default.
General availability is scheduled for August 2026 worldwide.
At the time of writing, Microsoft has not published dedicated technical documentation for this specific update. Refer to the Message Center announcement for current details and watch for additional Microsoft Learn documentation as the rollout approaches.
Thank you for reading. If you would like to keep up with future Microsoft 365, Entra ID, Security, and Copilot updates, feel free to follow me on LinkedIn. You'll find a link to my LinkedIn profile in the main menu on the front page.

Comments