Passkeys Are Becoming the Default in Microsoft Entra: How to Prepare Your Team


Introduction

For many small businesses, signing in to Microsoft 365 is such a routine part of the workday that a new prompt can catch employees off guard. Microsoft has begun rolling out a change to the system behind those sign-ins, Microsoft Entra ID: employees who are enabled to use text messages or voice calls for multifactor authentication (MFA) may be prompted to register a passkey instead. The rollout began September 1, 2026, but that date did not mean every employee’s sign-in changed at once.

This is a security improvement, but it is also a people-and-process change. A little preparation now can help your team adopt stronger sign-ins without turning a routine workday into a series of help-desk calls.

Employee uses a passkey to sign in on a laptop while an IT advisor helps a colleague set up theirs.

In This Article

What Is a Passkey?

A passkey lets someone prove their identity using a device or credential they control, often unlocked with a fingerprint, face recognition, or device PIN. Unlike a password or a code sent by text, a passkey is designed to work only with the legitimate site or app it was created for. That makes it much harder for a fake sign-in page to steal and reuse.

Microsoft Entra supports different passkey options. Some are tied to one device, such as a passkey in Microsoft Authenticator or a physical FIDO2 security key. Others can sync through a supported credential manager. The right choice depends on employees’ devices, how they work, and the level of protection their roles require.

What Is Changing—and When?

The immediate change is a prompt, not the sudden removal of text-message or voice-call MFA. As Microsoft’s rollout reaches an organization, users enabled for SMS or voice authentication are automatically brought into its passkey registration campaign. After completing MFA at sign-in, they may see a prompt to set up a passkey. For now, that registration prompt can generally be postponed.

The later deadline matters too. Microsoft plans to stop providing its own SMS and voice delivery for most users on February 1, 2027. Global Administrators and external users have a later July 1, 2027 deadline; internal guest users remain on the February schedule. After an applicable deadline, someone whose only available MFA method is Microsoft-provided SMS or voice will need to register a passkey before continuing to sign in, unless the organization has arranged a supported telephony provider. These dates apply to Microsoft Entra ID in the public cloud; other cloud environments have a separate timeline.

For business leaders, the takeaway is straightforward: there is time to plan, but postponing every registration prompt is not a long-term plan.

Start With the People, Not the Setting

Before changing sign-in policies, find out how employees authenticate today. Your IT team or managed service provider should identify who is still enabled for SMS or voice, who already uses a phishing-resistant method, and which users may need a different approach. Microsoft recommends reviewing authentication policies and identifying affected users as a first step.

Pay particular attention to roles that do not fit a standard office setup:

  • Employees who use shared or kiosk devices.
  • Staff who do not have a compatible work phone.
  • People who regularly replace or switch devices.
  • Administrators with access to sensitive systems.
  • Employees working across Windows, Mac, and mobile devices.

A physical security key may be more practical for one group, while a supported device-based or synced passkey may be simpler for another. Microsoft recommends planning by user type rather than assuming one method will work equally well for everyone.

Make Registration Familiar Before It Appears

An unexpected security prompt can look suspicious—even when it is legitimate. Tell employees in advance what is changing, approximately when they may see a registration request, and where to find approved instructions. Encourage them to start from their normal Microsoft sign-in or your organization’s established IT guidance rather than following a link in an unverified message.

Keep the instructions short and specific to the devices your team actually uses. Explain who to contact if registration does not work, and ask a small pilot group to try the process first. Microsoft recommends testing with representative users and devices, then monitoring registration progress and support requests before expanding the rollout.

For example, a business might start with a few office staff, an employee who travels, and someone who uses a shared workstation. Their feedback can reveal issues that an IT-only test would miss.

Plan for Lost Devices and Account Recovery

A stronger sign-in method still needs a practical recovery process. What happens if an employee loses a phone, replaces a laptop, or misplaces a security key?

Microsoft recommends that users register at least two authentication methods so they have a backup if their primary method is unavailable. It also supports a Temporary Access Pass: a time-limited credential that an authorized administrator can use to help someone register a new passkey or regain access after an appropriate identity check.

Before rolling out passkeys widely, make sure your organization knows who can approve a recovery request, how that person verifies the employee’s identity, and how a replacement credential is issued. Those steps are especially important for administrators and employees who must be able to work during an urgent situation.

What If SMS or Voice Is Still Necessary?

Some businesses may have a genuine technical, operational, or regulatory reason to continue using text messages or voice calls for certain users. Microsoft says organizations will be able to use a supported telephony provider through the Microsoft Security Store rather than Microsoft’s native delivery. The configuration option is scheduled to become available beginning October 30, 2026, and provider-related costs may apply.

That should be an intentional exception, not the default simply because the current setup is familiar. Identify the affected users, document why they need that method, and test the alternative before their applicable retirement deadline.

A Practical Passkey Preparation Checklist

To make the transition manageable, focus on these steps:

  1. Identify employees who are enabled for SMS or voice MFA.
  2. Choose suitable passkey options for different roles and devices.
  3. Pilot registration with a representative group before a broader rollout.
  4. Communicate what employees will see and where they can get help.
  5. Prepare backup authentication and account-recovery procedures.
  6. Track registrations and help-desk issues so no one is left relying solely on a method approaching retirement.

Make the Change With Confidence

Passkeys can give employees a simpler, more phishing-resistant way to sign in. But the best rollout is not just a technical switch. It accounts for real devices, real workflows, clear employee communication, and a dependable way to recover access when something goes wrong.

If your business uses Microsoft 365 and you are unsure who still relies on SMS or voice MFA, ExcalTech can help review your current sign-in methods and build a practical transition plan. Starting now gives your team room to test, adjust, and adopt stronger authentication without an avoidable last-minute rush.

«
»