Author: Dan Briggs | Published: 6 August 2026 | Reading time: 18 minutes
Executive summary
From 1 September 2026, Microsoft starts switching passkeys on by default across Microsoft Entra ID, and by 1 February 2027 it retires its own SMS and voice call authentication service entirely, according to Microsoft’s own Entra ID security update posted 13 July 2026. If your business, like most of our clients, still leans on text-message or phone-call MFA codes for staff who sign into Microsoft 365, that free, built-in verification method has an expiry date. We’re already fielding calls from clients in Sydney, Brisbane and Central West NSW asking whether this is a scam prompt or a genuine Microsoft change — it’s genuine, and it’s one of the more consequential identity changes Microsoft has pushed through Entra ID this year. This whitepaper explains what’s actually changing, why it matters more for regional and multi-site businesses than head-office IT teams appreciate, and what to check before the rollout reaches your tenant.
What’s changing, and when
Microsoft Entra ID (formerly Azure AD) is the identity system behind every Microsoft 365 sign-in. Two related changes are landing on the same timeline, and Australian businesses need to treat them as one project rather than two separate notices to file away.
First, starting 1 September 2026, Microsoft is switching the passkey Registration Campaign to “Microsoft managed” for eligible tenants. In practice, that means any user currently set up for SMS or voice call MFA will start being prompted, at sign-in, to register a passkey instead. Microsoft’s rollout notes describe this as a gradual change that “may take time to reach all tenants,” so you may not see it on day one — but it is coming to every Entra tenant that hasn’t already opted out.
Second, and more consequential for anyone who hasn’t modernised their MFA setup, Microsoft is retiring its own SMS and voice authentication service on 1 February 2027. After that date, Microsoft will no longer send the text messages or make the automated calls that deliver one-time codes to staff phones for MFA. Organisations that want to keep offering telephony-based MFA will need to configure a third-party telecom provider through the Microsoft Security Store themselves — Microsoft is getting out of the SMS/voice delivery business, not banning the method outright, but it is handing the cost and configuration burden to you.
Microsoft has published a temporary opt-out that lets admins delay both changes on their tenant while they prepare, but Microsoft has also confirmed that after 1 February 2027, passkey enablement will be enforced for all in-scope users regardless of tenant settings. The opt-out buys time. It doesn’t buy indefinite exemption.
Why Microsoft is doing this now
This isn’t a cosmetic change. SMS and voice MFA have well-documented weaknesses: SIM-swap fraud, SS7 network interception, and simple phishing pages that relay a one-time code in real time (sometimes called an “adversary-in-the-middle” attack) all defeat text-message codes without needing to touch the user’s device. Microsoft’s own security blog frames the retirement as closing off one of the most commonly exploited MFA gaps in enterprise environments.
Passkeys, which are built on the FIDO2/WebAuthn standard, remove the shared-secret code entirely. Instead of typing in a number that could be phished, relayed or intercepted, the user approves the sign-in with their device’s biometric sensor, PIN, or a physical security key. There’s no code to steal because there’s no code being transmitted at all. The FIDO Alliance’s 2026 State of Passkeys report — based on an 11,000-consumer survey across ten countries including Australia — found that 75% of people have now enabled a passkey on at least one account and 68% of organisations globally have deployed or are actively deploying passkeys for employee sign-in. Microsoft is moving with, not ahead of, where enterprise identity is already heading.
For Australian businesses this dovetails with a compliance direction that’s already been signalled elsewhere. The ASD’s retirement of the Essential Eight in favour of a broader Essential 8 successor framework, which we covered when it was announced, put stronger emphasis on phishing-resistant authentication rather than “any MFA will do.” Passkeys sit squarely inside that phishing-resistant category; SMS codes do not.
Passkeys, explained without the jargon
Strip away the marketing and a passkey is a cryptographic key pair. One half stays locked to your device (a phone, laptop, or hardware key like a YubiKey); the other half sits with Microsoft. When you sign in, your device proves it holds the private half using a fingerprint, face scan, or PIN — that proof never leaves the device and can’t be phished, guessed, or relayed to a fake login page the way a six-digit SMS code can.
A few practical points we find clients ask about on every call:
- Passkeys can be stored on a phone (Windows Hello, Face ID, Android biometrics), synced across a person’s own devices via their Microsoft, Apple, or Google account, or kept on a dedicated hardware key for staff without a compatible phone.
- Registering a passkey does not remove a user’s password immediately. Microsoft’s rollout keeps existing sign-in methods available side by side during the transition; the passkey becomes the preferred, faster option.
- Shared or kiosk-style devices — common in hospitality reception desks and warehouse floors — need a specific plan, because a passkey tied to one person’s biometrics doesn’t work cleanly on a shared login. We’ll come back to this in the rollout section.
It’s worth being clear about what this rollout is not. It is not Microsoft killing MFA generally, and it is not a forced abandonment of every existing sign-in method overnight. Authenticator app push notifications, hardware FIDO2 keys already in use, and Windows Hello for Business all remain unaffected. The change is specifically about the SMS text message and automated voice call delivery paths — the two weakest links in the MFA chain — being retired as a Microsoft-hosted service, with passkeys promoted as the default replacement experience for anyone currently sitting on one of those two methods.
What happens if you do nothing
Doing nothing doesn’t mean nothing happens — it means Microsoft makes the decision for you, on Microsoft’s timeline, without your input on which staff get prompted first or how the change is communicated internally.
Three concrete risks show up in the businesses we work with:
- Help desk load spikes. When staff are unexpectedly prompted to “set up a passkey” mid-sign-in with no warning, a predictable share of them will call IT support confused, assume it’s phishing, or simply get stuck. We saw an almost identical pattern when Microsoft pushed number-matching MFA prompts a few years back — the technology was sound, but the lack of internal communication generated a support ticket wave that was entirely avoidable.
- Line-of-business apps that hard-code SMS MFA break silently. Some older remote access tools, VPN clients, and finance platforms are configured to expect a text-message code specifically, not just “any MFA method.” When Microsoft’s SMS service switches off on 1 February 2027, those integrations don’t gracefully fail over to a passkey prompt — they simply stop authenticating users until someone reconfigures them.
- Compliance and cyber-insurance gaps. Insurers and auditors are increasingly asking specifically about phishing-resistant MFA, not just “is MFA enabled.” A business that hasn’t reviewed its authentication methods by the time this question comes up in a renewal or an APRA CPS 230-driven due diligence review (a topic we’ve covered previously for businesses that supply regulated financial entities) is answering from a weaker position.
The regional coverage problem nobody’s talking about
Here’s the angle most of the coverage on this change misses, and it’s the one we’d flag first to any client outside a capital city CBD: SMS and voice MFA retirement assumes reliable mobile coverage at the point of sign-in. That assumption doesn’t hold everywhere we operate.
Across our Central West NSW client base — Orange, Bathurst, and Dubbo in particular — we regularly see staff working from properties, depots, and second sites with patchy or no mobile signal, relying on office Wi-Fi for connectivity but still needing a phone signal to receive an SMS code. Telstra’s own coverage map has been shrinking in parts of regional NSW, a change we flagged for Central West businesses in July. For those staff, passkeys are arguably a better outcome than the status quo, not a worse one: a passkey stored on a laptop or authenticated via Windows Hello doesn’t need mobile signal at all, it only needs the device itself. But that’s only true if the passkey is provisioned and tested before the SMS fallback disappears. We’ve seen the opposite scenario play out with other Microsoft authentication changes — a regional office finds out its fallback method no longer works only when someone genuinely can’t get a text message through, and by then it’s an urgent support call, not a planned migration.
The practical implication: if any part of your workforce operates from a location with inconsistent mobile coverage — farm offices, warehouse sites, client premises without guest Wi-Fi — passkeys tied to a device rather than a phone number are worth prioritising for those staff first, well ahead of the September prompts starting to appear. It flips the usual rollout order (head office first, remote sites last) on its head, and it’s a sequencing decision most generic guidance on this change won’t tell you to make.
Action checklist for the next six weeks
The gap between now and 1 September 2026 is short. Here’s what we’re recommending clients action before the Microsoft-managed rollout reaches their tenant.
| Action | Why it matters | Who owns it |
|---|---|---|
| Audit which users and apps currently rely on SMS or voice MFA in Entra ID | You can’t plan a transition for methods you haven’t inventoried | IT admin / MSP |
| Identify line-of-business apps and VPN clients hard-coded to expect SMS codes | These won’t fail over automatically when SMS is retired | IT admin, app owners |
| Flag staff and sites with unreliable mobile coverage for early, device-based passkey enrolment | Removes phone signal as a single point of failure at sign-in | IT admin, site managers |
| Decide on a plan for shared/kiosk devices (reception desks, warehouse terminals) | Passkeys tied to biometrics don’t transfer cleanly between users | IT admin |
| Draft a short staff communication explaining the passkey prompt before it appears | Cuts help desk tickets and phishing confusion dramatically | IT admin / management |
| If telephony MFA must be retained past February 2027, configure a third-party provider via Microsoft Security Store | Microsoft is not providing SMS/voice delivery itself after this date | IT admin / MSP |
| Test passkey sign-in with a small pilot group before the campaign reaches all staff | Surfaces device compatibility issues on your own hardware fleet, not in production | IT admin |
How to roll out passkeys without breaking your team
We’re recommending a staged approach rather than letting the Microsoft-managed campaign hit every user simultaneously.
1. Start with a pilot group
Pick a small, technically comfortable group — five to ten people across different device types (Windows laptop, iPhone, Android) — and have them register passkeys deliberately, ahead of the automatic prompt. This surfaces device or browser compatibility issues on your own fleet before the rest of the business sees the prompt.
2. Communicate before Microsoft does
A short, plain-language email or intranet note explaining “you’ll see a prompt to set up a passkey over the coming weeks, here’s what it is and why” does more to reduce support tickets than any amount of technical preparation. Staff who understand the prompt is legitimate and expected are far less likely to dismiss it as phishing or call the help desk in a panic.
3. Solve shared devices separately
For reception terminals, warehouse scanners, or any shared login, passkeys tied to individual biometrics aren’t a clean fit. Options include a hardware security key assigned to the device rather than the person, or keeping a managed telephony provider configured specifically for that use case. Don’t let the shared-device question stall the rest of the rollout — solve it as its own workstream.
4. Prioritise coverage-poor sites
As set out above, staff at sites with unreliable mobile signal benefit most from a device-based passkey and should be enrolled early, not last.
5. Keep a documented fallback for the transition window
Until 1 February 2027, existing SMS and voice MFA continues to work if you haven’t opted into early enforcement. Use that window deliberately — don’t treat it as “not our problem until next year.”
6. Budget for hardware keys where biometrics aren’t practical
Not every device in a small business fleet has a fingerprint reader or camera capable of Windows Hello. Older desktops, some shared terminals, and budget laptops may need a physical FIDO2 security key, typically costing between $30 and $70 per key depending on brand and features. Building this into your rollout budget now avoids a scramble to source keys once staff start hitting compatibility gaps mid-prompt.
Key dates at a glance
| Date | What happens |
|---|---|
| 1 September 2026 | Microsoft begins rolling out Microsoft-managed passkey registration prompts to eligible Entra ID tenants; rollout reaches tenants gradually, not all at once |
| Now – 1 February 2027 | Temporary opt-out available for admins who need more time to prepare; existing SMS/voice MFA continues to function |
| 1 February 2027 | Microsoft retires its own SMS and voice authentication service; telephony MFA only continues if a customer-configured provider is set up via Microsoft Security Store |
| After 1 February 2027 | Passkey enablement enforced for all in-scope users regardless of tenant opt-out settings |
Frequently asked questions
Do we have to switch to passkeys, or can we keep using SMS codes?
You can keep using SMS or voice MFA past February 2027, but only if you configure a third-party telecom provider through the Microsoft Security Store yourself, since Microsoft is retiring its own delivery service on that date. For most small and mid-market businesses, moving to passkeys is simpler and more secure than taking on a new telephony vendor relationship.
Will this cost us anything?
Passkey registration itself has no additional licensing cost within existing Microsoft 365 and Entra ID plans. Costs only arise if you choose to keep SMS/voice MFA running past February 2027, in which case you’ll be paying a third-party telecom provider directly, or if you need to purchase hardware security keys for staff on shared devices.
What if a staff member loses their phone after registering a passkey?
Passkeys can be re-registered on a new device using standard Entra ID account recovery processes, the same way lost authenticator app access is handled today. We recommend documenting this recovery process for your help desk before the rollout begins, rather than working it out during a genuine lost-device incident.
Does this affect Microsoft 365 licensing or Copilot in any way?
No. This is purely an identity and authentication change in Entra ID. It’s unrelated to Microsoft 365 or Copilot licensing changes, including the ones we’ve covered around Copilot in 30 trials and 1 July price rises.
Our staff work across sites with poor mobile coverage — does that make this harder?
It makes early planning more important, not harder in the long run. A passkey stored on a laptop or authenticated via device biometrics doesn’t rely on mobile signal at all, which removes a point of failure for coverage-poor sites once it’s properly provisioned and tested.
Is this the same thing as the Essential Eight changes?
They’re related but distinct. The ASD’s Essential 8 successor framework pushes businesses toward phishing-resistant authentication as a maturity goal, which passkeys satisfy and SMS codes do not. This Entra ID change is Microsoft’s own product timeline for retiring SMS/voice delivery and defaulting to passkeys, and it applies regardless of which Essential Eight maturity level your business is targeting. Acting on this Entra change now also moves you closer to Essential 8 phishing-resistant MFA requirements, so the two pieces of work are worth planning together rather than separately.
Get help before September
All IT Services works with businesses across Sydney, Brisbane, Central West NSW, and Melbourne to plan Microsoft 365 and Entra ID identity changes like this one before they land on staff screens unannounced. If you’d like us to audit your current MFA setup, flag which apps and sites need attention first, and run the rollout for you, call us on 1300 425 548 or get in touch through our contact page.
