Microsoft is changing how Microsoft 365 users sign in, making passkeys the default login method and phasing out its own SMS and voice-call verification.
- What it is: From 1 September 2026, Microsoft Entra ID will automatically prompt eligible users to set up a passkey during multi-factor authentication. Microsoft-provided SMS and voice codes stop working entirely from 1 February 2027.
- Who is affected: Any business using Microsoft 365 or Entra ID for staff sign-in, particularly those still relying on text message or phone call verification codes.
- The risk: Businesses that take no action risk staff being locked out of email and other Microsoft 365 services once SMS and voice codes are switched off.
- What to do: Start moving staff to the Microsoft Authenticator app or a physical security key now. If SMS or voice must be kept for some staff, a third-party telecom provider will need to be configured through the Microsoft Security Store from 30 October 2026.
Passkeys are a stronger, phishing-resistant way to sign in, and we recommend businesses use the next few months to get staff comfortable with the change before the SMS cut-off. Full details are in Microsoft's official documentation.