
Microsoft Entra ID to default to passkeys, phasing out SMS and voice codes by 2027
Microsoft will make passkeys the default authentication method for Microsoft Entra ID starting September 1, 2026. The change primarily affects businesses and organizations that use Entra ID to manage employee access. On February 1, 2027, Microsoft will stop providing SMS and voice call authentication codes, requiring customers to transition to other sign in methods.
Microsoft says the changes respond to increasingly sophisticated phishing and account takeover attempts, including attacks that use AI to create more convincing messages. The company now considers SMS and voice multifactor authentication insufficient against modern phishing techniques. Passkeys instead use cryptographic credentials stored on a user’s device and linked to the legitimate service domain, making them much harder to steal through fake login pages.
Organizations will still be able to use Windows Hello for Business, including biometric authentication, and FIDO2 security keys. Microsoft recommends identifying employees who still rely on SMS or voice codes, preparing a company wide passkey rollout, and informing workers about the upcoming changes.




Comments
Using SMS is always risky for MFA. I've always used a separate OTP app for this. If the organisation uses device based passkeys, there's a chance you'd be forced to used Microsoft Authenticator.
Wow if windows 11 wasn’t bad enough let’s make it even worse again by being forced to use this unholy service
Phasing out SMS in favor of stronger MFA is good, at least from this article there's nothing to indicate you need a Microsoft passkey.