The change
There are two deadlines and several user populations
Microsoft says it automatically enabled passkey registration prompts from 1 September 2026 for Entra users enabled for SMS or voice authentication. Its own SMS and voice delivery ends on 1 February 2027 for most users, including internal guests. Global Administrators and external users have until 1 July 2027. After the relevant date, users whose only available MFA method is SMS or voice must register a passkey during sign-in unless their organisation has configured a supported customer-managed telephony provider.
Automatic enablement is not registration
What to check
Measure the last mile, not the policy toggle
Begin with Microsoft's method inventory, including legacy MFA settings, and separate enabled, registered and actually used authentication methods. Include contractors, rarely used accounts, privileged identities and recovery workflows. A user who can sign in with a passkey today may still depend on SMS for self-service password reset or a device replacement path.
- 1
Find the SMS and voice population. Use Microsoft's documented discovery steps and confirm who is affected by each deadline.
- 2
Prove registration and sign-in. Pilot by device type and user group. Track successful passkey registration and real sign-ins, not only the number of prompts sent.
- 3
Test recovery. Rehearse lost-device, new-device, account-recovery and help-desk scenarios before removing telephone-based fallbacks.
- 4
Decide exceptions deliberately. If a valid operational need remains, assess a supported telephony provider through Microsoft Security Store, including coverage, cost and resilience.
- 5
Communicate safely. Give users a trusted internal path to register. Expect phishing that imitates migration prompts and remind staff not to follow unsolicited setup links.
Defender note
Identity migration is a continuity exercise
Passkeys improve resistance to phishing and code theft, but a rushed cutover can strand legitimate users. The best readiness measure is a tested path into and back into the account for every population, with exceptions documented and monitored. Recheck Microsoft's live guidance before final rollout; deployment timing and available providers can change.