Microsoft Entra ID Mandates Passkeys, Retires SMS and Voice MFA
Microsoft is phasing out SMS and voice-based multi-factor authentication in Entra ID, making passkeys the default and mandatory authentication method by February 2027 to bolster security against phishing.

Microsoft is taking a significant step towards enhancing security by making passkeys the default authentication method within Microsoft Entra ID, while simultaneously retiring its own SMS and voice-based multi-factor authentication (MFA) services. This strategic shift, announced to take full effect by February 1, 2027, aims to move organizations away from authentication methods that are highly susceptible to phishing and social engineering attacks.
Starting September 1, 2026, users who currently rely on SMS or voice for MFA will be automatically prompted to register passkeys during their next MFA sign-in. Microsoft will manage this registration campaign by default, though users will have the option to postpone the prompt during a transition period. The move is driven by the inherent vulnerabilities of SMS and voice authentication, which can be compromised through methods like SIM swapping, social engineering, number porting, and interception, making them unreliable security measures.
Passkeys, in contrast, leverage cryptographic credentials that are tied to a user's device or a credential manager. This approach eliminates the need for reusable shared secrets that can be phished from fake websites, thereby offering robust protection against phishing and replay attacks. Microsoft Entra ID supports two types of passkeys: synced passkeys, which can be used across multiple devices via credential managers like iCloud Keychain or Google Password Manager, and device-bound passkeys, which are specific to a device and include options like Windows Hello for Business, Microsoft Authenticator passkeys, and FIDO2 hardware security keys.
The complete retirement of Microsoft-provided SMS and voice authentication is scheduled for February 1, 2027. After this date, organizations that still depend on these telecom-based channels will need to utilize a customer-managed telecom provider available through the Microsoft Security Store. Microsoft plans to provide information on these providers starting September 18, 2026, with customer configuration expected to be available from October 30, 2026.
Following the February 2027 deadline, users whose sole MFA option is SMS or voice will encounter a mandatory passkey registration prompt during sign-in. Failure to register a passkey will result in blocked account access. Microsoft emphasizes that there will be no opt-out from this enforcement, underscoring the critical need for early migration to avoid service disruptions.
To facilitate this transition, administrators are advised to first identify users still enabled for SMS or voice authentication through the Entra Authentication Methods Policy or legacy configurations. Microsoft offers a PowerShell-based analyzer to assist in this discovery process. Security teams should then enable Passkey (FIDO2) support, create targeted user groups, and initiate a phased registration campaign before the automatic migration begins.
While Microsoft is offering a temporary opt-out for the automatic passkey enablement phase between September 1, 2026, and February 1, 2027, administrators using Microsoft Graph to set the passkeyDynamicMigration property should be aware that this only delays the transition. It does not circumvent the February 2027 retirement and mandatory passkey registration. For enterprises, this announcement signals the need to relegate SMS and voice MFA to legacy fallback options and prioritize more secure methods like passkeys, Windows Hello for Business, and FIDO2 security keys.
The broader implications of this move extend to the ongoing industry-wide push for more secure authentication methods. By mandating passkeys and phasing out less secure legacy options, Microsoft is aligning with global efforts to combat credential-based attacks and improve the overall security posture of digital identities. This proactive approach aims to significantly reduce the attack surface for organizations relying on Entra ID for identity and access management.