Passkeys become the default: Is your business ready to say goodbye to SMS codes?
A quiet change with big consequences
If you still receive a code by SMS or a phone call when signing in to Microsoft 365, you will notice a change in the coming months. On 6 August 2026, Microsoft announced that passkeys will become the default sign-in verification method for everyone who currently uses SMS or voice calls, and that SMS and voice codes will be retired entirely in early 2027. There is no opt-out and no setting to turn it off.
Microsoft is not alone. Apple and Google have already integrated passkeys deeply into their ecosystems, and both browsers and major web platforms increasingly present passkeys as the first option, before you even see a password field. The shift from passwords and one-time codes to passkeys is no longer a vision of the future. It is well underway.
In this article we cover what a passkey actually is, why SMS codes are no longer good enough, which dates you need in your calendar, and what you can do now to make the transition calm instead of stressful.
What is a passkey?
A passkey is a way of signing in without typing codes. Instead of waiting for an SMS, you confirm on your own phone or computer that it is really you, with your face, your fingerprint or your device PIN. It is the same gesture you use to unlock your phone.
Technically, passkeys are built on asymmetric cryptography and the FIDO Alliance's WebAuthn standard. When you create a passkey, a key pair is generated: The private key stays on your device and never leaves it, while the service only stores the public key. There is no code that can be intercepted, guessed or reused across services.
The clever part sits under the bonnet: A passkey is cryptographically bound to the genuine sign-in address. On a scammer's fake login page it simply does not work. And there is no code you could accidentally hand to the wrong person, because there is no code. That is why security professionals call passkeys phishing-resistant.
Why are SMS codes no longer good enough?
One-time codes by SMS were better than nothing for years, but today they are the weakest form of multi-factor authentication. Criminals have developed effective ways to bypass them:
- Fake login pages: Modern phishing kits capture both the password and the SMS code in real time and sign in before the code expires.
- SIM swapping: Attackers take over the victim's phone number through the carrier and then receive all the codes themselves.
- Interception in transit: SMS messages are not encrypted and can be intercepted on the way.
In the vast majority of successful account takeovers we see today, an intercepted one-time code plays a part. A passkey cuts that entire risk away. And let us be honest: It is also simply more pleasant. No waiting for an SMS that never arrives, no typing over codes, just your fingerprint or your face, and you are in. Safer and easier at the same time, that does not happen often.
The timeline: Two dates you need to know
- From 1 September 2026, employees who currently use SMS or voice calls will receive an invitation to set up a passkey when they sign in. It is a friendly nudge: It explains itself, takes a few minutes, and from then on they sign in with face, fingerprint or PIN. SMS keeps working during this period.
- From February 2027, Microsoft stops SMS and voice codes completely. Employees who only have that method will not simply get in any more: The sign-in screen first requires them to set up a passkey before they can continue. Not something you want a colleague to run into on a busy Monday morning.
Between those two dates sits exactly the room you need to arrange this calmly instead of under pressure. Only organisations that genuinely cannot do otherwise for legal reasons will get an exception route via their telecom provider. For virtually every SME the answer is: The switch is coming, and fortunately it is also the better choice.
What does it mean for your IT department?
For most businesses this is not a big project, but leaving it is not a plan either. A few things require some thought:
An overview of sign-in methods. Your Microsoft Entra ID environment shows exactly who still uses SMS or voice calls for verification. That list is your entire job. Without the overview, you risk employees being locked out in February 2027.
Employees without a company phone. A passkey does not have to live on a phone. It can also sit on the work computer itself, with Windows Hello and face or fingerprint recognition, or on a small hardware key such as a YubiKey for the keyring. There is a suitable solution for every situation, even without a personal phone in the mix.
Recovery and fallback access. What happens when an employee loses their phone? In a passkey-first world, documented recovery procedures are more important than ever. Establish clear helpdesk routines for identity verification, and consider hardware keys as break-glass access to critical systems.
Policies and Conditional Access. If you use Conditional Access in Entra ID, your policies should be updated to prefer phishing-resistant methods. You also need to decide whether to allow synced passkeys across devices or require device-bound passkeys with attestation. Device-bound gives the strongest security, synced gives the smoothest user experience.
Passkey sprawl. When Apple, Google and Microsoft each store passkeys in their own ecosystems, employees' credentials can quickly end up scattered across personal Apple accounts, Google accounts and work accounts. Consider a central credential manager so the business keeps visibility and control, especially in environments with both personal and company-owned devices.
A practical plan in four steps
- Map your current sign-in methods. Pull the authentication methods report in Entra ID and find everyone who still relies on SMS or voice calls. At the same time, map which of your other systems support passkeys.
- Help that group switch. Setting up a passkey or getting started with Microsoft Authenticator takes a few minutes, especially with a short guide or a colleague on hand. Start with the IT team, then roll out to the rest in smaller waves.
- Give employees a heads-up. A short message beforehand ("you will soon see this question when signing in, that is completely normal") prevents unrest and calls to the helpdesk.
- Define fallback and recovery paths. Document how an employee regains access after losing a device, and establish break-glass access with hardware keys for the most critical accounts.
Already using Microsoft Authenticator? Then you are well on your way
If your employees already use the Microsoft Authenticator app with number matching, you are in good shape: The app is not going away, and you have already left the weak SMS route behind. The passkey invitation is mainly aimed at colleagues still using SMS or phone calls. But switching to passkeys is a good idea for app users too, because it is that bit safer and faster again.
Want help getting through the transition?
At MI Support IT we help our clients with the entire transition: We create an overview of who still uses SMS, guide the switch to passkeys and make sure nobody finds a locked door in February 2027. As part of our IT security services we also advise on Conditional Access, device strategy and recovery procedures.
Not sure where you stand today? You are always welcome to contact us for a no-obligation chat about getting the switch in place well in advance.
