Passkeys are becoming the default in Microsoft Entra ID: what businesses should prepare



Microsoft is changing the default authentication experience for organisations using Entra ID. From 1 September 2026, it will begin prompting users who are enabled for SMS or voice authentication to register a passkey as the rollout reaches their organisation. Microsoft-provided SMS and voice delivery then ends on 1 February 2027.

This is a worthwhile security improvement, but it should be treated as a managed business change rather than left until users encounter an unfamiliar prompt.

Why Microsoft is moving beyond text-message codes

Passwords and one-time codes can be phished. A convincing sign-in page can persuade someone to enter both, giving an attacker what they need while the information is still valid. SMS and voice also depend on telecom channels that can be targeted through interception, social engineering or SIM-related attacks.

Passkeys use public-key cryptography instead. The private credential stays on the user’s trusted device, security key or approved credential manager. The legitimate service verifies the matching public credential without the user being given a secret that they can accidentally type into an imitation website.

The National Cyber Security Centre now recommends using passkeys wherever a service supports them, with two-step verification retained where passkeys are not available.

Start by identifying who is affected

Do not assume that enabling multifactor authentication means everyone uses the same method. Review the Entra authentication-method policy and reporting to identify users and groups still enabled for SMS or voice.

Separate the findings into practical user types:

- administrators and people with privileged access;
- ordinary office users with managed devices;
- remote and mobile workers;
- frontline or shared-device users;
- contractors and temporary staff;
- users with accessibility requirements; and
- genuine operational exceptions.

The right credential and recovery route may differ between these groups. Microsoft’s deployment guidance recommends a persona-based rollout rather than treating the organisation as one uniform population.

Choose the right authentication experience

Microsoft Entra supports several phishing-resistant options. These include synced passkeys, passkeys held in Microsoft Authenticator, device-bound credentials, FIDO2 security keys and local credentials such as Windows Hello for Business.

A synced passkey may be convenient for an ordinary user working across several devices. A hardware security key may be more appropriate for a privileged administrator or a user who cannot depend on a personal mobile device. Windows Hello can provide a smooth local experience on a managed computer. Shared-device and frontline arrangements need separate thought because the assumptions behind a dedicated personal device may not apply.

The objective is not to select the same method for everybody. It is to provide each user group with a secure method that fits how they actually work.

Run a representative pilot

A pilot should cover more than successful registration. Include users from different roles, devices and working arrangements, then test the complete journey:

- receiving and understanding the registration prompt;
- registering the chosen credential;
- everyday sign-in;
- accessing important Microsoft 365 and business applications;
- using a replacement or secondary device;
- losing access to the primary credential; and
- recovering the account safely.

Record the issues and update the user guidance before expanding the rollout. A technically successful pilot involving only the IT team will not reveal the questions faced by an occasional user, a mobile worker or someone using a shared environment.

Design recovery before deployment

Account recovery can become the weakest part of a strong authentication design. If the normal sign-in is phishing-resistant but the helpdesk restores access after a weak identity check, an attacker may simply target the recovery process.

Microsoft recommends that users have at least two authentication methods registered so they have a backup if a device is lost, replaced or unavailable. Organisations should also define how Temporary Access Pass or another controlled bootstrap method will be issued, who may approve it and how the user’s identity will be verified.

Test recovery during the pilot. Confirm what happens when a phone is lost, a member of staff changes device, an administrator loses a security key or a remote worker cannot attend the office. Recovery instructions should be clear enough for the service desk to follow consistently without improvising under pressure.

Prepare people for the prompts

From 1 September 2026, affected users may encounter a passkey-registration prompt during multifactor authentication as Microsoft’s rollout reaches the organisation. Explain the change before that happens.

A useful communication should show users:

- why the change is being made;
- what the legitimate registration prompt looks like;
- which device or method they should use;
- what they must do if the prompt appears unexpectedly;
- where approved instructions are stored; and
- how to obtain help without sharing passwords or verification codes.

Keep the explanation short and practical. Security adoption improves when the safe route is obvious and support is available at the moment of change.

Manage genuine SMS and voice exceptions

Some organisations may have regulated, technical or operational reasons to retain SMS or voice. Microsoft says details and pricing for supported telecom providers will be published on 18 September 2026, with administrators able to select a provider from 30 October 2026.

Treat continued use as a documented exception. Record the affected users, business reason, owner, associated cost, compensating controls and review date. Do not preserve SMS or voice simply because nobody has assessed the alternative.

The Varciti perspective

A good passkey rollout combines identity security, device readiness, user communication, support procedures and business continuity.

Varciti can review the authentication methods currently enabled in Microsoft 365, identify the users and working arrangements affected, recommend suitable credential options and create a controlled pilot and rollout plan. We can also help test registration and recovery, prepare user guidance and document justified exceptions.

The aim is not merely to meet Microsoft’s dates. It is to leave the organisation with stronger authentication that people can use confidently and a recovery process that does not undermine it.

Passkeys are becoming the default in Microsoft Entra ID: what businesses should prepare
Sorry, this item is currently out of stock.
We currently hold [remaining-stock] units of this item in stock. The remainder will be put on back order.
You cannot order more of this item than we currently hold in stock.
You must order at least [min-order-qty] of this product.
You must order at least [min-order-qty] of this product. We currently hold [remaining-stock] in stock. The remainder will be put on back order.