Microsoft 365 · Entra ID · Passkeys · MFA · IT security

Microsoft passkeys 2026: what companies need to change in Microsoft 365 and Entra ID now

Microsoft is moving sign-in in Entra ID decisively towards phishing-resistant methods. Since 1 September 2026, passkeys have been switched on automatically and actively promoted for users who previously relied on SMS or voice calls. On 1 February 2027, the SMS and voice authentication provided by Microsoft comes to an end. For companies, now is the right time to prepare users, devices, policies and recovery paths properly.

Why Microsoft is making passkeys the standard now

Passwords and SMS codes have accompanied companies for years, but they are not robust against every modern phishing method. Attackers can build deceptively realistic sign-in pages, capture passwords and, in some scenarios, even relay one-time codes in real time. Passkeys take a different approach: the sign-in is cryptographically bound to the genuine website or service.

Microsoft therefore describes passkeys as part of the shift to phishing-resistant authentication. For Microsoft 365 environments, this does not mean that every password disappears overnight. It does mean, however, that companies should review their current MFA strategy: who still uses SMS? Which users already have Windows Hello for Business? Where are FIDO2 security keys needed? And which special cases exist?

Important for 2026: Companies that plan the switch actively can introduce passkeys in a controlled way. Those who wait risk unnecessary support cases as Microsoft continues to phase out the previous telephony-based methods.

Microsoft's timeline: September 2026 to February 2027

Since 1 September 2026, users who are enabled for SMS or voice calls in Entra ID have automatically been enabled for passkeys and prompted to register one when they sign in with MFA. With this, Microsoft has effectively set the migration in motion.

On 1 February 2027, the delivery of SMS and voice codes provided by Microsoft in Entra ID will be discontinued. Organisations that still need telephony for regulatory, technical or operational reasons can use customer-managed providers. However, Microsoft recommends switching to phishing-resistant methods such as passkeys, Windows Hello or FIDO2 wherever possible.

Microsoft publishes the official timeline and the latest guidance in its documentation on passkeys and the retirement of SMS/voice in Entra ID.

What is a passkey – explained simply?

A passkey replaces the classic secret that users type in and an attacker could copy with a cryptographic key pair. The private key stays on the device or in a protected passkey store. The service only receives the public part. When signing in, it is proven cryptographically that the user holds the matching private key.

The practical advantage: a passkey only works for the service it was created for. A fake Microsoft sign-in page therefore cannot simply take over the key. It is precisely this binding to the genuine service that makes passkeys far more robust against classic phishing attacks and so-called adversary-in-the-middle scenarios.

Windows Hello, FIDO2 key or synced passkey?

In everyday business, there is not just one single type of passkey. Which method fits depends on devices, roles and security requirements.

  • Windows Hello for Business: Particularly useful on managed Windows devices. Users can sign in with a PIN or biometrics without the actual sign-in secret leaving the computer.
  • FIDO2 security keys: Physical keys are suitable for especially sensitive accounts, administrators, shared workstations or as a defined backup method.
  • Device-bound passkeys: The key remains bound to a specific device and is therefore easy to control.
  • Synced passkeys: Can be available on several devices via a supported passkey provider. Here, companies should check carefully which providers and device categories they want to allow.

What matters, therefore, is not just "switching on passkeys", but an authentication strategy: which user group gets which method and which recovery path?

How companies should prepare for the switch

1. Take stock

First check which authentication methods are actually used in the tenant. Users whose only second factor is SMS or a voice call are particularly important. Old accounts, guests, service accounts and privileged administrators should also be considered separately.

2. Define target groups

A pilot with IT, power users and selected departments reduces risks. Administrators can be given a stricter standard than regular users. Field staff, production or shared devices may need different methods than classic office workstations.

3. Check devices and policies

Passkeys work best when end devices, browsers, operating systems and Entra policies fit together. For Windows workstations, it is also worth checking whether Windows Hello for Business has already been rolled out properly.

4. Prepare communication

The technical part is only half of the project. Users need to know what will change at their next sign-in, why a registration prompt appears and whom to contact when they change devices.

In practice: a sensible passkey rollout in five steps

  1. Analysis: Identify active SMS/voice users and authentication methods.
  2. Pilot: Test passkeys with a small group of users.
  3. Recovery: Walk through the loss of a smartphone, laptop or security key.
  4. Rollout: Migrate user groups in stages and plan support capacity.
  5. Clean-up: Remove SMS/voice methods and old registrations that are no longer needed.

Microsoft also provides an FAQ on the switch. For special cases such as external users, telephony providers or the question of possible sign-in interruptions in particular, the official Entra ID FAQ is worth a look.

Common mistakes when introducing passkeys

  • Switching all users at once: This creates an unnecessary number of support cases and makes troubleshooting harder.
  • Looking only at the technology: Without clear user communication, even a good security solution becomes a source of frustration.
  • Not planning a recovery path: Devices get lost, replaced or broken. Recovery must be tested in advance.
  • Treating administrators like standard users: Privileged accounts need particularly robust and separate sign-in methods.
  • Leaving old methods open indefinitely: If insecure methods remain in place in parallel without limit, the security gain shrinks.

Do not forget emergency access and administrators

Whenever authentication changes, it must be clear how the company will remain able to act if something goes wrong. This includes documented break-glass accounts, controlled FIDO2 keys, secure storage, clearly defined responsibilities and regular functional tests.

It is especially critical that emergency accounts do not quietly turn into normal working accounts. They should exist solely for defined exceptional situations and be monitored accordingly. At the same time, restoring access for a regular user must not depend on the very device that was lost being needed for confirmation.

What companies should do now

  • Identify active SMS and voice users in the Entra tenant.
  • Assess Windows Hello for Business, FIDO2 and passkey policies.
  • Define a pilot group and test real everyday scenarios.
  • Document recovery and device changes.
  • Secure administrator accounts separately.
  • Prepare user communication before the rollout.
  • Reach a reliable target state by 1 February 2027 at the latest.

Conclusion: passkeys are not a feature switch, but an authentication project

Microsoft's change is a good opportunity to modernise the entire sign-in process in Microsoft 365 and Entra ID. Companies should not simply replace SMS with a new button, but look at user groups, devices, recovery, privileged accounts and policies as a whole.

büKOM Systemhaus GmbH supports companies with Microsoft 365, Entra ID, MFA, passkeys, Windows Hello for Business and the technical preparation of a controlled rollout. The goal is a sign-in process that remains practical for users while becoming considerably more resistant to phishing.

Why büKOM for Microsoft 365 & passkeys?

Because secure sign-in only works when technology, devices and users fit together

A passkey migration affects identities, end devices, policies, support and emergency processes. büKOM connects these areas and helps you implement the switch in a planned rather than hectic way.

A clear view of your tenant We review authentication methods, policies, user groups and special cases in context.
Staged rollout, not big bang A pilot, communication, recovery and a gradual introduction reduce disruption and support effort.
Regional Microsoft expertise Your contact for Microsoft 365, Entra ID and IT security in Rhein-Neckar, Ladenburg, Mannheim and Heidelberg.

You might also be interested in