If your team signs in to Microsoft 365 with a password and a text message code, you are about to see a new prompt.

Starting September 1, 2026, Microsoft begins rolling out a change in Microsoft Entra ID (the sign-in system behind Microsoft 365): passkeys become the default sign-in experience. For most businesses, this shows up as a “please set up a passkey” nudge during sign-in.

This is a good move, but it is still a change. The goal is to adopt stronger sign-ins without accidentally locking out the people who keep your business running.

What Microsoft is changing (and why you should care)

Microsoft’s message is straightforward: passkeys are becoming the default authentication experience in Entra ID starting September 1, 2026, and Microsoft-provided SMS and voice MFA are on a retirement timeline. February 1, 2027 is the date Microsoft calls out for full retirement of Microsoft-provided SMS and voice in Entra ID.

In plain terms, Microsoft is trying to move organisations away from sign-in methods that are easy to trick (or intercept) and toward methods that are much harder to phish.

A practical way to think about it:

  • Passwords and SMS codes can be typed into a fake website.
  • A passkey is tied to the real sign-in page and your device, so it is far harder to reuse or steal.

Passkeys, explained like a normal person

A passkey is a modern sign-in credential based on FIDO2. Instead of “something you know” (a password), it is “something you have” (your phone, laptop, or security key) plus a local unlock (Face ID, fingerprint, or a PIN).

A few details that matter for business owners:

  • Passkeys are phishing-resistant. Even if someone convinces an employee to click a bad link, a passkey generally cannot be replayed on the attacker’s site.
  • Passkeys can live in different places. They might be stored on a hardware security key, inside Microsoft Authenticator, or as a device-bound credential like Windows Hello for Business.
  • You still need a rollout plan. Stronger sign-in is great, but you want it introduced in a controlled way, with support for edge cases like shared devices and new hires.

Who gets hit first in September 2026

Microsoft is not instantly forcing every user everywhere to switch on day one. The initial push is targeted.

As Microsoft rolls out the change to each tenant, the first group Microsoft calls out is:

  • Users enabled for SMS or voice authentication. Those users will be automatically enabled for passkeys, and the next time they do MFA they can be prompted to register a passkey.

Two important “owner-level” takeaways:

  • It is about who is enabled, not who actually uses SMS. You can have users who usually use the Authenticator app, but if SMS is still enabled for them, they may get pulled into the passkey nudge.
  • This is a user experience change, not just a security setting. Your helpdesk will feel it if you do not tell staff what the prompt means.

What to ask IT to verify in your Entra tenant this week

You do not need to become an Entra admin to manage this well. You just need your IT team to confirm a few specifics and show you evidence.

Ask them to check:

  • “Who is enabled for SMS or voice today?” Get a list (or at least a count) of users who are enabled for SMS/voice in the Authentication Methods Policy, including any legacy settings that still apply.
  • “Are passkeys enabled, and which types are allowed?” Entra lets you control passkeys (FIDO2), including whether Authenticator passkeys and security keys are allowed, and whether there are restrictions.
  • “What will Conditional Access do when users try to register?” Some Conditional Access controls can accidentally create loops or block registration flows. You want a tested, documented path for a normal user to register a passkey.
  • “Do we have two emergency access (‘break-glass’) accounts, and are they excluded from Conditional Access?” These accounts are your safety net if a policy goes wrong or MFA methods fail.
  • “What is our onboarding plan for passkeys?” New hires are where lockouts happen. If the plan is “we will figure it out when it happens”, that is a risk you can avoid.

If your IT team can answer those clearly, you are already ahead of most organisations.

A calm rollout plan for phishing-resistant MFA (without locking people out)

The best rollouts are boring. They have a pilot group, a back-out option, and a way to help the few people who always have a special case.

A practical sequence looks like this:

  • Start with admins. Require phishing-resistant MFA for Global Admins and other high-privilege roles first. Use an authentication strength or policy that only allows phishing-resistant methods.
  • Keep at least two working sign-in methods during the transition. For example, a passkey plus an app-based method, until you are confident the passkey coverage is solid.
  • Use Temporary Access Pass (TAP) for bootstrapping. TAP is designed to let a user register strong methods without a fragile “guess-and-hope” process, especially for onboarding or recovery.
  • Pilot with real-world users. Include at least one person who uses a shared workstation, one remote worker, and one executive. If it works for them, it will work for most.
  • Communicate the prompt in plain English. A short internal note like “You may be asked to set up a passkey. Choose ‘Authenticator’ if you want to use your phone, or ask IT if you are on a shared device” will prevent a lot of confusion.

The edge cases that tend to bite small businesses

Most users will sail through passkey registration. The support tickets tend to come from a few predictable scenarios.

Plan for these upfront:

  • Shared devices. If multiple staff share one PC, you need clear rules about whether they can register device-bound methods on that machine, and what happens when someone leaves.
  • Conditional Access “too strict, too soon”. If you require phishing-resistant authentication everywhere before users can register it, you can block the very step you are asking them to complete.
  • Lost phone, new phone, broken laptop. Your recovery process needs to be written down. This is where TAP and well-protected emergency access accounts matter.

A simple way to define “done”

You will know you are in a good place when:

  • SMS/voice is no longer enabled for everyday users. Not just “nobody uses it”. It is actually off.
  • Most staff have a phishing-resistant method registered. Passkeys, Windows Hello for Business, or a FIDO2 security key.
  • Onboarding and recovery are repeatable. New hires can start on day one, and lost-device recovery does not turn into a fire drill.

If you would like help reviewing your Entra authentication methods, Conditional Access policies, and a passkey rollout plan that fits your real working environment, the Flexnet Networks team can help you get it in place.

Sources