Microsoft Entra ID Is Moving Beyond SMS: Is Your Business Ready for Passkeys?0%
    Back to blog
    Security·27 Juil 2026

    Microsoft Entra ID Is Moving Beyond SMS: Is Your Business Ready for Passkeys?

    By Helion Cloud Team

    Microsoft is making passkeys the default Entra ID experience and will retire native SMS and voice delivery on 1 February 2027. Here is how to prepare.

    Share

    SMS was the easiest way to add a second sign-in step, but it can be defeated through phishing, SIM swapping and social engineering. Microsoft is therefore changing direction: passkeys become the default authentication experience in Entra ID. This directly affects organizations still using text messages or voice calls to protect Microsoft 365.

    01

    What changes and when

    The rollout begins on 1 September 2026. Users enabled for SMS or voice will progressively be prompted to register a passkey during multifactor authentication. On 1 February 2027, Microsoft will stop providing native SMS and voice delivery in Entra ID. Organizations with a specific requirement may select a third-party telecom provider through Microsoft Security Store and pay the related costs.
    02

    What a passkey actually is

    A passkey replaces a copyable secret with cryptographic proof bound to a device or synchronized through a credential manager. Users can sign in with Windows Hello, Microsoft Authenticator, a FIDO2 key or a compatible manager. The legitimate service receives proof, never a reusable secret, which makes passkeys phishing-resistant by design.
    03

    An action plan for IT leaders

    First identify users still relying on phone methods in Entra authentication reports. Select passkey types that fit devices and workflows, then run a small pilot covering mobile workers, leaders and support. Prepare recovery procedures and Temporary Access Pass onboarding. Finally, launch a progressive registration campaign with clear user communication and a known support path.
    04

    Mistakes that can lock people out

    Enabling everything for everyone without a pilot is risky. Check shared devices, emergency accounts, people without a corporate smartphone and offline scenarios. Do not remove old methods before recovery has been tested. A sound project combines authentication policy, user enablement, support and adoption measurement.

    Summary

    The end of native SMS is not an outage waiting to happen, but a transition to organize now. An inventory, a pilot and a registration campaign are enough to avoid a rushed migration. Helion Cloud can audit Entra ID methods, define passkey profiles and support users through adoption.

    Need support

    Our team of experts based in Lille supports companies across France, Belgium and Europe. Available Monday to Friday.