What you need to know
Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.
Potentially affected
Microsoft Entra ID and Microsoft 365 administrators; identity, security, compliance, and service-desk teams; public-cloud tenants with users enabled for SMS or voice in Authentication Methods Policy or legacy MFA settings. SSPR and B2B/internal guest scenarios also require review.
DSE recommendation
Inventory affected users, select and pilot replacement methods, communicate the change, and complete migration before February 1, 2027.
Bottom line: Beginning September 1, 2026, Microsoft will start rolling out passkeys as the default authentication experience for users enabled for SMS or voice in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will end. Affected organizations should move users to a phishing-resistant method before that deadline or, where there is a documented need to retain SMS or voice, configure a customer-managed telecom provider.
Source fact: what Microsoft is changing
Microsoft is not eliminating every possible use of SMS and voice. It is retiring the native telecom delivery that Microsoft currently provides for those methods in Entra ID. Microsoft says SMS and voice provide weaker protection than phishing-resistant credentials because telephone channels can be phished, intercepted, redirected, or compromised through attacks such as SIM swapping.
Microsoft recommends passkeys as the primary migration path. Entra ID supports synced passkeys and device-bound credentials, including Microsoft Authenticator passkeys, Entra passkeys on Windows, and FIDO2 security keys. Other phishing-resistant options may also fit particular environments.
Key dates
| Date | Microsoft change | What organizations should know |
|---|---|---|
| September 1, 2026 | Microsoft begins the public-cloud rollout. As it reaches an organization, users enabled for SMS or voice in the Authentication Methods Policy or legacy MFA settings are auto-enabled for passkeys. The registration campaign is placed in a Microsoft-managed state for those users, who are nudged to register after completing MFA. | This is a rollout, not a claim that every Entra user changes simultaneously. The automatic cohort is users currently enabled for SMS or voice. |
| September 18, 2026 | Microsoft plans to publish supported telecom providers, deployment guidance, pricing, and commercial terms in the Microsoft Security Store. | Organizations with a genuine regulatory, technical, or operational need for SMS or voice can begin comparing options. |
| October 30, 2026 | Admins are scheduled to be able to select and configure a supported customer-managed telecom provider. | Microsoft recommends testing the provider with a pilot group before broad deployment. Partner telecom costs are the customer’s responsibility. |
| February 1, 2027 | Microsoft-provided SMS and voice delivery ends in public-cloud Entra ID. | Without a configured customer-managed provider, Microsoft-managed SMS or voice can no longer satisfy authentication requirements. |
| After February 1, 2027 | A user whose only available MFA method is SMS or voice receives a blocking passkey-registration prompt and must register before continuing sign-in. | There is no opt-out from this enforcement. |
Scope and important exceptions
- The published dates apply to Microsoft Entra ID public-cloud environments only. Other cloud environments will receive separate dates and guidance.
- The native SMS and voice retirement applies across Entra, including self-service password reset.
- B2B and internal guest users are included in the retirement scope. Microsoft says passkey support for those users is planned by the end of calendar year 2026.
- If a tenant has no users enabled for SMS or voice, Microsoft says no action is required for this change. Administrators should verify that condition rather than assume it.
The temporary opt-out is not a migration plan
Microsoft Learn documents a temporary opt-out for the automatic passkey enablement and registration-campaign rollout between September 1, 2026, and February 1, 2027. It is configured through Microsoft Graph using the passkeyDynamicMigration opt-out setting and requires the Policy.ReadWrite.AuthenticationMethod permission. Microsoft also notes that moving users out of SMS or voice in the Authentication Methods Policy before September 1 prevents the automatic passkey nudge for those users.
The opt-out does not postpone retirement. Beginning February 1, 2027, the enforcement timeline applies regardless of that setting, and Microsoft provides no opt-out from the final requirement. Because the documented configuration uses a Microsoft Graph beta endpoint, administrators should confirm the current Microsoft procedure immediately before making the change.
DSE recommendation: migration action plan
The following steps are DSE recommendations for managing the transition. Microsoft’s announced requirements and dates are described above.
- Inventory now. Identify every user enabled for SMS or voice in both the Authentication Methods Policy and legacy MFA settings. Review actual method-registration and usage data, SSPR dependencies, guest users, privileged roles, shared-device workflows, and recovery processes.
- Choose the target experience. Prefer passkeys where supported, then document approved alternatives for devices or workflows that need a different phishing-resistant method.
- Pilot before expanding. Test registration, normal sign-in, device replacement, account recovery, temporary access, and help-desk escalation with representative users and devices.
- Drive enrollment deliberately. Enable the target method, use a controlled registration campaign, and give users device-specific instructions before prompts appear. Track completion instead of treating policy enablement as proof of adoption.
- Prioritize privileged and high-risk users. Move administrators, executives, finance personnel, remote-access users, and other frequently targeted groups first. Apply authentication-strength controls in stages after confirming recovery paths.
- Use the temporary opt-out only with an owner and exit date. It can create implementation time, but it should not become a reason to defer the project.
- Retain telecom only for a documented exception. If SMS or voice is necessary, review provider information on September 18, configure and pilot beginning October 30, and complete deployment before Microsoft’s February deadline.
- Finish early. DSE recommends completing production migration by December 15, 2026, leaving time to resolve exceptions and support users before enforcement.
What users should expect
Users already signing in with a passkey, Windows Hello for Business, a FIDO2 security key, or another approved phishing-resistant method can continue using it. Users who remain enabled for SMS or voice may see a prompt to register a passkey after completing MFA as the rollout reaches their organization. Microsoft currently documents unlimited snoozes during the pre-retirement registration campaign, but the post-retirement prompt for users who have no other method will be blocking.
Related DSE guidance
- MFA, passkeys, and authentication strength
- Deploy phishing-resistant authentication by user and device readiness
Official reference
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication, Microsoft Learn, last updated August 10, 2026
- Frequently asked questions about SMS and voice retirement, Microsoft Learn
- Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID, Microsoft Security Blog, published July 13, 2026
Source review completed August 11, 2026. Microsoft may revise implementation details; confirm current guidance before changing production policy.
Review the official source
Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication · Published August 10, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE