Microsoft Drops SMS and Voice MFA for Passkeys in Entra ID
Microsoft Entra ID will stop using SMS and voice multifactor authentication (MFA) by February 1, 2027. The move marks a shift towards more secure passkey-based authentication methods.
The company is making passkeys the default experience for Entra users starting September 1, 2026. Passkeys are designed to be phishing-resistant and use cryptographic key pairs rather than shared secrets like passwords or one-time codes.
Entra ID will automatically enable users for passkeys if they are currently using SMS or voice authentication. During a subsequent sign-in requiring MFA, eligible users will be prompted to register a passkey. This change affects all tenants and does not offer an opt-out option.
The company advises administrators to adopt a staged rollout plan when implementing the new policy. This includes enabling FIDO2 passkeys, creating security groups for affected users, launching a registration campaign, and delivering targeted communications. Users can initially snooze the enrollment prompt indefinitely, so organizations should pair technical configuration with clear deadlines and end-user guidance.