Passkeys are now the preferred authentication method in cybersecurity, offering stronger protection against phishing and account compromise. With Microsoft Entra ID moving to a default passkey sign-in experience, organisations should start preparing now to ensure they are ready for this change.
The move away from passwords and other phishable authentication methods towards phishing-resistant access alternatives has been gathering pace for several years. Microsoft’s decision to make passkeys the default sign-in experience in Entra ID is another significant step in that direction.
Passkeys offer stronger protection against phishing, credential theft, and account compromise than traditional authentication methods. The challenge is getting there with the least disruption to day-to-day operations.
What’s changing?
There are two separate changes organisations need to be aware of.
The first is passkey registration.
Since 1 September 2026, passkey registration has been enabled by default in Microsoft Entra ID. Users who sign in using SMS or voice-based authentication will now be prompted to register a passkey. While users can choose to skip the registration process for now, Microsoft plans to enforce passkey registration from 1 February 2027.
The second change is the retirement of Microsoft-delivered SMS and voice authentication.
From 1 February 2027, Microsoft will no longer provide SMS and voice authentication directly through Entra ID. Organisations that still rely on those methods will need to move users to alternative authentication methods or work with a third-party provider.
The transition has already begun and users will be prompted to begin passkey registration now. It’s important that this process is kept simple and accessible for users and to avoid help desk overload.
It’s important to get your users registered
Security professionals understand the value of passkeys. But for many users, the registration can feel like a frustrating extra step that stands between them and signing in.
When they are presented with a passkey registration prompt, one of three things tends to happen:
- They ignore it.
- They click through as quickly as possible without understanding what they’re doing.
- They contact the help desk.
These can all create operational challenges.
For example, if a user registers their only passkey on a laptop or phone that is later replaced, they may be unable to sign in and set up a passkey on the new device. Restoring access could then require the help desk to verify the user and issue a Temporary Access Pass, making a clear account recovery process essential.
So, communication with users is just as important as the technology itself.
At a minimum, support teams should be made aware that users may begin seeing passkey registration prompts. Organisations should also consider proactive user communications explaining what passkeys are and answering common questions.
A small amount of preparation will save a number of help desk calls later.
Don’t overlook account recovery
Passkeys are excellent for security, but account recovery needs to be considered before organisations accelerate adoption.
Organisations should therefore consider the following:
- What happens if a user loses the device that stores their passkey?
- How does a user regain access if their laptop or phone is replaced?
- Is the recovery process secure enough to prevent abuse?
- Is it simple enough for users to complete without unnecessary help desk support?
You only have to look at last year’s Scattered Spider activity in the retail sector for an example of why has highlighted the risks around account recovery.
Entra Account Recovery uses an identity verification provider, Verified ID and Face Check to confirm the user’s identity before restoring access. This gives organisations a more secure and consistent way to confirm identity when users need to register a new authentication method.
Are you actually ready for passkeys?
Another consideration is whether your environment is able to support passkeys in a way that works for users.
For example:
- Can users register passkeys on personal devices?
- Are there restrictions around device types?
- Will Windows Hello for Business be part of your approach?
- Do all your SAML apps support the respective authentication context classes?
- Do some users require hardware security keys such as YubiKeys instead?
- How will users without corporate managed devices authenticate?
These question don’t necessarily prevent passkey adoption, but they need answering before passkeys become the default sign-in experience. The key to this process is not to rush. This is not a ‘flick a swich’ project, it’s one that relies on having the right recovery processes, device strategy, user guidance, and support in place.
Planning for the retirement of SMS and voice authentication
Organisations should also decide what to do about the retirement of Microsoft-delivered SMS and voice authentication. If you currently rely on this method you will need to decide whether to move users to these alternatives:
- Use a third-party provider for SMS or voice-based authentication (Microsoft made telecom provider options available on 18 September and if you decide to remain with SMS and voice authentication you should select your provider by 30 October).
- Move users to Microsoft Authenticator or TOTP.
- Or if you’re in a strong position for passkeys, perhaps this is the nudge to take the next step.
Remember also that this change only affects SMS and voice authentication. Microsoft Authenticator and TOTP authentication remain available alternatives.
However, organisations should not underestimate the user experience implications. Some users who were previously happy to receive a text message may be less comfortable installing Microsoft Authenticator on a personal device. In those cases, organisations may need to consider alternatives such as corporate-owned devices or hardware security keys.
Final thoughts
Ultimately, Microsoft Entra ID’s shift to passkeys is a positive step for security. The challenge is making sure that your organisation is ready for it.
In the short term, the priority should be understanding how passkey registration prompts could affect users and support teams. Looking ahead to February 2027, organisations will also need a clear plan for the retirement of Microsoft-delivered SMS and voice authentication.
Need help preparing for Microsoft’s passkey-first future? Contact Kocho to discuss your passkey readiness today.
Microsoft Entra e-Guide
Secure access with Microsoft Entra
Learn how Microsoft Entra enables Zero Trust access using passwordless authentication, Conditional Access, and identity‑driven network controls.
Discover how you can:
- Replace passwords with phishing‑resistant authentication
- Apply Conditional Access to enforce Zero Trust access decisions
- Secure private app access without VPN‑based trust
- Evaluate session risk in real time
- Reduce identity attack surface