Entra ID just defaulted to passkeys: a runbook before SMS and voice MFA disappear
Since September 1, 2026, Entra ID auto-enrolls your SMS and voice MFA users into passkey registration nudges — and Microsoft-provided SMS/voice retires for good on February 1, 2027, with no opt-out. Here is how to find who is exposed, control the rollout, and configure passkey profiles before the deadline.
If nobody on your team touched the Authentication Methods policy in the last two weeks, it doesn’t matter — Microsoft touched it for you. Since September 1, 2026, every user in your tenant who is enabled for SMS or voice MFA has been silently moved into a Microsoft-managed passkey registration campaign. Next time they complete MFA, they get nudged to register a passkey. By default, they can snooze that nudge forever — which sounds harmless until February 1, 2027, when Microsoft-provided SMS and voice delivery is retired for good, with no opt-out, for every tenant, no exceptions.
That’s a five-month window between “quietly started” and “hard cutover,” and most of it is already gone. Here’s a concrete plan to get ahead of it.
The timeline you’re actually working against
| Date | What happens |
|---|---|
| September 1, 2026 | Users enabled for SMS/voice in the Authentication Methods Policy (or legacy MFA settings) are auto-enabled for passkeys and put into a Microsoft Managed registration campaign. |
| September 18, 2026 | Microsoft publishes details on customer-managed telecom providers for organizations that still need SMS/voice. |
| October 30, 2026 | You can select and configure a third-party telecom provider through the Microsoft Security Store. |
| February 1, 2027 | Microsoft-provided SMS/voice delivery is retired entirely. Users whose only MFA method is SMS or voice get a blocking prompt to register a passkey before they can sign in. No opt-out, enforced for all tenants. |
The driver is straightforward: SMS and voice are phishable and increasingly targeted by SIM-swap and MFA-fatigue attacks, so Microsoft is pushing every tenant toward phishing-resistant credentials by default rather than leaving it as an opt-in best practice.
What the auto-enrollment actually does
If you do nothing, affected users get folded into a passkey profile allowing all passkey types (device-bound and synced) and a Registration Campaign targeting passkeys, set to Microsoft Managed. On their next MFA sign-in, they see a “set up a passkey” prompt — with unlimited snoozes unless you change that. In practice this means a slow trickle of registrations, a support queue that doesn’t spike but doesn’t clear either, and zero control over which passkey types or attestation requirements apply to which users.
That’s fine for a small shop. For an enterprise with admin tiers, regulated user segments, or a fleet of frontline devices without biometric sensors, you want to drive this deliberately.
Step 1: find out who is actually exposed
Before deciding anything, pull the list of users still relying on SMS or voice. Microsoft Graph’s authentication method registration report supports filtering directly:
GET https://graph.microsoft.com/v1.0/reports/authenticationMethods/userRegistrationDetails
?$filter=methodsRegistered/any(x:x eq 'mobilePhone')
Or with the Microsoft Graph PowerShell SDK (requires Reports Reader, Security Reader, or Global Reader):
Connect-MgGraph -Scopes "AuditLog.Read.All"
Get-MgReportAuthenticationMethodUserRegistrationDetail `
-Filter "methodsRegistered/any(x:x eq 'mobilePhone')" |
Select-Object UserPrincipalName, IsAdmin, IsMfaCapable, MethodsRegistered
Microsoft also publishes a dedicated SMS/voice usage analyzer script that does the same job with a friendlier report. Either way, export this list and split it: privileged accounts, regulated segments (if any), and everyone else. That split drives step 2.
Step 2: design passkey profiles instead of one flat policy
Passkey (FIDO2) profiles let you apply different rules to different groups instead of one tenant-wide setting — device-bound vs. synced, attestation enforcement, and AAGUID-based allow/block lists for specific authenticators. A reasonable enterprise split looks like this:
| Segment | Passkey types | Attestation | Key restrictions |
|---|---|---|---|
| IT admins, executives, engineering | Device-bound only | Enforced | None |
| General staff (HR, sales, ops) | Device-bound + synced | Not enforced | None |
| Pilot group for Authenticator rollout | Device-bound | Enforced | Allow only Microsoft Authenticator AAGUIDs |
Configure this under Entra ID > Security > Authentication methods > Policies > Passkey (FIDO2), opting in to passkey profiles first (this is a one-way switch — you can’t opt back out of profiles once enabled, though you can still edit them freely afterward). Synced passkeys via iCloud Keychain or Google Password Manager are the easiest onboarding for general staff since there’s no enrollment friction beyond the platform’s own passkey UI; device-bound passkeys with attestation enforced are the right call for anyone with standing admin rights, since attestation lets Entra ID verify the authenticator’s make and model against trusted metadata.
Step 3: control the timing instead of letting it control you
You don’t have to accept the September 1 rollout as-is. Two levers:
Slow it down. If you need more runway before Microsoft auto-enables passkeys and the registration campaign, set a tenant-wide opt-out via Graph (requires Policy.ReadWrite.AuthenticationMethod):
PATCH https://graph.microsoft.com/beta/policies/authenticationmethodspolicy
Content-Type: application/json
{
"optOutSettings": {
"passkeyDynamicMigration": true
}
}
This only buys time between now and February 1, 2027 — the hard cutover applies regardless of this setting.
Speed it up, deliberately. If you’d rather drive adoption on your own terms than wait for stragglers, enable a Microsoft Managed registration campaign scoped to your own SMS/voice security group (built in step 1) under Authentication methods > Registration campaign, after confirming Passkey (FIDO2) is enabled and those users sit inside a passkey-enabled profile. This gets you the same nudge experience, but targeted and on your schedule rather than everyone’s simultaneously.
Step 4: if you genuinely still need SMS or voice
Some regulated workflows have a real, documented reason to keep an out-of-band SMS channel. For those specific segments — not as a blanket exception — evaluate a telecom provider through the Microsoft Security Store starting September 18, and configure it starting October 30. Budget for this separately: you’ll be contracting and paying the telecom partner directly: Microsoft is stepping out of that business entirely.
The takeaway
The registration campaign nudge is forgiving right now — unlimited snoozes, no forced action. February 1, 2027 is not. Between now and then, the work is the same regardless of tenant size: find your SMS/voice population, decide device-bound vs. synced per segment, and choose whether you’re throttling the rollout or driving it. Doing that in September beats doing it as an emergency help-desk exercise five weeks before the cutover.
Sources & further reading:
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication — Microsoft Learn
- How to enable passkeys (FIDO2) in Microsoft Entra ID — Microsoft Learn
- Get userRegistrationDetails — Microsoft Graph API reference
- Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID — Microsoft Security Blog