Passkeys become the default sign-in for Microsoft 365 on September 1, 2026, and Microsoft’s own SMS and voice login codes retire on February 1, 2027. If anyone in your company still proves who they are with a six-digit text message, this change reaches them, announced in Message Center notice MC1426371 and already on a fixed timeline.
The good news: this is one of the rare Microsoft changes that makes life easier for end users, not harder. The catch is that “easier” only happens if someone prepares. This guide covers what changes on each date, why, and the short list of things to do before September.
What is actually changing
Two dates matter, and they do different things:
- September 1, 2026: every user currently enabled for SMS or voice MFA gets automatically enabled for passkeys. The next time they sign in and complete MFA, Microsoft nudges them to register a passkey. The prompt is skippable, indefinitely, so nothing breaks; it just starts appearing.
- February 1, 2027: Microsoft stops sending SMS and voice codes entirely. From that point, a user whose only MFA method is SMS or voice hits a blocking prompt: register a passkey before the sign-in can continue. There is no skip and no opt-out, for any tenant.
Note the wording: what retires is Microsoft-provided delivery. An organization that genuinely must keep text-message codes can contract its own telecom provider (covered below). Everyone else moves to passkeys.
Why Microsoft is killing the text-message code
SMS is the weakest form of MFA still in wide use. The code can be phished: a fake login page asks the user for it and relays it to the real site in seconds. The phone number can be stolen outright through SIM-swap fraud, a phone-store social-engineering attack that requires no technical skill. Neither of these is theoretical; both are routine in real incident reports.
A passkey resists all of it for a simple reason: there is no code. Nothing to read out, nothing to type into the wrong page, nothing to intercept. The cryptographic key never leaves the device and only answers to the genuine site.
What a passkey is, in plain English
A passkey is a digital key stored on something the user already has: their phone, their Windows PC through Windows Hello, or a small USB security key. To sign in, they unlock it the way they unlock the device, with a fingerprint, their face, or a PIN. It feels like unlocking a phone, because that is what it is. In practice it is faster than waiting for a text.
Passkeys come in two flavors. Synced passkeys live in iCloud Keychain or Google Password Manager and follow the user across their devices. Device-bound passkeys stay on one device, such as Microsoft Authenticator, Windows Hello, or a hardware key. The distinction matters for your security policy, not for your users; both count as phishing-resistant and both satisfy the new requirement.
What happens if you do nothing
Nothing catastrophic, which is exactly why it gets ignored. From September, your SMS users start seeing an unexplained “set up a passkey” prompt and snoozing it, and a few of them call whoever handles IT to ask if it is a scam. That is the mild version.
The February version is worse: the codes stop, and every remaining SMS-only user gets walked through passkey registration by force, mid-sign-in, on a Monday morning, with no preparation and nobody assigned to help. No one is locked out permanently, but you have converted a planned rollout into a company-wide fire drill.
The difference between those two outcomes is a few hours of preparation.
What to do between now and September
- Find out who is affected. Microsoft publishes a report and a PowerShell script that lists every user still enabled for SMS or voice. If you have an IT partner, ask them for the count. A non-zero answer means your tenant is in scope.
- Run the registration campaign on your own schedule. The passkey nudge can be turned on today, before Microsoft turns it on for you. Starting early means stragglers surface in October, not February.
- Tell people what is coming. A short note: what a passkey is, why the change is happening, what the prompt will look like. Users who expect the prompt register; users surprised by it call the help desk or ignore it as phishing.
- Handle the edge cases deliberately. Employees without smartphones get a hardware key or Windows Hello. Shared devices, frontline workers, and service accounts deserve a named owner and a plan, because they are the ones the blocking prompt will strand.
If you genuinely need SMS to keep working
Some regulated scenarios require an out-of-band text or call. For those, Microsoft is opening a catalog of telecom providers through the Microsoft Security Store: provider details publish September 18, 2026, and configuration opens October 30, 2026. You contract with the carrier directly and pay per message.
Treat this as an exception path, not an escape hatch. Document which regulation or workflow requires it, scope it to the smallest possible group, and default everyone else to passkeys. Remember the reset angle too: the retirement covers self-service password reset, so a user who verifies resets by text needs either another method or that provider in place.
Where to start
If you have an IT partner, the question to ask is simple: “How many of our users still sign in with SMS, and what is the plan to get them onto passkeys before September?” A vague answer is information too.
If you do not have one, this sits squarely in what our Microsoft 365 management and cybersecurity services exist for: we run the report, stage the rollout, send the user communications, and handle the stragglers. Get in touch and we will start with the count. Most businesses are one short project away from never sending a login code again.