Microsoft has made its direction clear: the future of authentication is phishing-resistant.
Beginning September 1, 2026, Microsoft will start making passkeys the default authentication experience in Microsoft Entra ID. Then, on February 1, 2027, Microsoft-provided SMS and voice-based multifactor authentication (MFA) will be retired. Organizations that continue to rely on text messages and phone calls for identity verification need to start planning now.
For security leaders, this is more than a product update. It’s a compelling event that should accelerate long-standing Zero Trust initiatives and efforts to eliminate phishing-susceptible authentication methods.
Why Microsoft Is Making This Change
Identity has become the primary target in modern cyberattacks.
As identity attacks grow more sophisticated in the AI era, attackers increasingly rely on phishing, social engineering, MFA fatigue attacks, and SIM-swapping techniques to compromise accounts. Microsoft’s move away from SMS and voice authentication reflects a broader industry recognition that traditional authentication methods no longer provide sufficient protection against today’s threats.
Passkeys address this challenge by replacing shared secrets with public-key cryptography. Rather than relying on passwords or codes delivered through text messages, passkeys use cryptographic credentials tied to trusted devices and protected by biometrics or device PINs.
Organizations that have invested in strong identity and access management strategies are already moving toward authentication models that are resistant to phishing, credential theft, and account takeover attacks.
This shift aligns directly with Zero Trust principles: never trust, always verify, and continuously evaluate access requests regardless of location or device.
The Timeline Every IT Leader Should Know
Microsoft’s transition will occur in two major phases:
- September 1, 2026: Passkeys become the default authentication experience in Microsoft Entra ID. Users who currently authenticate with SMS or voice methods will begin receiving passkey enrollment prompts following MFA sign-ins.
- February 1, 2027: Microsoft-provided SMS and voice authentication services will be retired. Users whose only authentication method is SMS or voice may be blocked from accessing their accounts until they register a supported phishing-resistant authentication method.
The message is clear: waiting until 2027 is not a strategy.
Why This Matters Beyond Compliance
Some organizations may see this change as another technology migration. In reality, it’s an opportunity to strengthen one of the most targeted areas of the security stack: identity.
Many organizations have already invested in Zero Trust strategies, conditional access policies, endpoint management, and security monitoring. Yet many still rely on authentication methods that attackers know how to exploit.
Microsoft’s announcement creates an opportunity to:
- Reduce reliance on phishing-prone authentication methods.
- Improve protection against credential theft and account takeover attacks.
- Modernize identity security in support of Zero Trust initiatives.
- Improve the user experience by eliminating authentication codes.
- Strengthen resilience through better authentication recovery processes.
Organizations that act early can transform a mandatory transition into a meaningful security improvement initiative.
Common Challenges We’re Seeing
For most organizations, enabling passkeys isn’t the difficult part. Understanding the scope of the transition is.
Common questions include:
- Which users still rely on SMS or voice MFA?
- How many contractors and partners are affected?
- What happens when users lose or replace devices?
- How should hardware security keys fit into the strategy?
- What recovery processes should IT establish?
- How do you support users across multiple Microsoft tenants?
Organizations operating across multiple business units, acquisitions, or Microsoft 365 environments often discover that authentication modernization is more complex than it first appears.
A Stronger Approach: Phishing-Resistant MFA
The most successful organizations won’t simply replace one authentication method with another. They’ll use this opportunity to implement a broader phishing-resistant authentication strategy.
A modern approach typically includes:
- Passkeys as the primary authentication method: Passkeys provide a secure, user-friendly experience while significantly reducing phishing risk.
- Hardware security keys for critical users: Administrators, executives, and privileged users often benefit from additional phishing-resistant authentication controls.
- Documented recovery processes: Identity security only works if users can regain access quickly and securely after device loss or replacement.
- Zero Trust-aligned governance: Authentication modernization should support broader governance, identity lifecycle management, and Conditional Access initiatives.
Why SMS and Voice MFA Are No Longer Enough
Organizations have relied on SMS authentication for years because it’s familiar and easy to deploy. Unfortunately, attackers have adapted.
Many of the authentication methods organizations still trust today remain vulnerable to the very threats Microsoft is trying to address through passkeys.
Teams looking to understand the growing threat landscape should review these common phishing tactics and how attackers continue to target users and credentials.
The reality is simple: if attackers can steal, intercept, trick, or socially engineer a credential, it’s no longer sufficient as your primary defense.
How NRI Helps Organizations Prepare
Organizations know they need to move away from SMS and voice MFA. The challenge is building a realistic roadmap.
NRI helps organizations prepare through:
- Security and MFA readiness assessments.
- Passkey deployment planning and rollout strategies.
- Phishing-resistant authentication roadmaps.
- Hardware security key implementation.
- Identity recovery process development.
- User awareness and adoption programs.
- Broader Zero Trust modernization initiatives.
Our team helps organizations assess their current environment, identify risks, and create practical plans that align technology, people, and security objectives.
Whether you’re evaluating your current authentication approach or conducting a broader security posture assessment, the key is starting before the deadlines begin driving urgency.
Get Started Before the Prompts
These changes are coming quickly and authentication modernization takes time.
User communications, pilot programs, device readiness, recovery planning, governance decisions, and support processes all require coordination across IT and security teams.
The organizations that begin now will have time to test, refine, and deploy passkeys on their terms. The organizations that wait may find themselves managing a large-scale authentication transition under a fixed deadline.
Microsoft’s announcement is more than a product update. It’s a clear signal that phishing-resistant authentication is becoming the new standard.
Organizations that embrace that change today can strengthen security, improve user experience, and accelerate their Zero Trust journey.
Talk to our team today and develop a strategy for phishing-resistant authentication.


