Microsoft is making passkeys the default Microsoft 365 login from 1 September… SMS codes are on the way out.
If your team signs into Microsoft 365 with a password plus a text, next week will feel a bit different. From 1 September 2026, Microsoft starts making passkeys the default way to prove who you are. Staff who still use SMS authentication will be asked to register a passkey the next time they complete Microsoft 365 MFA. You can skip the prompt for now. However, that breathing space does not last forever.
Here is the timetable in plain English. On 1 February 2027, Microsoft will stop providing its own SMS and voice call verification. After that, anyone whose only extra check is a text or a phone call will hit a blocking screen. They will need a passkey to get back into email, Teams, or SharePoint. So treat September as a rehearsal, not a surprise.
Why the change?
Text message codes did a useful job for years. They got millions of people onto two-step verification when they had nothing else. Meanwhile, attackers have caught up. SIM swapping, fake login pages, and AI-written phishing emails can intercept a one-time code or trick someone into entering it into the wrong field. If that sounds familiar, we have already written about how those emails are getting sharper in our guide to AI phishing attacks.
Passkeys work differently. They sit on a trusted device and use a private key that never gets typed into a website. As a result, a fake Microsoft page cannot harvest the secret the way it can harvest a password or a six-digit code. In addition, people approve with a fingerprint, face scan or PIN instead of hunting for a late text. That is the point of phishing-resistant authentication: a phishing-proof login without the extra faff.
The National Cyber Security Centre now recommends passkeys wherever a service supports them. You can read that in plain English on the NCSC passkeys page. Microsoft’s own timeline, including the SMS authentication retirement, sits on Microsoft Learn.
What will people actually see?
For most offices this is not a big-bang cutover. From 1 September, Microsoft will automatically enable passkeys for users who currently have SMS or voice switched on. The next time those people complete MFA, they will see a nudge to register a passkey. By default, they can snooze it. Furthermore, people who already use Microsoft Authenticator, Windows Hello or FIDO2 security keys can keep using those methods. Passwordless sign-in is already there for them.
The risk is not the technology. The risk is an unbriefed inbox. Picture a busy Monday in accounts: a passkey prompt appears, someone clicks away, then rings because “Microsoft has locked me out.” A five-minute note this week prevents that. Tell people what they will see, that they can skip it for now, and that a quiet afternoon is a better moment than a client call.
A short, practical order of work
First, find out who still relies on SMS authentication or voice call verification. In a Microsoft 365 tenant, that is a settings job, not a guess. Second, pick the method that fits how people work. A synced passkey on a phone suits most hybrid staff. A device-bound passkey in Microsoft Authenticator, or a FIDO2 hardware key, suits administrators and anyone who handles payroll. Third, start with global admins, finance, and anyone with access to the whole mailbox estate. Strong authentication belongs there first.
In addition, plan the boring bits that usually cause the delay: lost phones, shared PCs on a shop floor, and staff on a home laptop the business does not manage. Therefore write down who people should call, and test that route with two or three friendly guinea pigs before you roll it out more widely.
Meanwhile, keep your other Microsoft 365 MFA methods in good shape. Authenticator-app approvals still beat text messages. And if you want the wider picture of how multi-factor authentication fits with Cyber Essentials and day-to-day logins, our MFA page is here.
Three things before 1 September
Tell staff that a passkey prompt may appear after they sign in, and that it is genuine Microsoft behaviour, not a scam. Ask IT support, in-house or a partner, to list who still uses SMS or voice codes. Register passkeys for administrators first, then run a small pilot with a friendly team.
The era of “text me a code” is ending for a good reason. Get ahead of the prompt, and your team will barely notice the upgrade. Leave it to chance, and February 2027 will feel a lot closer than it looks.