Microsoft Passkey: How to Opt Out
Microsoft Entra
10. Aug 2026 17:13

Microsoft Passkey: How to Opt Out

von HubSite 365 über Jonathan Edwards

No-Faffing Managed IT Support & Cyber Security Support. Made in Yorkshire, built for the UK.

Microsoft expert: delay Passkeys rollout with a Graph beta opt out via Entra Auth Admin to buy migration time

Key insights

  • Passkey opt-out: Use the single Microsoft Graph command passkeyDynamicMigration to pause Microsoft’s September passkey rollout for your tenant.
    This step delays user registration prompts but does not cancel the overall migration timeline.
  • Key dates: API support available from 2026-08-01, rollout starts 2026-09-01, and Microsoft-provided SMS/voice retires on 2027-02-01.
    Plan any pause as a short window before the retirement deadline.
  • Admin checks: Verify your tenant state first using read-only checks before applying the opt-out.
    The control follows least privilege and uses the Authentication Policy Admin role instead of Global Admin for safer delegation.
  • What the opt-out does and does not do: It postpones the passkey enablement and the Registration Campaign for September but does not extend the February 2027 SMS/voice retirement or remove passkey features from Entra.
    Use it to buy migration time, not as a permanent solution.
  • Operational steps to consider: Use the pause to migrate users, set up customer-managed telecom or paid providers, update policies, and prepare user communications.
    Be aware registration prompts can become blocking by the February retirement date for tenants relying on Microsoft SMS/voice.
  • Risks and testing: The opt-out endpoint is a beta endpoint, so test the command in a staging tenant and document changes before applying to production.
    Apply changes deliberately and monitor impacts rather than relying on Microsoft to make the choice for you.

Summary of the video

In a recent YouTube video, Jonathan Edwards explains how administrators can temporarily delay Microsoft’s new default authentication flow that pushes users toward passkeys. The video frames the change as a scheduled nudge from Microsoft that begins on September 1, 2026, while stressing that this option only pauses the initial rollout rather than cancels the long-term plan. Edwards highlights a single Microsoft Graph setting named passkeyDynamicMigration and shows how a tenant can use it to opt out for a limited window. Consequently, he warns administrators to act deliberately and to understand the limits of the control before relying on it.


What the opt-out actually does

Edwards explains that the opt-out delays the automated registration prompts and the broader push to make passkeys the default path in Microsoft Entra. However, the video makes clear that the opt-out does not remove passkeys from Entra, nor does it stop Microsoft’s overall plan to retire its own SMS/voice authentication services. Instead, this control temporarily prevents Microsoft from auto-enabling the registration campaign on a tenant during the specified period, giving IT teams breathing room to prepare.


He also emphasizes that the opt-out is accessible via an API and is intended for targeted use, not as a permanent policy replacement. Moreover, Edwards points out that the command touches authentication rollout scheduling and is surfaced on a beta endpoint, which carries its own risks for production environments. Therefore, administrators must weigh the convenience of a single command against the potential instability of relying on a beta API.


Timeline and limits to keep in mind

According to the video, Microsoft published a timeline where API support and opt-out details start on August 1, 2026, the automated rollout begins on September 1, 2026, and the retirement of Microsoft-provided SMS/voice authentication takes effect on February 1, 2027. Edwards underscores that the opt-out window only delays activity through February 1, 2027, and that after that date tenants relying solely on Microsoft’s SMS/voice will face enforced changes. In short, the opt-out buys time but it does not change the final retirement date, so planning must account for the February deadline.


Tradeoffs and operational challenges

The video engages with several tradeoffs administrators should consider, starting with user experience versus administrative control. On one hand, postponing prompts can reduce confusion for end users and provide time for communications and training, but on the other hand it prolongs reliance on legacy verification paths that Microsoft plans to retire. Edwards also highlights a governance tradeoff: the permission to run the opt-out is assigned to the Authentication Policy Admin role rather than the Global Admin role, which is a least-privilege design but requires careful role assignment and auditing.


Additionally, the choice introduces technical and compliance challenges because some organizations will need to integrate paid, customer-managed telecom providers or move users to other modern authentication methods. Edwards warns that using a beta Graph endpoint and a single command to delay rollout can introduce uncertainty into larger change programs, especially if administrators skip checks or neglect a coordinated migration plan. Therefore, teams must balance the short-term benefit of delay against the long-term work to replace retired services.


Practical recommendations for administrators

Edwards recommends that IT teams treat the opt-out as a tactical tool, not a strategic solution, and to use it only after verifying tenant state and migration readiness. He suggests confirming which users and authentication methods are in scope and ensuring the necessary roles are in place so the opt-out can be applied and later reversed without disruption. As a next step, administrators should inventory dependencies on Microsoft-provided SMS/voice and evaluate alternatives, including passkeys, customer-managed telecom, or other methods that meet their security and compliance needs.


Finally, Edwards advises documenting every decision and running any changes deliberately so that Microsoft does not make the timing choice for you. He stresses the value of testing the opt-out in a controlled environment, communicating the plan to stakeholders, and preparing a migration timeline that aligns with the firm February deadline. By doing so, organizations can use the short delay effectively and reduce the operational risk of the broader transition.


Microsoft Entra - Microsoft Passkey: How to Opt Out

Keywords

delay Microsoft passkey rollout, opt out Microsoft passkeys, disable Microsoft passkey rollout, pause Windows passkey deployment, Microsoft passkey opt-out guide, stop passkey enforcement Windows, manage passkey rollout Microsoft 365, how to opt out of passkeys on Windows