Overview of the change
In a recent webinar, Nick Ross [MVP] (T-Minus365) explained how Microsoft is shifting authentication in Entra away from SMS and voice and toward stronger, phishing-resistant options such as passkeys. Consequently, administrators and managed service providers should treat this as a planned, enforced change rather than an optional recommendation. Ross laid out clear timelines and practical implications so IT teams can prepare without surprises.
First, Microsoft will automatically enable passkeys for users relying on phone-based methods starting on September 1, 2026, and then fully retire its built-in SMS and voice delivery on February 1, 2027. After the retirement date, tenants that must keep phone-based delivery will need a customer-managed telecom provider from the Microsoft store to continue using phone factors. Therefore, organizations that do not act will see native phone factors stop working and should expect enforced registration flows for stronger methods.
Technical and administrative details
Ross emphasized that this change affects both MFA and SSPR flows in Entra, and that some legacy settings can make migration trickier than administrators expect. Notably, certain SSPR configurations can still allow SMS even when legacy MFA options appear disabled, which raises the risk of surprise exceptions during rollout. As a result, teams must audit both modern and legacy configurations to find users who remain reachable only by phone.
Moreover, the forced behavior includes a blocking prompt for users whose only recovery or authentication method is SMS or voice, requiring them to register a passkey to continue signing in. To manage this more gracefully, Microsoft offers the Authentication Methods Policy and registration campaign controls that can stage adoption. Administrators should also evaluate alternatives such as the Microsoft Authenticator, device-bound or synced passkeys, and FIDO2 security keys depending on user devices and security needs.
Tradeoffs and practical challenges
On one hand, moving to passkeys and other phishing-resistant methods significantly improves protection against interception and SIM swap attacks, and thus reduces account compromise. On the other hand, this shift introduces user friction during the transition and may increase short-term support volume, especially for users with older phones, limited device capabilities, or poor connectivity. Therefore, IT teams must balance the immediate operational cost of migration against the long-term security gains.
In addition, relying on a third-party telecom integration after retirement brings new operational and cost tradeoffs, because a customer-managed telecom provider requires procurement, regional compatibility checks, and ongoing management. Likewise, regulatory or accessibility requirements in certain regions might limit how quickly an organization can remove phone-based fallbacks. Consequently, decision makers should consider phased approaches and exceptions for high-risk or constrained user populations.
Recommended migration steps
Ross recommends that administrators begin with a thorough inventory to identify accounts still registered for or relying on SMS and voice, and to check for unexpected re-enabling of phone factors via SSPR settings. Next, organizations should centralize control in the Authentication Methods Policy rather than continue to rely on legacy MFA settings, because the modern policy enables clearer rollout controls. In practice, this inventory-driven approach helps prioritize pilots and preserves access for users who need time to transition.
Then, pilot deployments and registration campaigns help reduce disruption by prompting users to adopt passkeys or alternative phishing-resistant methods in a measured fashion. Ross explains how administrators can delay or temporarily opt out of the automatic passkey enablement for controlled groups, while preparing broader adoption for the September 2026 milestone. Finally, teams should document an exception process and determine whether any group needs a telecom integration after the February 2027 retirement.
What IT teams should expect
Expect a phased program that combines technical changes with a communication plan, because the most successful migrations balance security, usability, and timing. In particular, help desks should prepare for an initial surge of support requests, and communication templates can reduce confusion by offering clear steps for end users; the original webinar included template examples and resources to support that work. Over time, however, the shift to phishing-resistant factors should lower incident rates and credential-based risk.
In short, Nick Ross’s guidance frames this as a manageable project rather than a sudden emergency: start with discovery, pilot carefully, and use registration campaigns to limit disruption while meeting Microsoft’s timeline. Ultimately, organizations that plan now will gain stronger protection and avoid last-minute scramble when native phone delivery ends. Therefore, IT teams should inventory their tenants, run targeted pilots, and prepare communications so the transition is secure and user-friendly.
