All Posts

Microsoft Entra Passkeys and SMS MFA Retirement: What Small Businesses Should Do Before 2027

8 September, 2026
#Managed IT
#Cybersecurity
#Microsoft 365
Microsoft Entra passkeys and Microsoft 365 MFA migration planning for small businesses

Microsoft Entra Passkeys and SMS MFA Retirement: What Small Businesses Should Do Before 2027

Many small businesses added multi-factor authentication to Microsoft 365 because cyber insurance applications, security advice, and real-world phishing incidents made the need obvious.

That was the right move.

But MFA is changing. Microsoft Entra ID is moving away from weaker, phishable authentication methods and toward passkeys as the default sign-in experience. For small and midsize businesses, this is not only a security announcement. It is an operational planning issue.

If employees still rely on text messages or phone calls for Microsoft 365 MFA, the business needs a migration plan before those methods become a support problem.

Microsoft says that on September 1, 2026, users who are enabled for SMS or voice authentication in Entra ID will be automatically enabled for passkeys and nudged to register them. On February 1, 2027, Microsoft-provided SMS and voice delivery will be retired in Microsoft Entra ID. After that date, users whose only available MFA method is SMS or voice will receive a blocking prompt to register a passkey before they can continue signing in, unless the organization has configured a customer-managed telecom provider for a legitimate operational need.

The security direction is sensible. The risk for small businesses is waiting until employees are confused, remote users are blocked, executives cannot access email, or the help desk is flooded with urgent sign-in problems.

Why This Topic Is Timely

Microsoft is tightening identity security across Entra ID and Microsoft 365 because attackers keep targeting sign-in workflows, not only passwords.

In the first quarter of 2026, Microsoft Threat Intelligence reported approximately 8.3 billion email-based phishing threats, with QR code phishing more than doubling by the end of the quarter and credential phishing remaining a dominant objective. Microsoft also describes business email compromise as phishing that uses trusted-looking senders to trick people into approving payments, transferring funds, or revealing customer data.

For small businesses, that connects directly to Microsoft 365 identity. A compromised Microsoft 365 account can expose email, Teams chats, OneDrive files, SharePoint content, invoices, vendor conversations, customer data, and administrator settings. If attackers can steal credentials, relay a login, abuse a weak MFA method, or pressure an employee into approving access, they may be able to turn a sign-in event into invoice fraud or data exposure.

Microsoft's passkey shift also follows other identity hardening moves. Microsoft has been enforcing MFA for admin portals, and as of July 1, 2026, new Microsoft Entra tenants block device code flow as part of security defaults. The trend is clear: identity controls that once felt optional are becoming expected baseline security.

The buyer-relevant keyword cluster behind this post is Microsoft Entra passkeys, Microsoft 365 SMS MFA retirement, voice MFA retirement, passkeys for Microsoft 365, phishing-resistant MFA, Microsoft 365 account takeover, identity protection for small business, and Microsoft 365 security planning.

This is not a vanity topic. It affects daily access, email security, help-desk readiness, cyber insurance posture, executive protection, and buyer trust.

What Is Actually Changing

There are two dates small businesses should understand.

September 1, 2026: Passkeys Become the Default Direction

Microsoft says users enabled for SMS or voice will be auto-enabled for passkeys in the Entra authentication methods policy and prompted through a registration campaign when they sign in and complete MFA.

That does not mean every user is magically ready. Employees may still need supported devices, clear instructions, backup methods, and help understanding what a passkey is.

The best time to prepare is before users see new prompts and start guessing.

February 1, 2027: Microsoft-Provided SMS and Voice Are Retired

Beginning February 1, 2027, Microsoft-provided SMS and voice delivery will be retired in Microsoft Entra ID. Microsoft says there is no opt out for this February behavior.

Users whose only available MFA method is SMS or voice will have to register a passkey during sign-in before they can continue. Organizations that truly need SMS or voice for specific regulatory, technical, or operational reasons can evaluate customer-managed telecom providers through the Microsoft Security Store, but Microsoft recommends passkeys as the primary path where possible.

For many small businesses, the practical answer will be: move users to passkeys, Windows Hello for Business, FIDO2 security keys, or another phishing-resistant method before the deadline.

Why SMS and Voice MFA Are Being De-Emphasized

SMS and voice MFA are better than no MFA, but they are not the strongest option.

They can be exposed to:

  • SIM swap and phone-number takeover risk
  • social engineering against mobile carriers or help desks
  • phishing pages that ask users to type one-time codes
  • MFA relay attacks
  • employees approving or sharing codes during stressful calls
  • unreliable phone coverage for remote or traveling users
  • phone number changes that break account recovery

Passkeys use cryptographic authentication instead of a shared code that an employee can type into a fake page. When deployed correctly, they are designed to be phishing-resistant because the credential is tied to the legitimate service.

That matters because Microsoft 365 compromise usually does not stay limited to "someone logged in." It can become:

  • mailbox surveillance
  • malicious inbox rules
  • invoice redirection
  • customer or vendor impersonation
  • SharePoint and OneDrive data exposure
  • Teams reconnaissance
  • OAuth app abuse
  • MFA method changes
  • administrator account compromise
  • ransomware preparation

Strong authentication reduces the chance that a stolen password or tricked employee becomes a business-impacting incident.

What a Passkey Means in Practical Terms

A passkey is a passwordless credential based on public-key cryptography. The user proves they are allowed to sign in using a device unlock method such as Windows Hello, Face ID, fingerprint, PIN, Microsoft Authenticator, a platform credential manager, or a FIDO2 security key, depending on the organization's configuration.

For Microsoft 365 users, this can feel simpler than typing a password and waiting for a text code. But the rollout still needs planning.

Small businesses should decide:

  • which passkey types are allowed
  • which users should use device-bound credentials
  • which users can use synced passkeys
  • whether high-risk users need hardware security keys
  • how Windows, macOS, iOS, and Android users will register
  • what happens when a phone or laptop is replaced
  • how new employees prove identity during onboarding
  • how the help desk verifies MFA reset requests
  • how emergency access accounts are protected

The technology is only one piece. The business process around registration, recovery, and support is just as important.

Who Should Migrate First

Most small businesses should not treat this as a one-day tenant-wide switch. A phased rollout is safer.

Start with the users where account compromise would cause the most damage:

  • owners and executives
  • finance and payroll users
  • Microsoft 365 administrators
  • IT administrators and MSP access accounts
  • HR users
  • employees who approve vendor payment changes
  • users with broad SharePoint, OneDrive, or Teams access
  • customer-facing users with sensitive mailboxes
  • remote users who frequently sign in from new locations
  • break-glass accounts, with careful separate handling

These are the accounts attackers value most. They are also the accounts that should not be surprised by a new sign-in requirement during payroll, month-end close, a client deadline, or an incident.

The Small Business Migration Plan

A clean migration does not have to be complicated. It does need ownership.

1. Find Users Still Using SMS or Voice

Start with visibility.

Review authentication methods in Microsoft Entra ID and identify users who still have SMS or voice enabled. Separate occasional backup usage from users who depend on those methods every day.

Pay special attention to:

  • executives
  • finance users
  • administrators
  • shared operational roles
  • remote employees
  • employees with older phones or computers
  • users who frequently need help signing in
  • guest or external collaboration scenarios

Do not assume the tenant is ready because "MFA is enabled." The question is which methods people actually use.

2. Choose the Right Credential Pattern

Different users may need different options.

For many standard users, synced passkeys or platform credentials may be practical. For administrators, finance users, and highly sensitive roles, FIDO2 security keys or device-bound credentials may be more appropriate. For Windows-heavy environments, Windows Hello for Business may fit naturally. For mobile-heavy users, passkeys in Microsoft Authenticator may be useful.

The business should document the standard choice and the approved exceptions.

Avoid creating a confusing menu where every user makes their own security decision. That usually leads to inconsistent support and weak recovery habits.

3. Pilot Before Broad Rollout

Pick a small pilot group that represents the real business:

  • one administrator
  • one finance user
  • one executive or manager
  • one remote worker
  • one mobile-heavy user
  • one user with older hardware, if that exists
  • one person who commonly needs support

Test registration, daily sign-in, Outlook, Teams, SharePoint, OneDrive, mobile apps, browser sign-in, device replacement, password reset, and MFA reset procedures.

The pilot should answer practical questions before the entire company is affected.

4. Communicate in Plain Business Language

Employees do not need a lecture on cryptography. They need to know what is changing, why it matters, what they should do, and how to get help.

Good communication should say:

  • Microsoft is moving away from SMS and phone-call MFA.
  • The business is moving to stronger sign-in methods before the deadline.
  • Employees should not approve prompts or register methods they did not initiate.
  • The help desk will never ask for a one-time code.
  • MFA reset requests must follow a verified process.
  • Users should report unexpected sign-in prompts immediately.

This matters because attackers may use the transition itself as a lure. A fake "register your passkey" email or call could be used to steal credentials if employees are not told what the real process looks like.

5. Protect the Help Desk Process

Identity security often fails at the reset desk.

If an attacker cannot phish a passkey directly, they may call the business and pretend to be an employee who lost a phone, changed devices, or needs urgent MFA reset help.

Before rolling out passkeys, define how support will verify a user before:

  • resetting MFA methods
  • issuing a Temporary Access Pass
  • adding a new device
  • replacing a security key
  • changing recovery information
  • helping an executive or finance user regain access

The verification process should be stronger for higher-risk users. A rushed phone call should not be enough to reset the identity controls protecting company email and financial workflows.

6. Keep Backup Access Planned, Not Improvised

Users need a backup method. Microsoft recommends that users have at least two authentication methods registered so a lost or stolen device does not become an emergency.

That does not mean keeping weak methods everywhere forever.

The goal is managed resilience:

  • at least two approved methods where practical
  • documented lost-device procedures
  • separate handling for break-glass accounts
  • known inventory for hardware keys
  • tested recovery for executives and administrators
  • clear offboarding steps that remove old credentials

Security that locks everyone out during a normal device replacement will not survive. Support that resets access too casually will not protect the business. The right answer is a documented middle path.

7. Review Conditional Access and Security Defaults

Passkeys are strongest when the rest of the identity environment supports them.

Review:

  • whether Security Defaults or Conditional Access is being used
  • which users and apps are in scope
  • administrator and high-risk user policies
  • trusted location exceptions
  • device code flow exposure
  • legacy authentication and older mail protocols
  • unmanaged device access
  • risky sign-in review ownership
  • authentication method policies
  • report-only policies that should be enforced

This is where many small businesses need help. The interface may say MFA is present, while exceptions, old methods, special flows, or unmanaged devices still leave practical gaps.

Email Security Still Matters

Passkeys reduce account takeover risk. They do not make email threats disappear.

Small businesses should continue strengthening Microsoft 365 email security with:

  • anti-phishing policies
  • impersonation protection where licensed
  • spoof intelligence review
  • SPF, DKIM, and DMARC alignment
  • safe link and attachment protection where licensed
  • external sender labeling where appropriate
  • mailbox rule and forwarding monitoring
  • user reporting workflows
  • finance approval verification
  • account compromise response procedures

Identity and email security belong together. A phishing email often starts the incident. A Microsoft 365 identity lets the attacker move through the business. A mailbox gives the attacker context for fraud.

Treat passkey migration as part of a broader Microsoft 365 security review, not as a standalone checkbox.

Common Mistakes To Avoid

Small businesses can make this transition harder than it needs to be.

Avoid these mistakes:

  • waiting until February 2027 to find SMS-only users
  • assuming all employees understand passkeys
  • failing to test older devices and mobile workflows
  • leaving executives and finance users for last
  • keeping help-desk reset procedures informal
  • allowing every authentication method because it feels easier
  • forgetting shared devices and frontline workflows
  • ignoring guest and external collaboration users
  • not documenting hardware security key ownership
  • treating passkeys as a replacement for monitoring
  • using cyber insurance questionnaires as the only security roadmap

The point is not to chase every Microsoft security feature at once. The point is to reduce the identity paths attackers are most likely to exploit while keeping the business able to work.

A Practical Readiness Checklist

Use this checklist before the September 2026 registration push becomes background noise and before the February 2027 retirement becomes a support problem.

  • Inventory users enabled for SMS or voice MFA.
  • Identify users whose only practical MFA method is SMS or voice.
  • Prioritize administrators, finance, executives, HR, and high-access users.
  • Decide which passkey and phishing-resistant methods the business will support.
  • Confirm device readiness across Windows, macOS, iOS, and Android.
  • Pilot the rollout with real user types.
  • Create end-user communication before prompts appear.
  • Define the MFA reset and identity verification process.
  • Plan backup authentication methods.
  • Review Conditional Access or Security Defaults.
  • Check legacy authentication and device code flow exposure.
  • Review mailbox rule, forwarding, and suspicious sign-in monitoring.
  • Update onboarding and offboarding procedures.
  • Document exceptions with owners and review dates.
  • Schedule a follow-up review after rollout.

This is manageable when it is planned. It becomes disruptive when it is discovered during a lockout.

What CybarWorks Recommends

Small and midsize businesses should use the Microsoft Entra passkey transition as a forcing function to clean up Microsoft 365 identity security.

The highest-value actions are straightforward:

  1. Find every user still dependent on SMS or voice MFA.
  2. Move high-risk users to phishing-resistant methods first.
  3. Protect the help desk and MFA reset process.
  4. Review Conditional Access, Security Defaults, legacy authentication, and device code flow.
  5. Keep email security and mailbox compromise monitoring in the same conversation.
  6. Document the rollout so employees know what is real and what might be phishing.

CybarWorks helps small and midsize businesses secure Microsoft 365 without turning sign-in into chaos. We can review your tenant, identify weak authentication methods, plan a passkey migration, tighten Conditional Access, improve email security, and build practical processes for onboarding, offboarding, MFA resets, and account compromise response.

If your business still depends on SMS or phone-call MFA in Microsoft 365, contact CybarWorks. We can help you move to stronger identity protection before the deadline turns into a disruption.

Works Cited

Ready to transform your business with our IT expertise?