Microsoft Is Changing How You Sign In - Has Your IT Team Told You? 🔑
- Aug 26
- 3 min read
If your organisation uses Microsoft 365, there’s a change coming that your users are likely to notice.
From September 2026, Microsoft is moving users towards passkeys, with passkey registration becoming the default experience for users currently relying on SMS or voice authentication. And from February 2027, Microsoft-provided SMS and voice authentication is being retired. 📱

What's actually changing? 🔄
For many users, MFA has traditionally meant receiving a code by text message or phone call. Microsoft is now moving towards passkeys and other phishing-resistant authentication methods instead. From 1 September 2026, users in scope may start being prompted to register a passkey. Then, from 1 February 2027, Microsoft-provided SMS and voice authentication will be retired.
In simple terms: SMS codes are going out. Passkeys are coming in. 🔑
Why is Microsoft making the change? 🛡️
SMS and voice authentication are convenient, but they're not the strongest form of protection against modern attacks such as phishing and social engineering. Passkeys offer a more secure approach, using your device and methods such as a PIN, fingerprint or facial recognition to prove who you are. And for users, it can actually make signing in easier.
Instead of: Password → SMS code → enter code
It becomes: Sign in → fingerprint / face / PIN → you're in.
What does your business need to do? 📋
The biggest mistake would be to wait until the changes are enforced and hope everything works itself out. Your IT team should already be thinking about:
🔍 Identifying users still relying on SMS or voice authentication.
📢 Letting users know what is changing and why.
📖 Providing simple guidance on registering and using a passkey.
🧪 Testing the experience across your devices and users.
🔐 Making sure appropriate recovery and alternative authentication methods are available.
👥 Preparing your support team for the questions users will inevitably have.
This isn't just an IT configuration change - it's a user change too. If someone suddenly sees a Microsoft prompt asking them to register a passkey without any warning, they're much more likely to think something has gone wrong.
Not ready for September? ⏳
If your IT team hasn't started yet, there is a little breathing room. Microsoft has provided a mechanism to delay the automatic passkey enablement and registration campaign until February 2027, using Microsoft Graph and PowerShell.
That can give organisations more time to prepare their users, test the experience and put proper guidance in place.
But it's important to see this as a delay, not a way out. The February 2027 retirement of Microsoft-provided SMS and voice authentication is still coming.
So… has your IT team got this covered? 👀
This is one of those changes that can easily slip under the radar. But with thousands of users relying on Microsoft 365 every day, a poorly planned authentication change can quickly become a support headache. The organisations that get ahead of it will be the ones that communicate early, prepare their users and make the transition feel simple.
Need a hand getting ready? 🤝
At Mondo Cloud, we help organisations get more from Microsoft 365 - from Microsoft Entra and security through to automation, AI and the wider modern workplace. If you're not sure who in your organisation is still using SMS authentication, what needs changing, or how to prepare your users, we're happy to help.
Get in touch and let's make sure you're ready.
0800 640 4258

