Microsoft began automatically migrating Entra ID users from SMS and voice multi-factor authentication (MFA) to passkeys on 1 September 2026.
Starting September 1, 2026, tenants with users set up for text or phone-call codes will have those users automatically enabled for passkeys, and Microsoft will begin nudging them to register one at their next sign-in.
For Kent SMEs running Microsoft 365, this means staff who currently use text messages or voice calls for MFA will be prompted to register a passkey—potentially during their next login. If your organisation has not prepared staff or configured Entra ID passkey policies, you may face support tickets and login confusion within days.
Why Microsoft Is Retiring SMS and Voice MFA in Entra ID September 2026
Microsoft is ending its provision of SMS and voice call MFA methods because they are inherently less secure than modern alternatives.
Microsoft has published firm dates for ending Microsoft-provided SMS and voice multifactor authentication in Entra ID, the service behind your Microsoft 365 logins.
SMS-based authentication remains vulnerable to SIM-swapping attacks, interception, and social-engineering exploits. Voice calls face similar risks.
This change aligns with Microsoft’s broader push toward passwordless authentication for UK SMEs, a strategy that significantly reduces credential-based breach risks. Given that
credential-based attacks account for over 60% of breaches
, the migration to passkeys represents a material improvement in security posture for organisations that implement it properly.
What Happens from 1 September 2026: The Automatic Passkey Registration Process
From 1 September 2026, any user in your Entra ID tenant who currently has SMS or voice MFA as their primary or backup authentication method will be automatically enabled for passkey registration. The next time they sign in to a Microsoft service, they will be prompted to register a passkey using their device—typically via Windows Hello, Face ID, Touch ID, or a FIDO2 security key.
If users decline or skip the registration prompt, they will continue to see it at subsequent sign-ins. However, Microsoft has not specified a hard cut-off date when SMS and voice MFA will stop working entirely, meaning organisations have a brief window to manage this transition proactively rather than reactively.
What UK SMEs Must Do Before Staff Start Receiving Passkey Prompts
- Audit current MFA methods in Entra ID: Identify which users rely on SMS or voice authentication. In the Microsoft Entra admin centre, navigate to Users → Authentication methods to review per-user MFA settings.
- Enable passkey authentication policies: Ensure the passkey (FIDO2) authentication method is enabled in your tenant under Protection → Authentication methods → Policies. Configure which users or groups are permitted to register passkeys.
- Communicate the change to staff immediately: Send a brief email or Teams message this week explaining that some users will be prompted to register a passkey at their next login. Include simple instructions on what to expect and how to register using Windows Hello or their mobile device.
- Update your IT support documentation: Prepare step-by-step passkey registration guides for Windows, macOS, iOS, and Android devices. Anticipate support requests from users unfamiliar with biometric or hardware-based authentication.
- Test passkey registration with a pilot group: Before the prompts roll out widely, have a small group of technically confident users register passkeys and provide feedback on any friction points.
How This Migration Relates to Other Security Changes UK SMEs Are Facing
This passkey migration is one of several authentication and security changes UK SMEs must navigate in the second half of 2026. As covered in our recent analysis of Business Email Compromise overtaking ransomware as the top UK financial threat, credential theft and account takeover remain the dominant attack vectors. Passkeys directly address this risk by eliminating shared secrets (passwords and SMS codes) that attackers can intercept or phish.
Similarly, organisations that have been deferring MFA improvements due to user-experience concerns should note that
the most common reasons cited for not enforcing MFA were ‘concerns about staff disruption’ (44%), ‘not sure how to implement it’ (31%), and ‘hadn’t prioritised it yet’ (25%).
The automatic migration from SMS to passkeys removes the “not sure how to implement” barrier—Microsoft is now forcing the decision.
This change also intersects with the wider patching and update discipline UK SMEs must maintain. Microsoft’s recommendation to deploy Windows updates within three days reflects the same underlying pressure: the threat environment is accelerating, and reactive security postures no longer suffice.
Passkey Registration Options for UK SME Staff
When prompted to register a passkey, users will typically have several options depending on their device and operating system:
- Windows Hello (Windows 10/11): Uses facial recognition, fingerprint, or PIN tied to the device’s TPM chip. Most modern Windows laptops and desktops support this natively.
- Face ID or Touch ID (macOS, iOS): Apple devices registered to the user’s iCloud account can serve as passkeys, allowing biometric authentication across devices.
- Android biometrics: Newer Android devices (running Android 9 or later with compatible hardware) support passkey registration using fingerprint or face unlock.
- FIDO2 security keys: Physical USB, NFC, or Bluetooth security keys (such as YubiKey or Google Titan) offer the highest level of phishing resistance and are ideal for high-privilege accounts or users who work across multiple devices.
For Kent SMEs issuing company devices, the simplest path is enabling Windows Hello on corporate laptops and educating users on registration during onboarding. For organisations with a mix of personal and company devices (common under flexible-working arrangements), a policy decision is required on whether to permit personal devices as passkey authenticators.
What Happens to Users Who Cannot Register a Passkey
Some users may not have compatible hardware (older laptops without TPM 2.0, basic Android phones without biometric sensors). In these cases, organisations should configure fallback authentication methods that maintain security while avoiding SMS and voice calls.
Microsoft Authenticator app push notifications remain a secure alternative and work on nearly all smartphones. Administrators can configure Entra ID to require Authenticator as the primary method, with passkeys as the preferred option for compatible devices. Time-based one-time passwords (TOTP) generated by Authenticator or other apps also remain supported.
Critically, do not revert to SMS or voice MFA simply because a user finds passkey registration unfamiliar. The security gap is too significant, and
43% of UK businesses experienced a cyber breach or attack in the last 12 months
—most of which involved credential compromise.
Next Steps for Kent SMEs This Week
The automatic passkey migration began on 1 September 2026, meaning the prompts are already appearing for some users. To avoid disruption and ensure a smooth transition, Meridian Micro recommends Kent SMEs take the following actions this week:
- Review Entra ID authentication method policies and enable passkeys for all user groups
- Send immediate staff communication explaining the change and linking to simple registration instructions
- Prepare IT support with scripted responses and device-specific troubleshooting steps
- Identify any users on legacy hardware and plan hardware refresh or interim Authenticator-based MFA
- Document the new authentication flow in your onboarding and offboarding procedures
This migration is not optional, and deferring preparation will only create support burden later. The shift to passkeys represents a significant security improvement, but only if implemented with clear communication and technical readiness.
If your organisation needs assistance configuring Entra ID passkey policies, auditing current MFA settings, or training staff on passwordless authentication, Meridian Micro offers fixed-scope consultancy and hands-on support for Kent SMEs. Call our team on 01303 883111 to discuss your migration plan and ensure your business is ready for passwordless authentication in 2026.