01303 883111 info@meridian-micro.com Support Login
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
Security

Microsoft Entra ID SMS and Voice MFA Automatic Migration to Passkeys Starts 1 September 2026: What UK SMEs Must Do This Week

September 2, 2026 Meridian Micro

Microsoft began automatically migrating Entra ID users from SMS and voice multi-factor authentication (MFA) to passkeys on 1 September 2026.
Starting September 1, 2026, tenants with users set up for text or phone-call codes will have those users automatically enabled for passkeys, and Microsoft will begin nudging them to register one at their next sign-in.
For Kent SMEs running Microsoft 365, this means staff who currently use text messages or voice calls for MFA will be prompted to register a passkey—potentially during their next login. If your organisation has not prepared staff or configured Entra ID passkey policies, you may face support tickets and login confusion within days.

Why Microsoft Is Retiring SMS and Voice MFA in Entra ID September 2026

Microsoft is ending its provision of SMS and voice call MFA methods because they are inherently less secure than modern alternatives.
Microsoft has published firm dates for ending Microsoft-provided SMS and voice multifactor authentication in Entra ID, the service behind your Microsoft 365 logins.
SMS-based authentication remains vulnerable to SIM-swapping attacks, interception, and social-engineering exploits. Voice calls face similar risks.

This change aligns with Microsoft’s broader push toward passwordless authentication for UK SMEs, a strategy that significantly reduces credential-based breach risks. Given that
credential-based attacks account for over 60% of breaches
, the migration to passkeys represents a material improvement in security posture for organisations that implement it properly.

What Happens from 1 September 2026: The Automatic Passkey Registration Process

From 1 September 2026, any user in your Entra ID tenant who currently has SMS or voice MFA as their primary or backup authentication method will be automatically enabled for passkey registration. The next time they sign in to a Microsoft service, they will be prompted to register a passkey using their device—typically via Windows Hello, Face ID, Touch ID, or a FIDO2 security key.

If users decline or skip the registration prompt, they will continue to see it at subsequent sign-ins. However, Microsoft has not specified a hard cut-off date when SMS and voice MFA will stop working entirely, meaning organisations have a brief window to manage this transition proactively rather than reactively.

What UK SMEs Must Do Before Staff Start Receiving Passkey Prompts

How This Migration Relates to Other Security Changes UK SMEs Are Facing

This passkey migration is one of several authentication and security changes UK SMEs must navigate in the second half of 2026. As covered in our recent analysis of Business Email Compromise overtaking ransomware as the top UK financial threat, credential theft and account takeover remain the dominant attack vectors. Passkeys directly address this risk by eliminating shared secrets (passwords and SMS codes) that attackers can intercept or phish.

Similarly, organisations that have been deferring MFA improvements due to user-experience concerns should note that
the most common reasons cited for not enforcing MFA were ‘concerns about staff disruption’ (44%), ‘not sure how to implement it’ (31%), and ‘hadn’t prioritised it yet’ (25%).
The automatic migration from SMS to passkeys removes the “not sure how to implement” barrier—Microsoft is now forcing the decision.

This change also intersects with the wider patching and update discipline UK SMEs must maintain. Microsoft’s recommendation to deploy Windows updates within three days reflects the same underlying pressure: the threat environment is accelerating, and reactive security postures no longer suffice.

Passkey Registration Options for UK SME Staff

When prompted to register a passkey, users will typically have several options depending on their device and operating system:

For Kent SMEs issuing company devices, the simplest path is enabling Windows Hello on corporate laptops and educating users on registration during onboarding. For organisations with a mix of personal and company devices (common under flexible-working arrangements), a policy decision is required on whether to permit personal devices as passkey authenticators.

What Happens to Users Who Cannot Register a Passkey

Some users may not have compatible hardware (older laptops without TPM 2.0, basic Android phones without biometric sensors). In these cases, organisations should configure fallback authentication methods that maintain security while avoiding SMS and voice calls.

Microsoft Authenticator app push notifications remain a secure alternative and work on nearly all smartphones. Administrators can configure Entra ID to require Authenticator as the primary method, with passkeys as the preferred option for compatible devices. Time-based one-time passwords (TOTP) generated by Authenticator or other apps also remain supported.

Critically, do not revert to SMS or voice MFA simply because a user finds passkey registration unfamiliar. The security gap is too significant, and
43% of UK businesses experienced a cyber breach or attack in the last 12 months
—most of which involved credential compromise.

Next Steps for Kent SMEs This Week

The automatic passkey migration began on 1 September 2026, meaning the prompts are already appearing for some users. To avoid disruption and ensure a smooth transition, Meridian Micro recommends Kent SMEs take the following actions this week:

This migration is not optional, and deferring preparation will only create support burden later. The shift to passkeys represents a significant security improvement, but only if implemented with clear communication and technical readiness.

If your organisation needs assistance configuring Entra ID passkey policies, auditing current MFA settings, or training staff on passwordless authentication, Meridian Micro offers fixed-scope consultancy and hands-on support for Kent SMEs. Call our team on 01303 883111 to discuss your migration plan and ensure your business is ready for passwordless authentication in 2026.