Microsoft is making one of the most significant identity changes in recent memory this August 2026:
the company is making passkeys the default authentication method in Entra whilst simultaneously retiring SMS and voice call MFA options—an irreversible change that affects every user in your tenant
. For the
43% of UK businesses that experienced a cyber breach or attack in the last 12 months
, this shift to phishing-resistant authentication represents a critical security improvement, but it requires immediate planning and action from IT teams managing Microsoft 365 environments.
If your Kent SME relies on SMS text messages or voice calls as a second factor for Microsoft 365 authentication, you need to plan your migration to passkeys, authenticator apps, or hardware security keys now, before the legacy methods disappear from your tenant.
Why Microsoft Is Retiring SMS and Voice Call MFA in August 2026
SMS and voice call authentication have been security weak points for years. Attackers exploit these methods through SIM-swapping attacks, interception, and social engineering targeting mobile providers.
The NCSC (National Cyber Security Centre) recommends moving away from SMS-based MFA for all business-critical systems
, and Microsoft’s August 2026 enforcement finally makes this official policy rather than guidance.
The timing matters because
last month’s Microsoft 365 Message Center items were heavy on identity and access changes, most notably the retirement of SMS and voice MFA and the shift to passkeys as the default
. This is not a distant future change—it is happening now, in August 2026, and UK SMEs managing Microsoft 365 tenants need to act this month.
Passkeys offer phishing-resistant authentication that cannot be intercepted, stolen through social engineering, or compromised through SIM-swapping. Unlike SMS codes or voice calls, passkeys use cryptographic proof tied to specific devices and services, making them fundamentally more secure against the growing AI-driven threats targeting UK businesses in 2026.
What Changes for Microsoft 365 and Entra ID Users
The practical impact depends on how your organisation currently authenticates:
- SMS and voice call MFA will no longer be available as authentication factors once the retirement is enforced in your tenant
- Passkeys become the default authentication method for new users and fresh enrollments
- Existing users relying on SMS or voice calls must migrate to passkeys, authenticator apps (such as Microsoft Authenticator), or hardware security keys
- Administrator accounts face the highest priority for migration, as these represent the most valuable targets for attackers
For UK SMEs still using the older authentication methods, this is a mandatory transition.
The recommendation is to enforce 2-Step Verification (2SV) for all users and try to switch from SMS and push notifications to passkeys, authenticator apps or hardware security keys, especially for admins
.
Timeline and Tenant Rollout
As Microsoft adjusts timelines, keep an eye on your tenant’s rollout messages and update internal communications accordingly
. The Message Center in your Microsoft 365 admin portal will provide at least 30 days’ notice before these changes become active in your specific tenant, but August 2026 marks the general availability window.
If you have not yet received notification, check your Message Center now and review your current MFA configuration to understand which users are still relying on SMS or voice call authentication.
How UK SMEs Should Migrate to Passkeys This Month
The migration requires both technical configuration and user communication. Here is the practical action plan for Kent SMEs:
1. Audit Your Current MFA Configuration
Before you can migrate, you need to know where you are starting from:
- Log into the Microsoft Entra admin centre (formerly Azure AD)
- Navigate to Users → All users → Multi-Factor Authentication
- Review which authentication methods each user has registered
- Identify users still relying solely on SMS or voice call verification
- Pay particular attention to administrator accounts and service accounts
This audit shows you the scope of the migration and helps you prioritise which users need immediate attention.
2. Configure Passkey Support in Your Tenant
Microsoft 365 tenants need passkeys enabled in the authentication methods policy:
- In the Entra admin centre, go to Protection → Authentication methods
- Enable “Passkey (FIDO2)” for all users or specific security groups
- Configure whether passkeys can be used for both registration and authentication
- Set attestation requirements based on your security policies
If your organisation already has passkeys and passwordless authentication configured, you are ahead of the curve—now you need to ensure all users migrate from legacy methods.
3. Communicate the Change to Your Team
Users need clear, practical guidance about what is changing and what they must do:
- Explain why SMS and voice calls are being retired (security improvement, not arbitrary change)
- Provide step-by-step instructions for registering a passkey or authenticator app
- Set a deadline for migration—ideally at least one week before Microsoft’s enforcement date
- Offer IT support for users who encounter difficulties during enrollment
- Test the process yourself first so you can anticipate common issues
The transition will be smoother if users understand the “why” behind the change, not just the “what.”
4. Prioritise Administrator and Privileged Accounts
Administrator accounts represent the highest-value targets for attackers, so these should migrate first:
- Require all global administrators to register passkeys or hardware security keys immediately
- Enforce hardware security keys (such as YubiKey or similar FIDO2 devices) for the most sensitive roles
- Remove SMS and voice call options from administrator accounts before general enforcement
- Document the new authentication requirements in your security policies
For SMEs managing Microsoft 365 E3 licences or similar enterprise plans, this aligns with the broader shift toward Zero Trust security models that rely on strong, phishing-resistant authentication at every layer.
Alternative Authentication Methods Beyond Passkeys
Passkeys are the default and recommended method, but Microsoft supports other phishing-resistant options:
- Microsoft Authenticator app: Generates time-based one-time passwords (TOTP) and supports passwordless phone sign-in; widely compatible and easy to deploy across Windows, macOS, iOS, and Android devices
- Hardware security keys: Physical FIDO2 devices such as YubiKey, Google Titan, or Feitian keys; ideal for administrators and high-risk users who need maximum security
- Windows Hello for Business: Biometric authentication (face or fingerprint) tied to specific Windows devices; works well for organisations with Windows 11 devices and modern hardware
Each method has trade-offs in terms of cost, user experience, and deployment complexity. For most UK SMEs, a combination of passkeys and Microsoft Authenticator provides the best balance of security and usability.
What This Means for Wider Security and Patch Management
The retirement of SMS and voice call MFA is part of a broader pattern of accelerating security requirements across Microsoft 365.
The total number of vulnerabilities patched by Microsoft so far this year (1,380) has already surpassed 2020’s record-breaking year (1,250)
, and identity controls represent the first line of defence against these threats.
UK SMEs managing Microsoft 365 environments face an increasingly complex set of monthly updates, security changes, and configuration requirements. The MFA retirement sits alongside the Windows 10 feature freeze, Edge security update alerts, and Windows 11 Patch Tuesday changes as part of a sustained push toward higher baseline security standards.
For organisations that have historically treated SMS-based MFA as “good enough,” this August marks the end of that approach. The new baseline is phishing-resistant authentication, and it is now mandatory rather than optional.
How Meridian Micro Can Help Kent SMEs with Microsoft 365 Authentication Changes
Migrating authentication methods across an entire organisation requires technical expertise, user communication, and ongoing support. If your Kent SME needs assistance with the MFA retirement and passkey migration, Meridian Micro can help:
- Audit your current Microsoft 365 authentication configuration and identify users still relying on legacy methods
- Configure passkey support, authentication policies, and conditional access rules in your Entra ID tenant
- Provide clear, practical documentation and training for your team
- Offer ongoing support during the migration period to resolve enrollment issues and technical problems
- Review your wider security posture to ensure authentication changes align with broader IT security policies
The retirement of SMS and voice call MFA is not optional, and the deadline is approaching fast. Contact Meridian Micro today on 01303 883111 to ensure your Microsoft 365 environment is ready for the authentication changes arriving this month.
