Microsoft passkeys are replacing SMS codes: what UK businesses need to do

Passkeys became the Microsoft 365 default on 1 September 2026 and SMS codes retire on 1 February 2027. What UK businesses need to do.

Passkeys became the default way to sign in to Microsoft 365 on 1 September 2026, and Microsoft’s text-message and voice-call login codes retire for good on 1 February 2027. Here is what that means for a UK business, in plain English, and how to get through it without disruption.

In summer 2026, Microsoft announced the biggest change to how people sign in to Microsoft 365 in years. If you run a business on Microsoft 365, this has already started reaching every member of staff who proves who they are with a code sent by text. Nothing has stopped working yet, but the timetable is fixed and there is no opt-out at the end of it. The calm move is to plan now rather than wait for the blocking prompt in February.

What is changing, and when

The change applies to Microsoft Entra ID, the system behind Microsoft 365 sign-ins. Think of it as the reception desk for your Microsoft services: whenever someone opens Outlook, Teams or SharePoint, Entra ID checks they are who they say they are before letting them through.

Most businesses have strengthened that check with multi-factor authentication, or MFA: proving your identity in two ways, usually a password plus a one-time code sent by SMS or read out in a voice call. Those SMS and voice codes are what Microsoft is retiring, on this timetable:

Date What happens
1 September 2026 (already in effect) Passkeys became the default authentication method in Entra ID. Staff who sign in with SMS or voice codes are automatically enabled for passkeys and prompted to register one at their next MFA sign-in. The prompt can be snoozed during the transition, and SMS and voice codes keep working for now.
18 September 2026 Microsoft publishes details of the third-party telecom providers available to organisations that must keep SMS or voice.
30 October 2026 Configuration of a third-party provider becomes available in the Microsoft Security Store.
1 February 2027 Microsoft’s own SMS and voice authentication retire. Anyone whose only sign-in method is SMS or voice faces a blocking passkey registration prompt at sign-in, with no option to skip and no opt-out.

The dates come from Microsoft’s own SMS and voice retirement notice.

What is a passkey, and how is it different from a password or SMS code?

A passkey is a way of signing in without typing a password or a code. It is a digital key stored on something you own, usually your phone or your computer, and unlocked with the fingerprint, face scan or PIN you already use on that device.

The everyday comparison: an SMS code is like a door code, and anyone who overhears it can walk in with it. A passkey is like a physical door key that cannot be copied over the phone. Even if a criminal rings a member of staff with a convincing story, there is nothing to read out; the key never leaves the device and only works on the genuine Microsoft sign-in page.

In practice, most staff will hold their passkey in the Microsoft Authenticator app on a phone. It can also live on a Windows laptop or desktop through Windows Hello, or on a small physical security key that plugs into a computer, an option that matters for staff without smartphones.

Why Microsoft is retiring SMS and voice authentication

Microsoft’s stated reason is straightforward: SMS and voice codes are phishable, and they are increasingly defeated by AI-assisted social engineering, meaning scam calls and messages produced with AI tools, far more convincing than the clumsy attempts of a few years ago. A code a person can read out is a code a person can be tricked into reading out.

Passkeys are phishing-resistant: there is nothing for an attacker to steal or coax out of your staff. The National Cyber Security Centre makes the same point in its guidance on multi-factor authentication: the strongest second factors are the ones that cannot be handed over.

So this is a real security upgrade, not vendor churn. Microsoft is removing the weakest link in most sign-in chains.

What your staff will notice

Surprisingly little, and mostly for the better. Instead of waiting for a text and typing six digits, staff approve the sign-in with the same fingerprint, face or PIN they use to unlock their device. It is usually quicker than the code it replaces, with nothing to mistype and no waiting for a message that never arrives.

The one moment of friction is registration, the first-time setup where each person creates their passkey. Since 1 September 2026 Microsoft has been prompting people to do this at sign-in. A business that explained the prompt in advance sails through it; one that did not fields a week of “is this genuine?” calls. If your staff are asking that question now, the prompt is real.

Who needs to act, and the edge cases to plan for

If any of your staff sign in with a texted or spoken code today, you need a plan. For most people the move is simple, but three edge cases are worth thinking through early:

  • Staff without smartphones. A passkey does not require a company phone. It can sit on the person’s computer through Windows Hello, or on an inexpensive physical security key.
  • Frontline and shared-device workers. Staff who share terminals or hold no company device need a deliberate choice of method, typically hardware keys, decided well before the deadline.
  • Organisations that genuinely must keep SMS. If a compliance requirement means SMS or voice must stay, the route is a third-party telecom provider configured through the Microsoft Security Store, arranged and paid for by your organisation. Provider details are published from 18 September 2026 and configuration opens on 30 October 2026. It works, but decide it early rather than drift into it.

The common thread: none of these is a problem this autumn, and all of them are a scramble in January.

How to move your business to passkeys without disruption

A calm migration between now and early 2027 looks like this:

  1. Audit who relies on SMS and voice today. Your tenant records each user’s registered sign-in methods, so this is a report, not a guessing game. The SMS-only list is your to-do list.
  2. Pilot with a small group. Move a handful of willing staff across first, including at least one non-technical volunteer, and learn from their questions.
  3. Brief everyone. The registration prompts have been appearing since 1 September. A short, plain-English note to all staff explaining what the prompt looks like and that it is genuine prevents most of the confusion, and stops people snoozing it out of caution.
  4. Sweep up stragglers well before February 2027. The transition prompt can be snoozed indefinitely, so some people will put it off for months. Chase the remainder through the autumn so nobody meets the blocking prompt on deadline day.

It is a matter of configuration, communication and follow-through, not a heavy technical project.

How Lanmark handles the change for managed support clients

For businesses on our managed IT support, this transition is our job, not yours. We run the audit, configure passkeys, pilot with a small group, supply staff-facing comms you can send in your own name, and track registrations until the last SMS-only user is moved, all as part of the service.

Sign-in security is one layer of a wider defence. Our 24x7 managed detection and response catches whatever slips through, and our cyber security support and Microsoft cloud services sit around it. If your current provider has not yet mentioned the February 2027 date, that in itself is useful information.

Get ahead of the deadline

The first date has passed and the second, 1 February 2027, is fixed. The businesses that handle this well will be the ones that start with a list of names rather than a deadline.

Contact us or call 020 7123 4910 and ask us to check who in your business still relies on SMS codes. Our Microsoft 365 licence review can also surface your SMS-only users along the way.

Common questions

When did Microsoft passkeys become the default?

Passkeys became the default authentication method in Microsoft Entra ID on 1 September 2026. From that date, staff who sign in with SMS or voice codes are automatically enabled for passkeys and prompted to register one at their next MFA sign-in. The prompt can be snoozed during the transition period.

Will SMS login codes stop working in Microsoft 365?

Yes, eventually. Microsoft retires its SMS and voice authentication on 1 February 2027. Until then, text-message codes keep working and the passkey registration prompt can be snoozed. After that date staff need a passkey or another approved method.

What happens if staff have not set up a passkey by February 2027?

From 1 February 2027, anyone whose only sign-in method is SMS or voice faces a blocking passkey registration prompt at sign-in, with no option to skip it and no opt-out. They must register a passkey before continuing.

Do passkeys need a company smartphone?

No. A passkey can be held in the Microsoft Authenticator app on a company or personal phone, on a Windows computer through Windows Hello, or on a small physical security key. Staff without smartphones can use their computer or a hardware key instead.

Can we keep using SMS codes if we have to?

Only through a third party. Organisations that genuinely need SMS or voice must configure a third-party telecom provider through the Microsoft Security Store, arranged and paid for by the organisation itself.

Is a passkey more secure than a password and SMS code?

Yes. Passwords and SMS codes can be phished. A passkey is phishing-resistant: it stays locked to the user's device and only works on the genuine sign-in page, so it cannot be read out or entered into a fake one.

About this guide

Written by Lanmark, Lanmark Limited, 36 Basepoint, Victoria Road, Dartford, Kent DA1 5FS. Published .

Contact Lanmark

Book a free IT review.

We look at what you have, what it costs and where the risks are, and tell you plainly if you do not need to change anything.

Book a free IT review