
If your business uses Microsoft 365, a change is coming to how your staff log in. Microsoft has announced that from 1 September 2026, passkeys become the default sign-in method for Microsoft Entra ID (the identity system behind Microsoft 365 and Azure). Anyone currently using SMS or voice call codes for multi-factor authentication (MFA) will automatically be prompted to set up a passkey instead. Then, from 1 February 2027, Microsoft will switch off its own SMS and voice MFA entirely for tenants that haven’t arranged a third-party telecom provider through the Microsoft Security Store.
Why does this matter to a small or medium business? SMS and voice MFA codes are convenient, but they’re also one of the weaker links in account security — they can be intercepted or bypassed with SIM-swap scams and phishing kits. Passkeys use your fingerprint, face, or device PIN instead of a code you type in, which is both simpler for staff and far harder for criminals to steal remotely. But the flip side is disruption: any account whose only MFA method is SMS or voice will be locked out of normal sign-in until someone registers a passkey, so this needs a plan, not a surprise.
Three practical steps before the changes land:
- Check which staff accounts still rely only on SMS or voice MFA in the Microsoft 365 admin centre, and get them onto the Microsoft Authenticator app or a passkey now, ahead of the September deadline.
- If your team relies on shared or older devices where a personal passkey isn’t practical, look into a third-party telecom provider option before February 2027 so SMS doesn’t just stop working.
- Test the passkey sign-in flow with a small group first — staff who aren’t used to biometric login can get stuck without a bit of guidance.
Worried this affects your business? Get a free 15-minute IT check – call Trends IT on 0485 011 911 or visit /contact/.
