Microsoft Entra ID
Authentication

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

In brief

Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.

What Entra admins need to know

Move affected users to phishing-resistant authentication before the applicable deadline, or configure a customer-managed telecom provider where SMS or voice must remain available.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

To help enterprises adopt AI at scale, it is imperative for users to use secure authentication and move from phishable authentication methods to phishing-resistant authentication methods like passkeys. Therefore, Microsoft Entra ID is making passkeys the default sign-in experience, so every organization gets phishing-resistant security by default. SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID.

Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice. From February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will be retired; customersretired for all users except Global Administrators and external users. For Global Administrators and external users, Microsoft-provided SMS and voice authentication will be retired on July 1, 2027. Customers who still require these methods should configure customer-managed providers through the Microsoft Security Store. More information on customer-managed telecoms coming September 18th, 2026.

Users who already sign in with passkeys, Windows Hello for Business, or another phishing-resistant method can continue using those methods. However, users who remain enabled for SMS or voice maymight still receive prompts to register passkeys on eligible devices. The July 1, 2027 retirement date applies to Global Administrators and to external users only. Internal guest users still follow the February 1, 2027 retirement date. To check who in your tenant still uses SMS or Voice, see Find active SMS or Voice users in your tenant.

Retirement timeline

Date Milestone What you should do
September 1, 2026 Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in. Notify end users of the changes happening. Use the passkey deployment guide to prepare your environment for passkey use.
February 1, 2027 Microsoft Microsoft-provided SMS and Voice fullyvoice authentication is retired for all users except Global Administrators and external users. Internal guest users remain in Microsoft Entra IDscope for the February 1 retirement. Make sure every user isusers in scope for the February 1 retirement are on a phishing-resistant method (passkeys, Windows Hello, or FIDO2) before this date, or users maythey might experience sign sign-in disturbances.disruption.
After February 1, 2027 Users in scope for the February 1 retirement whose only available MFA method is SMS or voice will beare required to register a passkey during sign-in to continue accessing their account. This prompt will beis blocking. Users must register a passkey before they can continue to sign in to their account.
There is no opt out from this February 1 behavior. It will be enforcedbehavior for all tenants.users in scope of the February 1 retirement.
Migrate users in scope for the February 1 retirement to a phishing-resistant method or choose a telecom provider to continue using SMS or voice.
July 1, 2027Microsoft-provided SMS and voice authentication is retired for Global Administrators and external users. This July 1 exception applies only to external users. Internal guest users still follow the February 1, 2027 retirement date.Make sure Global Administrators and external users are on a phishing-resistant method before this date, or they might experience sign-in disruption.
After July 1, 2027Global Administrators and external users whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account.
There is no opt out from this July 1 behavior for Global Administrators and external users.
Migrate Global Administrators and external users to a phishing-resistant method or choose a telecom provider to continue using SMS or voice.

Prepare for transition to passkeys

5. After retirement

Beginning February 1, 2027, Microsoft-provided SMS and voice delivery will be retired in Microsoft Entra ID.ID for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1, 2027 retirement.

If your tenant still has users in scope for the February 1, 2027 retirement enabled for SMS or voice and you have nothaven't configured a customer-managed telecom provider through the Microsoft Security Store, those users willcan no longer be able to use SMS or voice to complete MFA and sign in as usual.

After this date, users in scope for the February 1, 2027 retirement whose only available MFA method is SMS or voice will beare required to register a passkey during sign-in to continue accessing their account. This prompt will beis blocking. Users must register a passkey before they can continue signing intoin to their account.

There is no opt out from this February 1 behavior. Itbehavior for users in scope of the February 1 retirement.

Beginning July 1, 2027, Microsoft-provided SMS and voice delivery will be enforcedretired for all tenants.Global Administrators and external users. This July 1 exception applies only to external users. Internal guest users still follow the February 1, 2027 retirement date.

After this date, Global Administrators and external users whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue signing in to their account.

There is no opt out from this July 1 behavior for Global Administrators and external users.

To avoid sign-in disruption, make sure users register a passkey or move to another phishing-resistant authentication method before February 1, 2027.their applicable retirement date. If your organization has a valid business, regulatory, or operational need to keep using SMS or voice, configure a customer-managed telecom provider before thisthat date.

Temporarily opt out of the automatic passkey enablement

}


After this setting is applied, your tenant is excluded from the automatic passkey enablement and Registration Campaign rollout during the opt-out period. Beginning February 1, 2027, standard passkey migration and enforcement timelines apply regardless of this setting.setting for users in scope of the February 1 retirement. Global Administrators and external users follow the July 1, 2027 retirement date instead.

If your tenant still has users enabled for Microsoft-managed SMS or voice on February 1, 2027,their applicable retirement date, and you haven't configured a customer-managed telecom provider through the Security Store, those users can no longer use SMS or voice to satisfy MFA requirements and continue signing in.

**There is no opt out for the February 1, 2027 enforcement. This requirement applies to all tenants.tenants on the applicable retirement date for each user population.**

## Frequently asked questions
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…