Microsoft Entra ID
Authentication

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

In brief

The documentation identifies Soprano and Telesign as initial private-preview providers for SMS and voice authentication. It also states that provider selection and configuration through Microsoft Security Store will begin October 30, 2026.

What Entra admins need to know

Administrators relying on SMS or voice should evaluate a provider and configure one before the applicable retirement date, or ensure affected users register passkeys or another phishing-resistant method to avoid sign-in disruption.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

To help enterprises adopt AI at scale, it is imperative for users to use secure authentication and move from phishable authentication methods to phishing-resistant authentication methods like passkeys. Therefore, Microsoft Entra ID is making passkeys the default sign-in experience, so every organization gets phishing-resistant security by default. SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID.

Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice. From February 1, 2027, Microsoft-provided telecomtelephony delivery for SMS and voice will be retired for all users except Global Administrators and external users. For Global Administrators and external users, Microsoft-provided SMS and voice authentication will be retired on July 1, 2027. Customers who still require these methods should configure customer-managed providersa telephony provider through the Microsoft Security Store. More information on customer-managed telecoms coming September 18th, 2026.Soprano and Telesign are the initial providers available during the private preview, and more providers will become available by general availability. For provider and offer information, see Choose a telephony provider for SMS and voice authentication.

Users who already sign in with passkeys, Windows Hello for Business, or another phishing-resistant method can continue using those methods. However, users who remain enabled for SMS or voice might still receive prompts to register passkeys on eligible devices. The July 1, 2027 retirement date applies to Global Administrators and external users. Internal guest users aren't included in that July 1 group and still follow the February 1, 2027 retirement date. To check who in your tenant still uses SMS or Voice, see Find active SMS or Voice users in your tenant.

|------|-----------|--------------------| | September 1, 2026 | Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in. | Notify end users of the changes happening. Use the passkey deployment guide to prepare your environment for passkey use. | | February 1, 2027 | Microsoft-provided SMS and voice authentication is retired for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1 retirement. | Make sure users in scope for the February 1 retirement are on a phishing-resistant method (passkeys, Windows Hello, or FIDO2) before this date, or they might experience sign-in disruption. | | After February 1, 2027 | Users in scope for the February 1 retirement whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account.
There is no opt out from this February 1 behavior for users in scope of the February 1 retirement. | Migrate users in scope for the February 1 retirement to a phishing-resistant method or choose a telecomtelephony provider to continue using SMS or voice. | | July 1, 2027 | Microsoft-provided SMS and voice authentication is retired for Global Administrators and external users. Internal guest users aren't included in this July 1 group and still follow the February 1, 2027 retirement date. | Make sure Global Administrators and external users are on a phishing-resistant method before this date, or they might experience sign-in disruption. | | After July 1, 2027 | Global Administrators and external users whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account.
There is no opt out from this July 1 behavior for Global Administrators and external users. | Migrate Global Administrators and external users to a phishing-resistant method or choose a telecomtelephony provider to continue using SMS or voice. |

Prepare for transition to passkeys

  1. Go to Entra ID > Authentication methods > Registration campaign.
  2. Set State to Microsoft Managed and target the security group of SMS and Voice users you created in step 1.

3. Evaluate a telecommunicationstelephony provider in theMicrosoft Security Store for operational needs

Microsoft recommends passkeys as the primary migration path for all users where possible. If you operate in a regulated industry or have an operational need for a telecomstelephony channel — for example, specific compliance regimes that require an out-of-band SMS, or scenarios where no other method is workable — you can use a telecomtelephony provider available through the Microsoft Security Store for those user segments.

  1. Identify the specific user segments where you have a genuine regulatory or operational need for a telecomstelephony channel. Document the requirement (which regulation, which scenario).requirement, such as the applicable regulation or scenario.
  2. Beginning September 18th, 2026, reviewReview the telecominitial private-preview providers, Soprano and Telesign, and their offers in Choose a telephony provider for SMS and voice authentication. More providers and related informationwill become available through the Microsoft Security Store to evaluate which option best meets your regional and compliance requirements.by general availability.
  3. Beginning October 30, 2026, customers who need to continue using SMS or voice will be able tocan select and configure a telecomtelephony provider from the Microsoft Security Store.
  4. Stand up the carrier contract through the marketplace flow and test with a pilot group before broad rollout.
  5. For every other user segment in your tenant, default to passkeys.

Beginning February 1, 2027, Microsoft-provided SMS and voice delivery will be retired in Microsoft Entra ID for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1, 2027 retirement.

If your tenant still has users in scope for the February 1, 2027 retirement enabled for SMS or voice and you haven't configured a customer-managed telecomtelephony provider through the Microsoft Security Store, those users can no longer use SMS or voice to complete MFA and sign in as usual.

After this date, users in scope for the February 1, 2027 retirement whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue signing in to their account.

There is no opt out from this July 1 behavior for Global Administrators and external users.

To avoid sign-in disruption, make sure users register a passkey or move to another phishing-resistant authentication method before their applicable retirement date. If your organization has a valid business, regulatory, or operational need to keep using SMS or voice, configure a customer-managed telecomtelephony provider before that date.

Temporarily opt out of the automatic passkey enablement

A temporary opt-out is available for the September 1, 2026 through February 1, 2027 changes. This lets you delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providersa telephony provider or migrating to other authentication methods.

To opt out, you need the Microsoft Graph Policy.ReadWrite.AuthenticationMethod permission. Update your authentication methods policy using Microsoft Graph and set the passkeyDynamicMigration property to true.

After this setting is applied, your tenant is excluded from the automatic passkey enablement and Registration Campaign rollout during the opt-out period. Beginning February 1, 2027, standard passkey migration and enforcement timelines apply regardless of this setting for users in scope of the February 1 retirement. Global Administrators and external users instead follow the July 1, 2027 retirement date. Internal guest users remain on the February 1, 2027 retirement date.

If your tenant still has users enabled for Microsoft-managed SMS or voice on their applicable retirement date, and you haven't configured a customer-managed telecomtelephony provider through theMicrosoft Security Store, those users can no longer use SMS or voice to satisfy MFA requirements and continue signing in.

There is no opt out for enforcement. This requirement applies to all tenants on the applicable retirement date for each user population.

Frequently asked questions

For answers to common questions about the SMS and voice retirement, telecomtelephony providers, opt-out options, and passkey migration, see Frequently asked questions about SMS and voice retirement.

Related links

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…