Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
In brief
The documentation identifies Soprano and Telesign as initial private-preview providers for SMS and voice authentication. It also states that provider selection and configuration through Microsoft Security Store will begin October 30, 2026.
What Entra admins need to know
Administrators relying on SMS or voice should evaluate a provider and configure one before the applicable retirement date, or ensure affected users register passkeys or another phishing-resistant method to avoid sign-in disruption.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
To help enterprises adopt AI at scale, it is imperative for users to use secure authentication and move from phishable authentication methods to phishing-resistant authentication methods like passkeys. Therefore, Microsoft Entra ID is making passkeys the default sign-in experience, so every organization gets phishing-resistant security by default. SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID.
Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice. From February 1, 2027, Microsoft-provided telecomtelephony delivery for SMS and voice will be retired for all users except Global Administrators and external users. For Global Administrators and external users, Microsoft-provided SMS and voice authentication will be retired on July 1, 2027. Customers who still require these methods should configure customer-managed providersa telephony provider through the Microsoft Security Store. More information on customer-managed telecoms coming September 18th, 2026.Soprano and Telesign are the initial providers available during the private preview, and more providers will become available by general availability. For provider and offer information, see Choose a telephony provider for SMS and voice authentication.
Users who already sign in with passkeys, Windows Hello for Business, or another phishing-resistant method can continue using those methods. However, users who remain enabled for SMS or voice might still receive prompts to register passkeys on eligible devices. The July 1, 2027 retirement date applies to Global Administrators and external users. Internal guest users aren't included in that July 1 group and still follow the February 1, 2027 retirement date. To check who in your tenant still uses SMS or Voice, see Find active SMS or Voice users in your tenant.
|------|-----------|--------------------|
| September 1, 2026 | Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in. | Notify end users of the changes happening. Use the passkey deployment guide to prepare your environment for passkey use. |
| February 1, 2027 | Microsoft-provided SMS and voice authentication is retired for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1 retirement. | Make sure users in scope for the February 1 retirement are on a phishing-resistant method (passkeys, Windows Hello, or FIDO2) before this date, or they might experience sign-in disruption. |
| After February 1, 2027 | Users in scope for the February 1 retirement whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account.
There is no opt out from this February 1 behavior for users in scope of the February 1 retirement. | Migrate users in scope for the February 1 retirement to a phishing-resistant method or choose a telecomtelephony provider to continue using SMS or voice. |
| July 1, 2027 | Microsoft-provided SMS and voice authentication is retired for Global Administrators and external users. Internal guest users aren't included in this July 1 group and still follow the February 1, 2027 retirement date. | Make sure Global Administrators and external users are on a phishing-resistant method before this date, or they might experience sign-in disruption. |
| After July 1, 2027 | Global Administrators and external users whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account.
There is no opt out from this July 1 behavior for Global Administrators and external users. | Migrate Global Administrators and external users to a phishing-resistant method or choose a telecomtelephony provider to continue using SMS or voice. |
Prepare for transition to passkeys
- Go to Entra ID > Authentication methods > Registration campaign.
- Set State to Microsoft Managed and target the security group of SMS and Voice users you created in step 1.
3. Evaluate a telecommunicationstelephony provider in theMicrosoft Security Store for operational needs
Microsoft recommends passkeys as the primary migration path for all users where possible. If you operate in a regulated industry or have an operational need for a telecomstelephony channel — for example, specific compliance regimes that require an out-of-band SMS, or scenarios where no other method is workable — you can use a telecomtelephony provider available through the Microsoft Security Store for those user segments.
- Identify the specific user segments where you have a genuine regulatory or operational need for a
telecomstelephony channel. Document therequirement (which regulation, which scenario).requirement, such as the applicable regulation or scenario. Beginning September 18th, 2026, reviewReview thetelecominitial private-preview providers, Soprano and Telesign, and their offers in Choose a telephony provider for SMS and voice authentication. More providersand related informationwill become availablethrough the Microsoft Security Store to evaluate which option best meets your regional and compliance requirements.by general availability.- Beginning October 30, 2026, customers who need to continue using SMS or voice
will be able tocan select and configure atelecomtelephony provider fromtheMicrosoft Security Store. - Stand up the carrier contract through the marketplace flow and test with a pilot group before broad rollout.
- For every other user segment in your tenant, default to passkeys.
Beginning February 1, 2027, Microsoft-provided SMS and voice delivery will be retired in Microsoft Entra ID for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1, 2027 retirement.
If your tenant still has users in scope for the February 1, 2027 retirement enabled for SMS or voice and you haven't configured a customer-managed telecomtelephony provider through the Microsoft Security Store, those users can no longer use SMS or voice to complete MFA and sign in as usual.
After this date, users in scope for the February 1, 2027 retirement whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue signing in to their account.
There is no opt out from this July 1 behavior for Global Administrators and external users.
To avoid sign-in disruption, make sure users register a passkey or move to another phishing-resistant authentication method before their applicable retirement date. If your organization has a valid business, regulatory, or operational need to keep using SMS or voice, configure a customer-managed telecomtelephony provider before that date.
Temporarily opt out of the automatic passkey enablement
A temporary opt-out is available for the September 1, 2026 through February 1, 2027 changes. This lets you delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providersa telephony provider or migrating to other authentication methods.
To opt out, you need the Microsoft Graph Policy.ReadWrite.AuthenticationMethod permission. Update your authentication methods policy using Microsoft Graph and set the passkeyDynamicMigration property to true.
After this setting is applied, your tenant is excluded from the automatic passkey enablement and Registration Campaign rollout during the opt-out period. Beginning February 1, 2027, standard passkey migration and enforcement timelines apply regardless of this setting for users in scope of the February 1 retirement. Global Administrators and external users instead follow the July 1, 2027 retirement date. Internal guest users remain on the February 1, 2027 retirement date.
If your tenant still has users enabled for Microsoft-managed SMS or voice on their applicable retirement date, and you haven't configured a customer-managed telecomtelephony provider through theMicrosoft Security Store, those users can no longer use SMS or voice to satisfy MFA requirements and continue signing in.
There is no opt out for enforcement. This requirement applies to all tenants on the applicable retirement date for each user population.
Frequently asked questions
For answers to common questions about the SMS and voice retirement, telecomtelephony providers, opt-out options, and passkey migration, see Frequently asked questions about SMS and voice retirement.
Related links
@@ -2,7 +2,7 @@ title: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication description: Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys. ms.topic: how-to-ms.date: 09/16/2026+ms.date: 09/23/2026 author: marinasanchezz1 ms.author: marisanchez ai-usage: ai-assisted@@ -14,7 +14,7 @@ ai-usage: ai-assisted To help enterprises adopt AI at scale, it is imperative for users to use secure authentication and move from phishable authentication methods to phishing-resistant authentication methods like [passkeys](concept-authentication-passkeys-fido2.md). Therefore, Microsoft Entra ID is making passkeys the default sign-in experience, so every organization gets phishing-resistant security by default. SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID. -Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice. From February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will be retired for all users except Global Administrators and external users. For Global Administrators and external users, Microsoft-provided SMS and voice authentication will be retired on July 1, 2027. Customers who still require these methods should configure customer-managed providers through the Microsoft Security Store. More information on customer-managed telecoms coming September 18th, 2026.+Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice. From February 1, 2027, Microsoft-provided telephony delivery for SMS and voice will be retired for all users except Global Administrators and external users. For Global Administrators and external users, Microsoft-provided SMS and voice authentication will be retired on July 1, 2027. Customers who still require these methods should configure a telephony provider through Microsoft Security Store. Soprano and Telesign are the initial providers available during the private preview, and more providers will become available by general availability. For provider and offer information, see [Choose a telephony provider for SMS and voice authentication](concept-phone-providers.md). Users who already sign in with passkeys, Windows Hello for Business, or another phishing-resistant method can continue using those methods. However, users who remain enabled for SMS or voice might still receive prompts to register passkeys on eligible devices. The July 1, 2027 retirement date applies to Global Administrators and external users. Internal guest users aren't included in that July 1 group and still follow the February 1, 2027 retirement date. To check who in your tenant still uses SMS or Voice, see [Find active SMS or Voice users in your tenant](#1-find-users-enabled-for-sms-or-voice). @@ -24,9 +24,9 @@ Users who already sign in with passkeys, Windows Hello for Business, or another |------|-----------|--------------------| | September 1, 2026 | Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in. | Notify end users of the changes happening. Use the [passkey deployment guide](how-to-deploy-phishing-resistant-passwordless-authentication.md) to prepare your environment for passkey use. | | February 1, 2027 | Microsoft-provided SMS and voice authentication is retired for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1 retirement. | Make sure users in scope for the February 1 retirement are on a phishing-resistant method (passkeys, Windows Hello, or FIDO2) before this date, or they might experience sign-in disruption. |-| After February 1, 2027 | Users in scope for the February 1 retirement whose **only available MFA method is SMS or voice** are required to register a passkey during sign-in to continue accessing their account. This prompt is **blocking**. Users must **register a passkey before they can continue to sign in** to their account.<br>**There is no opt out from this February 1 behavior for users in scope of the February 1 retirement.** | Migrate users in scope for the February 1 retirement to a phishing-resistant method or choose a telecom provider to continue using SMS or voice. |+| After February 1, 2027 | Users in scope for the February 1 retirement whose **only available MFA method is SMS or voice** are required to register a passkey during sign-in to continue accessing their account. This prompt is **blocking**. Users must **register a passkey before they can continue to sign in** to their account.<br>**There is no opt out from this February 1 behavior for users in scope of the February 1 retirement.** | Migrate users in scope for the February 1 retirement to a phishing-resistant method or choose a telephony provider to continue using SMS or voice. | | July 1, 2027 | Microsoft-provided SMS and voice authentication is retired for Global Administrators and external users. Internal guest users aren't included in this July 1 group and still follow the February 1, 2027 retirement date. | Make sure Global Administrators and external users are on a phishing-resistant method before this date, or they might experience sign-in disruption. |-| After July 1, 2027 | Global Administrators and external users whose **only available MFA method is SMS or voice** are required to register a passkey during sign-in to continue accessing their account. This prompt is **blocking**. Users must **register a passkey before they can continue to sign in** to their account.<br>**There is no opt out from this July 1 behavior for Global Administrators and external users.** | Migrate Global Administrators and external users to a phishing-resistant method or choose a telecom provider to continue using SMS or voice. |+| After July 1, 2027 | Global Administrators and external users whose **only available MFA method is SMS or voice** are required to register a passkey during sign-in to continue accessing their account. This prompt is **blocking**. Users must **register a passkey before they can continue to sign in** to their account.<br>**There is no opt out from this July 1 behavior for Global Administrators and external users.** | Migrate Global Administrators and external users to a phishing-resistant method or choose a telephony provider to continue using SMS or voice. | ## Prepare for transition to passkeys @@ -66,13 +66,13 @@ To configure a registration campaign for passkeys: 1. Go to **Entra ID > Authentication methods > Registration campaign**. 1. Set **State** to **Microsoft Managed** and target the security group of SMS and Voice users you created in step 1. -### 3. Evaluate a telecommunications provider in the Security Store for operational needs+### 3. Evaluate a telephony provider in Microsoft Security Store for operational needs -Microsoft recommends passkeys as the primary migration path for all users where possible. If you operate in a regulated industry or have an operational need for a telecoms channel — for example, specific compliance regimes that require an out-of-band SMS, or scenarios where no other method is workable — you can use a telecom provider available through the Microsoft Security Store for those user segments.+Microsoft recommends passkeys as the primary migration path for all users where possible. If you operate in a regulated industry or have an operational need for a telephony channel — for example, specific compliance regimes that require an out-of-band SMS, or scenarios where no other method is workable — you can use a telephony provider available through Microsoft Security Store for those user segments. -1. Identify the specific user segments where you have a genuine regulatory or operational need for a telecoms channel. Document the requirement (which regulation, which scenario).-1. Beginning September 18th, 2026, review the telecom providers and related information available through the Microsoft Security Store to evaluate which option best meets your regional and compliance requirements.-1. Beginning October 30, 2026, customers who need to continue using SMS or voice will be able to select and configure a telecom provider from the Microsoft Security Store.+1. Identify the specific user segments where you have a genuine regulatory or operational need for a telephony channel. Document the requirement, such as the applicable regulation or scenario.+1. Review the initial private-preview providers, Soprano and Telesign, and their offers in [Choose a telephony provider for SMS and voice authentication](concept-phone-providers.md). More providers will become available by general availability.+1. Beginning October 30, 2026, customers who need to continue using SMS or voice can select and configure a telephony provider from Microsoft Security Store. 1. Stand up the carrier contract through the marketplace flow and test with a pilot group before broad rollout. 1. For every other user segment in your tenant, default to passkeys. @@ -93,7 +93,7 @@ Use [end-user communication templates](https://aka.ms/mfatemplates) for email, T Beginning February 1, 2027, Microsoft-provided SMS and voice delivery will be retired in Microsoft Entra ID for all users except Global Administrators and external users. Internal guest users remain in scope for the February 1, 2027 retirement. -If your tenant still has users in scope for the February 1, 2027 retirement enabled for SMS or voice and you haven't configured a customer-managed telecom provider through the Microsoft Security Store, those users can no longer use SMS or voice to complete MFA and sign in as usual.+If your tenant still has users in scope for the February 1, 2027 retirement enabled for SMS or voice and you haven't configured a telephony provider through Microsoft Security Store, those users can no longer use SMS or voice to complete MFA and sign in as usual. After this date, users in scope for the February 1, 2027 retirement whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue signing in to their account. @@ -105,11 +105,11 @@ After this date, Global Administrators and external users whose only available M **There is no opt out from this July 1 behavior for Global Administrators and external users.** -To avoid sign-in disruption, make sure users register a passkey or move to another phishing-resistant authentication method before their applicable retirement date. If your organization has a valid business, regulatory, or operational need to keep using SMS or voice, configure a customer-managed telecom provider before that date.+To avoid sign-in disruption, make sure users register a passkey or move to another phishing-resistant authentication method before their applicable retirement date. If your organization has a valid business, regulatory, or operational need to keep using SMS or voice, configure a telephony provider before that date. ## Temporarily opt out of the automatic passkey enablement -A temporary opt-out is available for the September 1, 2026 through February 1, 2027 changes. This lets you delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods.+A temporary opt-out is available for the September 1, 2026 through February 1, 2027 changes. This lets you delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring a telephony provider or migrating to other authentication methods. To opt out, you need the Microsoft Graph `Policy.ReadWrite.AuthenticationMethod` permission. Update your authentication methods policy using Microsoft Graph and set the `passkeyDynamicMigration` property to `true`. @@ -128,16 +128,17 @@ Content-Type: application/json After this setting is applied, your tenant is excluded from the automatic passkey enablement and Registration Campaign rollout during the opt-out period. Beginning February 1, 2027, standard passkey migration and enforcement timelines apply regardless of this setting for users in scope of the February 1 retirement. Global Administrators and external users instead follow the July 1, 2027 retirement date. Internal guest users remain on the February 1, 2027 retirement date. -If your tenant still has users enabled for Microsoft-managed SMS or voice on their applicable retirement date, and you haven't configured a customer-managed telecom provider through the Security Store, those users can no longer use SMS or voice to satisfy MFA requirements and continue signing in.+If your tenant still has users enabled for Microsoft-managed SMS or voice on their applicable retirement date, and you haven't configured a telephony provider through Microsoft Security Store, those users can no longer use SMS or voice to satisfy MFA requirements and continue signing in. **There is no opt out for enforcement. This requirement applies to all tenants on the applicable retirement date for each user population.** ## Frequently asked questions -For answers to common questions about the SMS and voice retirement, telecom providers, opt-out options, and passkey migration, see [Frequently asked questions about SMS and voice retirement](concept-sms-voice-retirement-faq.yml).+For answers to common questions about the SMS and voice retirement, telephony providers, opt-out options, and passkey migration, see [Frequently asked questions about SMS and voice retirement](concept-sms-voice-retirement-faq.yml). ## Related links - [What are authentication methods?](overview-authentication.md) - [Plan a passkey deployment](how-to-deploy-phishing-resistant-passwordless-authentication.md) - [Authentication methods activity report](howto-authentication-methods-activity.md)+- [Frequently asked questions about telephony providers](phone-providers-faq.yml) 