The Download with John: Microsoft Sets Passkey Deadline
Earlier this month, Microsoft announced that SMS/text and phone call authentication will be retired on February 1st, 2027. Last month, we told you all about Passkeys and why they were fast becoming the default. Now, Microsoft has given it a timetable for their services, and it’s coming up fast.
Here is the timeline:
Sept 1, 2026 – Microsoft will be nudging users with SMS/Voice enabled to convert to Passkey authentication
Oct 30, 2026 – Companies with users where SMS/Voice options are mandatory will be able to choose a paid option to keep the service running
Feb 1, 2027 – Microsoft-provided SMS and voice authentication will be retired
Why the switch?
Text messages and phone calls have long been considered one of the least secure methods of multi-factor authentication. Phone calls can be intercepted, and SMS messages can be the target of sim swapping or account takeover attacks. Our recommendation has been to utilize the Microsoft Authenticator app for authentication, but there are some cases where that’s not possible. Whether it’s a user base that doesn’t have smartphones, or a company policy that employees don’t need to use their personal devices, SMS has been a convenient fallback option.
How should you move forward?
So, what should you do?
If you or your fellow users are utilizing text messages for authentication, you have a couple of options: First, you could simply convert to using passkeys on your workstation and mobile phone via the Microsoft Authenticator app or Windows Hello. You could also move to a FIDO2 Security Key – a small USB hardware token tied to your authentication that you carry around on your keychain, and it acts as your Passkey. Hardware security keys are the best option for those users who don’t have a company mobile device and opt to not have any work-related apps on their personal device.
Does this mean a major change for everyone?
If you’re already using the Microsoft Authenticator app for push notifications, this release from Microsoft will not force you to change your behavior at this time. From what we’ve seen, most users will fall into this category and will not need to see any change from this announcement. However, it would be a good idea to do an audit for any users that will be affected and try to get ahead of the timeline.
For any of our Managed Services clients, we’ll be performing an audit over the next few months, but if you have questions or would like some assistance, we are always here to help!