Entra Passkeys by Default: What Changes September 2026
Share on LinkedIn!
SimpleSharepoint #MicrosoftEntra #Microsoft365 #Passkeys #MFA #IdentityManagement #M365Admins #ITGovernance #Cybersecurity #ConditionalAccess
Entra passkeys by default will change how your employees interact with sign-in prompts starting September 1, 2026.
Microsoft is enabling passkeys as the default, preferred authentication method across Microsoft Entra ID. Alongside this shift, Microsoft-provided SMS and voice authentication are heading toward retirement. Full enforcement will begin on February 1, 2027.
Between those two dates sits a critical planning window for enterprise identity teams.
Understanding the Identity Retirement Clock
Starting September 1, 2026, users will be prompted to register and use passkeys as their primary sign-in method when authenticating. While existing MFA options will not disappear overnight on day one, legacy fallbacks face a hard deadline.
Microsoft-provided SMS and voice fallbacks will stop being supported by February 2027. To keep using phone delivery, your tenant must connect a customer-managed telecom provider via the Microsoft Security Store.
Why Moving Away From SMS and Voice Matters
Passkeys significantly elevate your identity security posture against modern phishing attacks. Relying on legacy SMS or voice calls as a help-desk fallback creates major security risks.
Skipping the telecom-provider decision or delaying passkey readiness creates unnecessary support friction. Your help desk will face severe bottlenecks when those legacy fallbacks phase out.
Strategic Action Items for Identity Administrators
Passkey rollouts that skip a structured pilot stage generate high ticket volumes. We recommend sequencing this rollout in deliberate, manageable stages:
- Pilot registration flows: Test the passkey registration experience with a targeted user group before September 1.
- Evaluate telecom needs: Decide if your organization genuinely requires a custom Security Store telecom provider for SMS and voice continuity.
- Update help desk playbooks: Revise operational documentation for account recovery and self-service password resets.



