September 1 matters. So does February 1. Microsoft says passkeys will become the default sign-in method in Entra ID on the first date, and Microsoft-provided SMS and voice authentication will retire on the second. That is not a small product note. It is a deadline for every company still leaning on the old fallback because nobody wanted to touch it yet.
The company says it is doing this because identity attacks are getting nastier in the AI era. Microsoft says AI-enabled phishing campaigns have reached click-through rates as high as 54%, compared with roughly 12% for more traditional campaigns. Once attackers can automate the pressure, shared-secret authentication starts looking like the weak link it always was.

The migration bill
On the surface, the rollout is clean. Users enabled for SMS or voice will be auto-enabled for passkeys when the change reaches their tenant, and the next MFA prompt will ask them to register. That sounds tidy until you remember every identity team owns a pile of exceptions: old phones, shared devices, service accounts, and the one business unit that always asks for just one more exception because somebody in the field still needs the old path.
Microsoft Learn is pretty direct about the business side. If an organization has a "legitimate business, regulatory, or technical need" to keep SMS or voice, it can move to telecom partners through the Microsoft Security Store. That keeps the door open for real edge cases. It also means the old fallback is no longer native and no longer free of paperwork.
The important part is that Microsoft is not pretending this is only a security upgrade. It is a migration project with a policy layer and, for some tenants, a commercial layer. If you need SMS or voice after the transition, Microsoft says the partner route will come with associated telecom costs. If you do not need it, the cleanest path is to move to passkeys and stop spending time defending the old setup.
Passwordless login has the same trap as any system migration: the hard part is not getting a feature to work once. The hard part is moving the work to a better system without losing the context that kept the old one alive. Identity programs fail when they treat that as a toggle instead of an operating change.
Why the clock matters
Passkeys use public-key cryptography instead of shared secrets, which is the real technical win here. Microsoft says that makes them phishing-resistant by design and simpler for users. The company also says passkeys can come in synced forms, like iCloud Keychain and Google Password Manager, or device-bound forms like Microsoft Authenticator, Entra passkeys on Windows, and FIDO2 security keys. That mix matters because the rollout has to fit a messy fleet, not a clean demo.
Sam C BarthHubSpot and RevOps help from the person who wrote thisI help teams clean up HubSpot, CRM data, and reporting so the system matches how the business runs.Visit samcbarth.comBleepingComputer's read on the announcement is the practical one: people already signing in with passkeys, Windows Hello for Business, FIDO2 keys, or smart cards can keep using those methods. So the real pressure is not on the people who already moved. It is on the long tail of SMS and voice users who still make the old system look normal because the organization never set a deadline.
That is why Microsoft is also pushing registration campaigns and tenant-level planning in its Learn docs. The company wants admins to find SMS and voice users, choose the passkey type that fits the device mix, and tell people what changes before the prompt lands. None of that is exciting. All of it is the work that decides whether a security rollout sticks or just creates another support ticket pile.
The useful way to read this is not as Microsoft killing choice. It is Microsoft deciding what the default should be. By making passkeys the standard and pushing SMS and voice into a managed exception, the company is saying the old convenience model is now the thing that needs a justification. That is a different kind of product decision. It turns identity from a loose preference into an operating rule.
So the real deadline is not the first prompt in September. It is February 1, 2027, when Microsoft-provided SMS and voice stop being a native option. After that, companies either live on passkeys, or they buy and manage a telecom path to keep the old fallback alive. That is the whole business story. The front door still works either way. The bill changes depending on which key you want to keep using.




