Microsoft is turning passkeys from an optional Entra feature into an operational deadline. From September 1, 2026, passkeys are scheduled to be enabled automatically for users who are enabled for SMS or voice authentication, accompanied by registration prompts. Native SMS and voice authentication then move toward retirement on February 1, 2027. The useful response is not a tenant-wide announcement. It is an inventory of the people, policies, and recovery paths that still depend on those methods.

Why it matters in production

The first risk is assuming that enabled means ready. A user can be eligible for passkeys while still lacking a compatible device, an approved registration path, or enough helpdesk support to complete enrollment. Guest users, shared devices, frontline roles, administrators, and accounts with restricted mobile use need separate treatment. Registration campaigns should therefore begin with cohorts whose device ownership and sign-in patterns are understood.

Smartphone with a visible lock screen held in one hand
Passkeys change sign-in at the device; rollout planning has to consider device ownership and registration together.

Authentication migration also changes recovery. Teams should test how passkey users regain access after losing a device, how Temporary Access Pass is issued, how SSPR behaves, and which break-glass accounts remain deliberately outside normal campaigns. A stronger primary factor does not help if recovery quietly falls back to an unmanaged phone number or an identity check the service desk cannot perform consistently.

A practical rollout starts with sign-in and authentication-method reports, maps remaining SMS and voice users to business owners, and pilots passkeys with support and security staff first. Measure registration completion, failed prompts, recovery cases, and exceptions. Microsoft provides a temporary opt-out mechanism, but that should buy time for a defined exception, not become a substitute for migration.

Two people confirming a process on a mobile device
Strong authentication remains reliable only when identity verification and recovery are equally clear.

Practical takeaway

The operational takeaway is simple: September 1 is the start of user-visible change, not the end of the project. Entra teams should know who will be prompted, how those users register, what happens when registration fails, and who owns recovery before Microsoft changes the default experience. Passkeys become safer when the migration runbook is as deliberate as the authentication method.