Microsoft 365 3 min read September 2, 2026

Do we need to switch to passkeys before Microsoft forces it?

Microsoft just changed the default login experience for every Microsoft 365 tenant. Here's what actually happens if you do nothing.

The question

"We got a notice that Microsoft is retiring text message login codes. Do we actually need to do anything, or is this one of those things where they push a deadline back three times and it never really happens?"

This one's real, and the first deadline already passed. Passkeys became Microsoft's default authentication experience on September 1, 2026 — the day before this question landed in our inbox.

What we told them

This is a real, dated change, not a "someday" announcement. Here's the actual timeline:

  • September 1, 2026 (already happened): Passkeys became the default sign-in method. Anyone currently using Microsoft-provided SMS or voice codes for MFA is being auto-enrolled for a passkey and prompted to register one at their next sign-in.
  • Now through early 2027: Users can skip that prompt as many times as they want, unless an admin turns off the "unlimited snooze" behavior. In practice, that means most people will keep clicking past it until it's forced.
  • February 1, 2027 (the real deadline): Microsoft-provided SMS and voice MFA stop working entirely for tenants that haven't set up a customer-managed telecom provider. Anyone whose only MFA method is a text code gets locked out of sign-in until they register a passkey on the spot.

The honest answer to "do we need to do anything" is yes, but you have time to do it right instead of doing it in a panic on January 31st. A passkey is also a real security upgrade, not just a compliance checkbox — it's tied to a device and can't be phished or intercepted the way an SMS code can. We're already seeing SMS-based MFA bypass show up in real attacks (a fake IT helpdesk call is enough to walk someone through handing over a code). Passkeys close that hole entirely.

What we're telling clients: don't wait for the forced migration. Turn on Microsoft's passkey registration campaign now, communicate the change to your team once, and get ahead of it while it's a scheduled rollout instead of a lockout-day scramble.

The takeaway

The February 2027 deadline is real, but the better move is treating this as a security upgrade you control now — not a compliance deadline you race later.

Got a question like this one?

Send it over — 20 minutes, no pitch, a straight answer either way.