The question
This one's real, and the first deadline already passed. Passkeys became Microsoft's default authentication experience on September 1, 2026 — the day before this question landed in our inbox.
What we told them
This is a real, dated change, not a "someday" announcement. Here's the actual timeline:
- September 1, 2026 (already happened): Passkeys became the default sign-in method. Anyone currently using Microsoft-provided SMS or voice codes for MFA is being auto-enrolled for a passkey and prompted to register one at their next sign-in.
- Now through early 2027: Users can skip that prompt as many times as they want, unless an admin turns off the "unlimited snooze" behavior. In practice, that means most people will keep clicking past it until it's forced.
- February 1, 2027 (the real deadline): Microsoft-provided SMS and voice MFA stop working entirely for tenants that haven't set up a customer-managed telecom provider. Anyone whose only MFA method is a text code gets locked out of sign-in until they register a passkey on the spot.
The honest answer to "do we need to do anything" is yes, but you have time to do it right instead of doing it in a panic on January 31st. A passkey is also a real security upgrade, not just a compliance checkbox — it's tied to a device and can't be phished or intercepted the way an SMS code can. We're already seeing SMS-based MFA bypass show up in real attacks (a fake IT helpdesk call is enough to walk someone through handing over a code). Passkeys close that hole entirely.
What we're telling clients: don't wait for the forced migration. Turn on Microsoft's passkey registration campaign now, communicate the change to your team once, and get ahead of it while it's a scheduled rollout instead of a lockout-day scramble.
The February 2027 deadline is real, but the better move is treating this as a security upgrade you control now — not a compliance deadline you race later.