August 6, 2026

Microsoft 365 Passkeys Are Coming: What Southwest Florida Businesses Must Do Before February 2027

Starting September 1, 2026, Microsoft Entra ID, the identity system behind every Microsoft 365 login, begins automatically prompting employees to set up a passkey instead of a text message code. By February 1, 2027, Microsoft-provided SMS and voice call authentication stops working for good unless a business has configured its own telecom provider. If your Naples, Fort Myers, or Tampa office still leans on text codes to sign into Outlook, Teams, or SharePoint, you have about six months to plan the switch before someone gets locked out.

  • Microsoft is making passkeys the default sign-in method in Entra ID starting September 1, 2026, and will prompt eligible users to register one automatically.
  • Microsoft-provided SMS and voice call authentication is retiring on February 1, 2027, with no opt-out after that date.
  • Text and voice codes are being dropped because they are increasingly easy to defeat with SIM-swap fraud, phishing pages, and automated attack tools.
  • A short-lived opt-out API opens August 1, 2026, but it only delays the September rollout. It does not push back the February shutdown.
  • Businesses that want to keep phone-based codes after February 2027 must set up a separate, paid telecom provider through the Microsoft Security Store.

What is actually changing in Microsoft 365 sign-in?

Today, most small businesses either use a password with a text code, or a password with the Microsoft Authenticator app. Under the new policy, Microsoft sets Passkey Registration to a Microsoft-managed state for eligible tenants beginning September 1, 2026. That means employees will start seeing prompts to register a passkey the next time they sign in, without an admin having to turn anything on. According to Microsoft’s own documentation on the change, users can skip the prompt at first, but Microsoft-provided SMS and voice authentication will no longer function after February 1, 2027, for any tenant that has not configured an alternate telecom provider.

Why is Microsoft getting rid of text message codes?

Text and voice codes were a big improvement over passwords alone, but they were never great at stopping a determined attacker. A criminal can call a mobile carrier and convince a support rep to move a phone number to a new SIM card, then intercept the next code sent to that number. Attackers also run real-time phishing pages that capture a code the instant an employee types it in, a technique known as adversary-in-the-middle. We covered how this plays out against Microsoft 365 accounts specifically in our earlier post on AI-powered phishing that bypasses MFA. Passkeys close that gap because the credential is bound to the actual Microsoft sign-in page and stored on a device, so there is no code for an employee to accidentally hand over. Coverage of the rollout from BleepingComputer confirms the same September 2026 and February 2027 dates published by Microsoft.

Why does this matter more during hurricane season?

Southwest Florida businesses already deal with spotty cell coverage during storms, and SMS codes are the first thing to stop arriving reliably when towers are overloaded or power is out. A passkey on a laptop or already-paired phone does not depend on a fresh text arriving at the right moment, which makes it more reliable when staff are working from a hotel room after evacuating.

What should Southwest Florida businesses do before September?

Start by identifying which employees currently rely only on SMS or voice codes, since they are the ones who will see registration prompts first. Walk a few people through setting up a passkey on a company laptop or phone so you know what the prompt looks like and can answer questions before it hits the whole team. If your business has a specific reason to keep phone-based codes, for example an industry compliance requirement or an employee without a compatible device, budget time now to configure a third-party telecom provider through the Microsoft Security Store rather than waiting until January 2027. It is also worth revisiting your broader Microsoft 365 protections while you are in there. Our recent piece on Safe Links protection in Microsoft 365 covers another setting worth checking during the same review.

What happens if a business does nothing?

Nothing breaks in September. Employees will just start seeing an optional prompt. The real deadline is February 1, 2027. After that date, anyone whose only registered method is Microsoft-provided SMS or voice will not be able to complete sign-in until they register a passkey or another supported method. For a business with a dozen employees and no IT department watching for this, that can mean a chaotic morning of locked-out staff right when accounts are needed most.

Frequently asked questions

Do we have to switch to passkeys right away?
Not immediately. Microsoft starts prompting eligible users to register a passkey on September 1, 2026, but text and voice codes keep working until February 1, 2027, unless your organization sets up a separate telecom provider.

What exactly is a passkey?
A passkey is a login credential stored on a phone, laptop, or security key that uses your fingerprint, face, or device PIN instead of a password and a text code. It is tied to the specific website or app, which is why it cannot be phished the way a text code can.

Will every employee be switched over at the same time?
No. Microsoft rolls the change out gradually to eligible accounts starting in September 2026, and users can skip the registration prompt for a while before the February 2027 cutoff makes phone-based codes stop working entirely for Microsoft-provided SMS and voice.

What if our business needs SMS codes for compliance or accessibility reasons?
You can keep phone-based authentication by configuring a supported third-party telecom provider through the Microsoft Security Store before the February 2027 deadline. Microsoft’s own SMS and voice service will not be an option after that date.

Want help walking your team through the passkey switch before the February 2027 deadline hits? SWFIT offers a free 15-minute IT and security review to look at your current Microsoft 365 sign-in setup and flag anything that needs attention. Request your free review here.

SWFIT

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

Your IT Partner Is Just a Click Away

Contact us now to explore customized IT solutions that drive efficiency, security, and success for your business.