Secure & resilient

Microsoft makes passkeys the default and retires SMS codes

Codes by text or phone call are disappearing as sign-in verification at Microsoft. What a passkey is, when your people will notice, and what you can calmly arrange now.

All articles

If you still get a code by text or a phone call when signing in to Microsoft 365, you’ll notice something in the coming months. On 6 August 2026 Microsoft announced that passkeys will become the default for everyone who currently uses SMS or a voice call as extra verification, and that those SMS and voice codes will disappear entirely in early 2027. No options menu, no opt-out. Below, in plain language: what’s changing, why this is actually good news, and what your business can do now.

What is a passkey, exactly?

A passkey is a way of signing in without typing over codes. Instead of waiting for a text message, you confirm on your own phone or laptop that it’s really you, with your face, your fingerprint or your device PIN. The same gesture you use to unlock your phone, in other words.

The clever part sits under the bonnet: a passkey is tied to Microsoft’s real sign-in address. On a scammer’s fake login page it simply doesn’t work. And there’s no code you could accidentally hand to the wrong person, because there ís no code. That’s why security people call passkeys phishing-resistant.

Why Microsoft is doing this

Codes by text or phone call were better than nothing for years, but by now they’re the weakest form of extra verification. Criminals harvest those codes with fake websites, take over phone numbers through the carrier (SIM swapping) or intercept codes in transit and use them quickly themselves. In almost every successful account takeover we see, an intercepted code plays a part.

A passkey cuts that whole risk away. And let’s be honest: it’s simply more pleasant too. No waiting for a text that never arrives, no typing over codes, just your finger or your face and you’re in. Safer and easier at the same time — that doesn’t happen often.

What will your people notice, and when?

Two dates to remember:

  • From 1 September 2026, employees who currently use SMS or a voice call will get an invitation to set up a passkey when they sign in. It’s a friendly nudge: it explains itself, takes a few minutes, and from then on they sign in with face, fingerprint or PIN. SMS keeps working during this period.
  • From 1 February 2027, Microsoft stops SMS and voice codes completely. Anyone who only has that method won’t simply get in any more: the sign-in screen first asks them to set up a passkey before they can continue. Not something you want a colleague to run into on a busy Monday morning.

Between those two dates sits exactly the room you need to arrange this calmly instead of under pressure.

What your organisation can do now

This isn’t a big project, but leaving it is no plan either. Three things:

  • Know who it affects. Your Microsoft environment shows exactly who still uses SMS or a voice call for verification. That list is your entire job.
  • Help that group switch. Setting up a passkey or the Microsoft Authenticator app takes a few minutes, especially with someone on hand to help or a short set of instructions.
  • Give people a heads-up. A short message beforehand (“you’ll soon see this question when signing in, that’s normal”) prevents unrest and calls to the helpdesk.

For our managed clients we’re simply taking care of this the way you’d expect from us: we see who’s still on SMS, guide the switch and make sure nobody finds a locked door in February. Not a client but curious where you stand? Our free security scan is a good starting point: sign-in and verification are exactly the kind of things it covers.

A few questions we often get

Can I postpone this or switch it off?

No. Microsoft offers no opt-out; from 1 February 2027 SMS and voice codes stop working. Only for organisations that genuinely can’t do otherwise for legal reasons will there be an exception route via their own telecom provider. For virtually every SME the answer is: switching is the way, and happily also the better one.

What if an employee doesn’t have a company phone?

A passkey doesn’t have to live on a phone. It can also sit on the work laptop itself (with Windows Hello, so face or fingerprint) or on a small security key for the keyring. There’s a suitable form for every situation, even without a personal phone in the mix.

We already use the Authenticator app. Do we need to do anything?

Then you’re in good shape: the app isn’t going away, and you’ve already left the weak SMS route behind. The passkey invitation is mainly aimed at colleagues still on SMS or a phone call. Switching to a passkey is still a fine idea for app users too, because it’s that bit safer and faster again.


Curious who in your organisation still signs in with SMS codes? Do the free security scan for a first picture, or book an introduction and we’ll look together at how to have this calmly arranged before February.

Questions about your own IT?

Take the free scan and see how your own IT is doing, instead of leaving it at general knowledge. Want to talk it through? A no-strings intro call is always an option.

Free and no-strings, no sales pitch.