Microsoft has quietly announced a change to how people sign in to Microsoft 365, and it is going to surprise a lot of businesses.
What is changing
Microsoft is retiring the text-message and phone-call codes that many people use as their second step at login. In their place, Microsoft is making passkeys the default. A passkey is a login tied to your device or a secure key instead of a code you type, and it is far harder for an attacker to steal or trick out of you.
The two dates that matter
On September 1, 2026, passkeys become the default and anyone still using SMS or voice codes will start getting prompted to set one up. Those early prompts can be postponed. On February 1, 2027, Microsoft stops providing SMS and voice codes altogether. After that, any user whose only login method is a text or a call will be required to register a passkey before they can get in, and there is no way to opt out.
Who feels this most
Any organization where staff still confirm logins with a texted code. If that is how most of your team signs in today, February is a hard wall, not a suggestion. This applies to standard Microsoft 365 business tenants.
What to do now
You do not need to wait. First, identify who is still on SMS or voice. Then move those people to a passkey, the Microsoft Authenticator app, or Windows Hello over the next few months, well ahead of the deadline. Moving to passkeys costs nothing extra and is a genuine security improvement. If you have a specific regulatory reason you must keep text codes, Microsoft will offer a paid third-party option, but for almost everyone passkeys are the better path.
Handled early, this is a quiet upgrade your team barely notices. Left to the last minute, it becomes a stack of locked-out users and support calls. Is your organization and support team ready?
Leave a Reply