← All articles

The Password Is Dead: Welcome to Passkeys

Microsoft has set the date: as of September 1, 2026, passkeys become the default authentication method in Entra ID, and SMS codes disappear in February 2027. This is no longer a trend — it's a deadline. Here's what a passkey is, why it's immune to phishing, and how to manage the transition without chaos.

The Password Is Dead: Welcome to Passkeys

On September 1, 2026, Microsoft flips a switch that will touch every business running Microsoft 365: passkeys become the default authentication method in Entra ID. Employees who still get their codes by text message will be prompted, at their next sign-in, to register a passkey. And on February 1, 2027, Microsoft-provided SMS and voice codes simply disappear from the platform.

This isn't tech-blog speculation — it's the official timeline, announced on July 13, with notification emails now landing in administrators' inboxes. The password, that 1960s invention we've been dragging around out of habit, has just received its termination notice. The good news: what replaces it is both simpler for your employees and radically more secure for your business. Provided you prepare the transition instead of enduring it.

Why passwords are no longer enough — even with MFA

The problem with passwords was never complexity. It's that they can be shared, guessed, resold and, above all, phished. One well-crafted fake Microsoft login page, one employee in a hurry, and it's done — password and MFA code included, because modern phishing kits relay both in real time.

Text messages fare no better: Microsoft itself now classifies SMS and voice among the most vulnerable authentication methods available — exposed to phishing, SIM-swap and replay attacks. And the machine has shifted into high gear: according to Microsoft's Digital Defense Report, AI-enabled phishing campaigns reach click-through rates as high as 54%, compared with roughly 12% for traditional campaigns. Four times more effective. We saw it with deepfake-era CEO fraud : the 2026 attacker no longer picks the lock — he convinces someone to open the door. As long as the key is something an employee knows and can type somewhere, it can be stolen.

So what exactly is a passkey?

A passkey is a unique digital key, created for one specific site or service, and locked inside your device — your computer, your phone, or a physical security key. To use it, you unlock the device the way you already do: fingerprint, face, or PIN. That's it. No password to remember, to reset, or to stick under the keyboard.

The magic is in what doesn't happen. Nothing is typed, so nothing can be intercepted. The key only works on the real site it was created for: a fake Microsoft page, however perfect, will never receive anything. And the key never leaves your device — there is no central database of passkeys to steal from the provider. Classic phishing doesn't just get harder; it becomes structurally impossible. It's exactly the Zero Trust logic applied to identity: stop trusting anything that can be copied.

Microsoft's timeline, in three moves

September 1, 2026: users still authenticating by SMS or voice call are automatically enabled for passkeys and nudged to register one at their next sign-in. Your IT team can get ahead of the change — or manage how it lands — but not ignore it: avoiding auto-enablement requires moving those users out of SMS/voice in the Authentication Methods Policy before that date.

February 1, 2027: Microsoft-provided SMS and voice codes are fully retired. After that date, any user for whom that was the only MFA method hits a blocking prompt: no sign-in until a passkey is registered. No opt-out, for any tenant.

What about organizations that must keep SMS? For a real regulatory or operational need, a third-party telecom provider will remain possible through the Microsoft Security Store — options and pricing published starting September 18, 2026, configuration available from October 30, 2026, to be completed before February 1, 2027. With the extra costs that come with it.

Translation for an SMB: within weeks, your employees will start seeing prompts to "create a passkey" — with or without your preparation. The only real decision left is whether this transition will be managed or improvised.

What companies that made the switch are seeing

The transition isn't just a compliance burden. According to the 2026 report from the FIDO Alliance — the body behind the standard — about 5 billion passkeys are already in use worldwide, and 68% of organizations have deployed or are deploying passkeys for their workforce. Those that have measure concrete gains: 45% report faster logins, 35% see password reset tickets melt away — the most mundane and time-consuming request in any IT department — and 32% record fewer phishing-related incidents.

In other words: more security and less friction, at the same time. That's rare. And if you're already paying for Microsoft 365, the infrastructure is already there: Windows Hello, the Authenticator app and physical security keys are tools included in what you already pay for .

The traps the transition has in store

An honest article also has to name the friction points, because there are some.

Shared accounts — the info@ mailbox, the front-desk workstation, the warehouse tablet — don't fit naturally with a key tied to one person and one device. You'll need to inventory them and find a clean solution: shared physical security keys or, better yet, the end of account sharing.

Personal devices raise the awkward question: if an employee registers their work passkey on a personal phone, what happens when they leave? The answer has to be prepared in advance — the same reflex as revoking access when employees depart , except it needs to be written down before, not after.

Account recovery becomes the new weak link. When there's no password left to reset, the "I lost my phone" procedure has to be rock-solid — otherwise that's what fraudsters will target, impersonating your employees to your IT support.

Nothing insurmountable. But each of these items gets settled either through a few calm decisions in August, or in a panic in February.

Where to start?

First, the inventory: who in your organization still authenticates by SMS or voice call? They're the ones Microsoft's timeline hits first. Next, a pilot project: enable passkeys for a small group — ideally leadership and the most targeted accounts — and test the real-life scenarios, including a lost device. Finally, communication: a clear message to the team before September, so that Microsoft's prompt is an expected step rather than one more suspicious email. The irony would be for a poorly announced security transition to be mistaken for phishing itself.

Which leaves the scheduling question: between today and September 1, there are a few weeks left. Enough to do things in order — inventory, pilot, communication. Not enough to put it off until fall.

At MMO Techno, this is exactly the kind of transition we guide SMBs through: inventorying current authentication methods, configuring passkeys in your Microsoft 365 environment, planning for the edge cases — shared accounts, personal devices, recovery procedures — and training your teams in plain language. The goal: make September 1 a non-event. If your employees still get their codes by text, let's talk before Microsoft does it for us .

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us