Microsoft is Switching Off Text Message Codes. Here’s What Passkeys Mean for Your Business

Instead of a code that can be read out, guessed, or intercepted, a passkey uses cryptography tied to your specific device, unlocked with your fingerprint, your face, or a PIN.

If you or your team sign in to Microsoft 365 with a text message or phone call code, that’s about to change – whether you plan for it or not.

Microsoft has confirmed that from 1 September 2026, passkeys will become the default way to prove your identity in Microsoft Entra ID (the system behind Microsoft 365 sign-in). Anyone currently using SMS or voice codes will start being nudged, automatically, to set up a passkey instead. By 1 February 2027, Microsoft stops providing SMS and voice codes altogether.

This isn’t a minor tweak to a settings menu. It’s Microsoft closing the door on one of the most commonly used and most commonly attacked forms of two-factor authentication in business today.

Why now?

Text message and phone call codes have always had a weakness: they rely on the phone network, not on you. A code can be intercepted, a SIM can be swapped, and a phone call can be talked out of someone by an attacker posing as IT support. None of that takes much skill, which is exactly why it keeps showing up in real breaches.

What’s changed is the scale of the problem. Microsoft’s own threat intelligence has tracked AI-generated phishing campaigns achieving click-through rates as high as 54%, against roughly 12% for older, more traditional attempts. Attackers are using AI to write more convincing messages, faster, at greater volume – and phishable codes are the easiest way in.

Passkeys close that door. Instead of a code that can be read out, guessed, or intercepted, a passkey uses cryptography tied to your specific device, unlocked with your fingerprint, your face, or a PIN. There’s no code to steal, because there’s no code at all.

What’s actually changing, and when

DateWhat happens
1 September 2026Users on SMS/voice are auto-enabled for passkeys and prompted to register one, next time they sign in
18 September 2026Microsoft publishes pricing for third-party telecom providers, for anyone who still needs SMS/voice
30 October 2026Businesses can configure a paid third-party SMS/voice provider, if genuinely needed
1 February 2027Microsoft-provided SMS and voice authentication ends completely
After 1 February 2027Passkey registration becomes mandatory for everyone, everywhere — no opting out

For most businesses, the sensible move is simply to get ahead of it: identify who’s still on SMS or voice, and get them onto a passkey on your own timeline, rather than Microsoft’s.

The bit most guidance skips: where does the passkey actually live?

This is the question we think businesses should be asking, and mostly aren’t.

A passkey has to be stored somewhere. Depending on how it’s set up, that “somewhere” is usually one of two places:

Locked to a single device. If someone registers a passkey using Windows Hello on their work laptop, that passkey lives on that laptop, and nowhere else. It won’t work on their phone, their second monitor at home, or a replacement machine after a repair. Lose the device, and you’re straight into account recovery.

Synced to a personal ecosystem account. If someone registers a passkey through their personal Apple or Google account (iCloud Keychain, Google Password Manager), it follows them – but it follows in their personal account, not your business. If that employee leaves, that passkey goes with them, tied to an account you have no visibility into and no control over.

Neither of those is a great fit for a business. What most businesses actually want is a third option: a passkey stored somewhere the business owns, that works across every device an employee uses, and that can be revoked the moment someone leaves — without depending on their personal Apple ID.

Where a password manager earns its keep

This is exactly the gap that a proper password manager fills, and it’s why we think this is a good moment for businesses to look at one properly, rather than leaving logins scattered across browsers and sticky notes.

Bitwarden, for example, now stores and syncs passkeys alongside your regular passwords, across Windows, Mac, iOS, Android, and every major browser. A passkey created in Bitwarden isn’t tied to one laptop or one personal Apple account, it’s tied to the vault, which your business controls. Set it up once, and it’s available wherever that person needs to sign in.

For a business, that means:

  • One place to manage both passwords and passkeys, rather than passkeys scattered across personal device ecosystems you can’t see into.
  • Instant offboarding. When someone leaves, you remove their vault access, not their personal iCloud account.
  • Shared logins done properly, through team vaults, rather than shared spreadsheets or sticky notes on a monitor.
  • A single audit trail of who has access to what, which matters increasingly for Cyber Essentials and similar accreditations.

It’s a natural pairing with the passkey change: Microsoft is pushing everyone towards stronger sign-in, and a password manager is what makes that stronger sign-in something your business actually controls, rather than something scattered across your team’s personal phones.

What to do next

If you’re not sure whether your organisation is affected, it’s worth checking now rather than waiting for Microsoft’s September deadline to make the decision for you. We’d suggest:

  1. Identifying which of your users are still relying on text message or phone call codes.
  2. Deciding, per user, whether a device-based passkey is enough, or whether a business-owned password manager is the better fit – particularly for anyone with access to shared or sensitive accounts.
  3. Rolling this out on your own schedule, with proper communication to your team, rather than letting Microsoft’s automatic prompts catch people off guard.

We’re helping several of our clients plan this over the coming weeks – from a quick audit of who’s exposed, through to a managed rollout of passkeys and, where it makes sense, a business password manager to go with it.

Get in touch if you’d like us to run that audit for your organisation.

Get this content straight to your inbox on the third Thursday of every month.

We won't spam you.
See our privacy policy for details.

Scroll to Top